Get a Pentest and security assessment of your IT network.

News

#AVGater attack abuse Quarantine vulnerabilities for privilege escalation

Security experts Florian Bogner devised a method dubbed AVGater to escalate privileges by abusing the quarantine feature of some antiviruses. The attack chain starts by inducting AV software into placing a malicious DLL file into quarantine. The attacker then uses the security applications Windows process, that runs with SYSTEM permissions, to restore the file. The malicious file is not restored to its original location, but to a different folder from which it is possible to execute a privileged process such as the Program Files or Windows folders.”]

Source: https://securityaffairs.co/wordpress/65405/hacking/avgater-attack-antivirus.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Botnet authors use Evernote account as C&C Server

News

Canadian agency breached as hackers exploit CVE-2017-5638 flaw in Apache Struts 2