Windows kernel bug now exploited in attacks to gain SYSTEM privileges

Share:

CISA has warned U.S. federal agencies to secure their systems against ongoing attacks targeting a high-severity Windows kernel vulnerability.

Tracked as CVE-2024-35250, this security flaw is due to an untrusted pointer dereference weakness that allows local attackers to gain SYSTEM privileges in low-complexity attacks that don’t require user interaction.

While Microsoft didn’t share more details in a security advisory published in June, the DEVCORE Research Team that found the flaw and reported it to Microsoft through Trend Micro’s Zero Day Initiative says the vulnerable system component is the Microsoft Kernel Streaming Service (MSKSSRV.SYS).

DEVCORE security researchers used this MSKSSRV privilege escalation security flaw to compromise a fully patched Windows 11 system on the first day of this year’s Pwn2Own Vancouver 2024 hacking contest.

Redmond patched the bug during the June 2024 Patch Tuesday, with proof-of-concept exploit code released on GitHub four months later.

“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” the company says in a security advisory that has yet to be updated to indicate the vulnerability is under active exploitation.

DEVCORE published the following video demo of their CVE-2024-35250 proof-of-concept exploit being used to hack a Windows 11 23H2 device.

Today, CISA also added a critical Adobe ColdFusion vulnerability (tracked as CVE-2024-20767), which Adobe patched in March. Since then, several proof-of-concept exploits have been published online.

CVE-2024-20767 is due to an improper access control weakness that allows unauthenticated, remote attackers to read the system and other sensitive files. According to SecureLayer7, successfully exploiting ColdFusion servers with the admin panel exposed online can also allow attackers to bypass security measures and perform arbitrary file system writes.

The Fofa search engine tracks over 145,000 Internet-exposed ColdFusion servers, although it is impossible to pinpoint the exact ones with remotely accessible admin panels.

CISA added both vulnerabilities to its Known Exploited Vulnerabilities catalog, tagging them as actively exploited. As mandated by the Binding Operational Directive (BOD) 22-01, federal agencies must secure their networks within three weeks by January 6.

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” the cybersecurity agency said.

While CISA’s KEV catalog primarily alerts federal agencies about security bugs that should be patched as soon as possible, private organizations are also advised to prioritize mitigating these vulnerabilities to block ongoing attacks.

A Microsoft spokesperson was not immediately available for comment when contacted by BleepingComputer earlier today for more details regarding CVE-2024-35250 in the wild exploitation.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
6:14 am, Jun 9, 2025
weather icon 12°C
L: 10° | H: 12°
clear sky
Humidity: 84 %
Pressure: 1021 mb
Wind: 3 mph WSW
Wind Gust: 7 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 8%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 4:44 am
Sunset: 9:15 pm
DailyHourly
Daily ForecastHourly Forecast
Today 10:00 pm
weather icon
10° | 12°°C 0 mm 0% 9 mph 84 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
weather icon
13° | 20°°C 1 mm 100% 10 mph 83 % 1020 mb 0 mm/h
Wed Jun 11 10:00 pm
weather icon
13° | 22°°C 0 mm 0% 12 mph 90 % 1021 mb 0 mm/h
Thu Jun 12 10:00 pm
weather icon
15° | 25°°C 1 mm 100% 11 mph 94 % 1018 mb 0 mm/h
Fri Jun 13 10:00 pm
weather icon
16° | 27°°C 1 mm 100% 10 mph 96 % 1020 mb 0 mm/h
Today 7:00 am
weather icon
12° | 12°°C 0 mm 0% 6 mph 84 % 1022 mb 0 mm/h
Today 10:00 am
weather icon
13° | 16°°C 0 mm 0% 7 mph 77 % 1022 mb 0 mm/h
Today 1:00 pm
weather icon
17° | 19°°C 0 mm 0% 9 mph 59 % 1021 mb 0 mm/h
Today 4:00 pm
weather icon
20° | 20°°C 0 mm 0% 9 mph 48 % 1021 mb 0 mm/h
Today 7:00 pm
weather icon
19° | 19°°C 0 mm 0% 8 mph 57 % 1019 mb 0 mm/h
Today 10:00 pm
weather icon
15° | 15°°C 0 mm 0% 9 mph 73 % 1019 mb 0 mm/h
Tomorrow 1:00 am
weather icon
14° | 14°°C 0 mm 0% 8 mph 78 % 1018 mb 0 mm/h
Tomorrow 4:00 am
weather icon
13° | 13°°C 0 mm 0% 10 mph 82 % 1017 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€92,494.16
-0.10%
Ethereum(ETH)
€2,180.07
-1.15%
Tether(USDT)
€0.88
0.00%
XRP(XRP)
€1.95
2.55%
Solana(SOL)
€132.37
0.66%
USDC(USDC)
€0.88
0.00%
Dogecoin(DOGE)
€0.159281
-1.34%
Shiba Inu(SHIB)
€0.000011
-1.63%
Pepe(PEPE)
€0.000010
-0.91%
Peanut the Squirrel(PNUT)
€0.233175
1.70%
Scroll to Top