Warning of zero-day vulnerabilities in window manager on PC
Recently, Kaspersky global security company has discovered a zero-day vulnerability in the Desktop Window Manager, warning of the risk of taking control of the system.
When analyzing the CVE-2021-1732 vulnerability that was once exploited by the BITT APT team, Kaspersky experts found a similar zero-day vulnerability. This is a vulnerability that has never been previously exploited and has not been associated with any known harmful agents. Immediately, Kaspersky notified Microsoft. Once confirmed, this zero-day vulnerability is named CVE-2021-28310.
'Initially, this vulnerability was discovered by our advanced technology to prevent the vulnerability and archive related findings. In fact, over the past few years, we have included many anti-exploit technologies in our products, and these technologies have consistently worked .''- Boris Larin - security expert at Kaspersky - said.
According to the researchers, it is likely that this vulnerability has been used but not discovered. This is a privilege escalation (EoP) vulnerability discovered in the Desktop Window Manager, allowing an attacker to execute malicious code on the victim's machine. This vulnerability can potentially be used in conjunction with other vulnerabilities in the browser to avoid the sandbox engine. Hackers can even gain privileges through this loophole to gain deeper access to a computer system.
However, Kaspersky's initial investigation has not revealed the full chain of infections. Therefore, security experts still do not know if this vulnerability will be used concurrently with another zero-day vulnerability.
To prevent threats from new vulnerabilities, Kaspersky experts recommend individuals and businesses to install patches for the vulnerability as soon as possible. In addition, IT security managers can use vulnerability and patch management in an endpoint security solution to simplify work. To avoid unexpected cyber attacks, units should also deploy an enterprise-level security solution that detects high-level threats early in the network.
You should read it
- The Mail app on iOS has serious vulnerabilities
- IBM developed a new technology to patch security holes
- Security vulnerabilities - basic insights
- HP publishes a series of critical vulnerabilities in the Teradici PCoIP protocol
- Find security holes on every site with Nikto
- Microsoft expert discovered a series of serious code execution errors in IoT, OT devices
- 5 common errors in managing security vulnerabilities
- New dangerous vulnerability in Intel CPU: Works like Specter and Meltdown, threatening all PCs and the cloud
- Many serious vulnerabilities have been discovered that allow attackers to take full control of the 4G router
- How to scan websites for potential security vulnerabilities with Vega on Kali Linux
- Microsoft rewards $ 250,000 for any talent that discovers the new Meltdown and Specter vulnerabilities
- Foreshadow - the fifth most serious security hole in the CPU in 2018
Maybe you are interested
Instructions to turn off the Spotify Canvas feature How to add wallpapers to the Debian 10 terminal Dell Latitude 9510 officially launched: 5G support, up to 30 hours of battery life Fix error 'Unfortunately Google Allo has Stopped Error on Android' 10 types of people you should avoid as far as possible in your life 8 types of people you should avoid as far as possible