Windows kernel bug now exploited in attacks to gain SYSTEM privileges

Share:

CISA has warned U.S. federal agencies to secure their systems against ongoing attacks targeting a high-severity Windows kernel vulnerability.

Tracked as CVE-2024-35250, this security flaw is due to an untrusted pointer dereference weakness that allows local attackers to gain SYSTEM privileges in low-complexity attacks that don’t require user interaction.

While Microsoft didn’t share more details in a security advisory published in June, the DEVCORE Research Team that found the flaw and reported it to Microsoft through Trend Micro’s Zero Day Initiative says the vulnerable system component is the Microsoft Kernel Streaming Service (MSKSSRV.SYS).

DEVCORE security researchers used this MSKSSRV privilege escalation security flaw to compromise a fully patched Windows 11 system on the first day of this year’s Pwn2Own Vancouver 2024 hacking contest.

Redmond patched the bug during the June 2024 Patch Tuesday, with proof-of-concept exploit code released on GitHub four months later.

“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” the company says in a security advisory that has yet to be updated to indicate the vulnerability is under active exploitation.

DEVCORE published the following video demo of their CVE-2024-35250 proof-of-concept exploit being used to hack a Windows 11 23H2 device.

Today, CISA also added a critical Adobe ColdFusion vulnerability (tracked as CVE-2024-20767), which Adobe patched in March. Since then, several proof-of-concept exploits have been published online.

CVE-2024-20767 is due to an improper access control weakness that allows unauthenticated, remote attackers to read the system and other sensitive files. According to SecureLayer7, successfully exploiting ColdFusion servers with the admin panel exposed online can also allow attackers to bypass security measures and perform arbitrary file system writes.

The Fofa search engine tracks over 145,000 Internet-exposed ColdFusion servers, although it is impossible to pinpoint the exact ones with remotely accessible admin panels.

CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog, tagging them as actively exploited. As mandated by the Binding Operational Directive (BOD) 22-01, federal agencies must secure their networks within three weeks by January 6.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” the cybersecurity agency said.

While CISA’s KEV catalog primarily alerts federal agencies about security bugs that should be patched as soon as possible, private organizations are also advised to prioritize mitigating these vulnerabilities to block ongoing attacks.

A Microsoft spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today for more details regarding CVE-2024-35250 in the wild exploitation.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
5:44 pm, Apr 20, 2025
weather icon 12°C
L: 11° | H: 13°
broken clouds
Humidity: 71 %
Pressure: 1006 mb
Wind: 6 mph ESE
Wind Gust: 12 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 82%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 5:53 am
Sunset: 8:04 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
11° | 13°°C 0 mm 0% 8 mph 72 % 1007 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
10° | 15°°C 1 mm 100% 8 mph 89 % 1013 mb 0 mm/h
Tue Apr 22 10:00 pm
weather icon
7° | 16°°C 0 mm 0% 9 mph 92 % 1018 mb 0 mm/h
Wed Apr 23 10:00 pm
weather icon
8° | 14°°C 1 mm 100% 6 mph 80 % 1019 mb 0 mm/h
Thu Apr 24 10:00 pm
weather icon
10° | 15°°C 0 mm 0% 5 mph 82 % 1022 mb 0 mm/h
Today 7:00 pm
weather icon
12° | 13°°C 0 mm 0% 8 mph 71 % 1007 mb 0 mm/h
Today 10:00 pm
weather icon
11° | 12°°C 0 mm 0% 6 mph 72 % 1007 mb 0 mm/h
Tomorrow 1:00 am
weather icon
10° | 11°°C 0 mm 0% 3 mph 79 % 1008 mb 0 mm/h
Tomorrow 4:00 am
weather icon
10° | 10°°C 0 mm 0% 2 mph 84 % 1007 mb 0 mm/h
Tomorrow 7:00 am
weather icon
10° | 10°°C 0.2 mm 20% 2 mph 89 % 1008 mb 0 mm/h
Tomorrow 10:00 am
weather icon
10° | 10°°C 0 mm 0% 1 mph 87 % 1009 mb 0 mm/h
Tomorrow 1:00 pm
weather icon
15° | 15°°C 0.2 mm 20% 3 mph 60 % 1009 mb 0 mm/h
Tomorrow 4:00 pm
weather icon
13° | 13°°C 1 mm 100% 8 mph 83 % 1010 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€74,333.40
-0.59%
Ethereum(ETH)
€1,388.82
-1.49%
Tether(USDT)
€0.88
0.02%
XRP(XRP)
€1.81
-0.74%
Solana(SOL)
€120.19
-1.15%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.135260
-2.29%
Shiba Inu(SHIB)
€0.000011
2.61%
Pepe(PEPE)
€0.000007
3.41%
Scroll to Top