Zero-Day Exploitation: Microsoft Kernel Streaming Service Under Attack
TL;DR Summary
A vulnerability (CVE-2023-36802) in the Microsoft Kernel Streaming Server, a Windows kernel component used for virtualization and sharing of camera devices, allows a local attacker to escalate privileges to SYSTEM. The vulnerability was discovered during an exploration of the Windows kernel attack surface, and a proof-of-concept exploit was developed. The exploit leverages an object type confusion vulnerability and a constant write-where primitive to achieve arbitrary kernel read-write and privilege escalation. The vulnerability was patched by Microsoft, and in-the-wild exploitation has been observed.
Critically close to zero (day): Exploiting Microsoft Kernel streaming service Security Intelligence
Reading Insights
Total Reads
0
Unique Readers
11
Time Saved
12 min
vs 12 min read
Condensed
97%
2,383 → 82 words
Want the full story? Read the original article
Read on Security Intelligence