Blog | G5 Cyber Security

Warning Hackers Exploiting New Windows Installer Zero-Day Exploit in the Wild

Security researcher Abdelhamid Naceri discovered a new variant of a privilege escalation vulnerability. The vulnerability was originally resolved as part of Microsoft’s Patch Tuesday updates for November 2021. The latest variant of CVE-2021-41379 is “more powerful than the original one,” he says. The proof-of-concept (PoC) exploit, dubbed “InstallerFileTakeOver,” works by overwriting the discretionary access control list (DACL) for Microsoft Edge Elevation Service to replace any executable file with an MSI installer file.”]

Source: https://thehackernews.com/2021/11/warning-hackers-exploiting-new-windows.html

Exit mobile version