Get a Pentest and security assessment of your IT network.

Cyber Security

Windows kernel zero-day vulnerability used in targeted attacks

The Windows kernel bug zero-day can be exploited by local attackers for privilege escalation (including sandbox escape) The flaw is a pool-based buffer overflow that exists in the Windows Kernel Cryptography Driver (cng.sys) It is currently tracked as CVE-2020-17087. The bug was added to the Project Zero issue tracker only 8 days ago, it was disclosed after only 7 days because it was being used by attackers in the wild. A patch for the bug is expected to be available on November 10.

Source: https://www.bleepingcomputer.com/news/security/windows-kernel-zero-day-vulnerability-used-in-targeted-attacks/

Related posts
Cyber Security

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

Cyber Security

Art of Twitter account hacking

Cyber Security

Alexa Eavesdropping Flub Re-Sparks Voice Assistant Privacy Debate

Cyber Security

Dan Geer, Richard Thieme on specialization in security