ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

New Windows Zero-Day

criticalExploit / PoC exploited in the wildimportance 60
Full article119 words · extracted from schneier.com · click to collapse

Google’s Project Zero has discovered and published a buffer overflow vulnerability in the Windows Kernel Cryptography Driver. The exploit doesn’t affect the cryptography, but allows attackers to escalate system privileges:

Attackers were combining an exploit for it with a separate one targeting a recently fixed flaw in Chrome. The former allowed the latter to escape a security sandbox so the latter could execute code on vulnerable machines.

The vulnerability is being exploited in the wild, although Microsoft says it’s not being exploited widely. Everyone expects a fix in the next Patch Tuesday cycle.

Tags: exploits, Windows, zero-day

Posted on November 2, 2020 at 2:01 PM11 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2020/11/new-windows-zero-day.html