Tag

Privilege Escalation

All articles tagged with #privilege escalation

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution
security3 days ago

Microsoft patches critical flaws across Entra ID, Arc, and Exchange Online that could enable remote code execution

Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that could let attackers with no privileges execute code remotely and escalate privileges. Key flaws include CVE-2026-69836 in Entra ID (deserialization of untrusted data), CVE-2026-65816 and CVE-2026-69555 in Azure Arc, CVE-2026-65801 in Exchange Online, and CVE-2026-65770 affecting an Azure Managed Instance for Apache Cassandra. Patches are in place and no action is required, with exploit code not publicly available. An August update notes CVE-2026-69836 was initially misflagged as exploited in the wild.

Windows Defender's Boot Driver Could Be Weaponized to Wipe Security Tools at Startup
technology4 days ago

Windows Defender's Boot Driver Could Be Weaponized to Wipe Security Tools at Startup

Check Point Research disclosed a technique that abuses Microsoft Defender’s built-in boot-time removal driver, BTR.sys, to perform kernel-level file and registry operations and potentially delete Defender components during boot. The driver is embedded in Defender and can be triggered with a PoC tool (BTR_CLI); it requires administrative SeLoadDriverPrivilege, but there is no evidence of real-world abuse yet. This isn’t a traditional software vulnerability but an architectural trust boundary that could be exploited, and Microsoft notes it doesn’t require immediate servicing. Defenses include restricting SeLoadDriverPrivilege and monitoring for specific Sysmon/Windows events, since BTR.sys is hard to blocklist without disrupting Defender.

Active Windows zero-day drives urgent August patch Tuesday across core services
security15 days ago

Active Windows zero-day drives urgent August patch Tuesday across core services

Microsoft’s August Patch Tuesday closes 398 CVEs, including CVE-2026-68820—a use‑after‑free in afd.sys that can escalate from code execution to SYSTEM and is under active exploitation—making it the top priority; four other high‑severity flaws (CVE-2026-62878 in Windows DNS Server, CVE-2026-62893 in Windows Deployment Services, CVE-2026-62815 in Microsoft QUIC, and CVE-2026-59124 in HPC Pack) are unauthenticated RCEs whose exploitation depends on service exposure. The update also finishes a two‑part SharePoint chain (CVE-2026-55040 and CVE-2026-63520) first disclosed by Rapid7. Prioritize systems with exposed DNS/WDS/QUIC/HPC services and ensure on‑prem SharePoint farms apply both July and August fixes to close the chain.

Linux XFS reflink flaw could grant root via race condition
security1 month ago

Linux XFS reflink flaw could grant root via race condition

Qualys warns of RefluXFS, a nine-year-old race-condition in the XFS reflink feature (CVE-2026-64600) that enables local unprivileged users to overwrite blocks backing protected files and gain root on Linux kernels 4.11+. The attack clones a target file to a scratch file and races concurrent writes in the copy-on-write path, causing disk-block modifications that survive reboot and produce no kernel logs. Affected distros include RHEL, Oracle Linux, Amazon Linux, Fedora, CentOS Stream, Rocky Linux, AlmaLinux, and CloudLinux, potentially impacting millions. Kernel patches are available and backported; reboot to verify. There are currently no reliable mitigations beyond patching.

XFS reflink race lets unprivileged users seize root on default Linux installs
security1 month ago

XFS reflink race lets unprivileged users seize root on default Linux installs

Qualys disclosed CVE-2026-64600, a race in XFS reflink that lets an unprivileged local user overwrite root-owned files and gain persistent root on default installations of RHEL, Fedora Server, Amazon Linux and other reflink-enabled XFS systems. The exploit requires Linux 4.11+ with reflink=1 and an attacker-writable directory on the same XFS volume as a protected file; it operates at the block layer and can survive reboots. Vendors have issued backported kernel fixes and recommend updating and rebooting; there are no practical mitigations otherwise. Check your XFS configurations (reflink status) and apply the appropriate RHSA advisories for your distro to verify patched kernels are running.

Zoom rolls out urgent Windows patches to block account takeover and privilege escalations
technology1 month ago

Zoom rolls out urgent Windows patches to block account takeover and privilege escalations

Zoom released security updates for Windows to fix a critical flaw (CVE-2026-53412, CVSS 9.8) in Zoom Workplace for Windows and related VDI components that could allow an unauthenticated attacker to take over accounts via network. The patch also addresses three high-severity issues (CVE-2026-53411, CVE-2026-53410, CVE-2026-53409) that could enable privilege escalation for authenticated users or via local access across Zoom Workplace, VDI, VDI plugin, and Zoom Rooms for Windows. Affected version details are provided for each product, and Zoom notes no active exploitation so far. The update also removes Meeting SDK for Windows from the affected scope. Users should install the latest versions to stay protected.

Zero-day lets non-admin modify admin accounts as patch blitz hits Windows
technology1 month ago

Zero-day lets non-admin modify admin accounts as patch blitz hits Windows

A new Windows zero-day called HiveLegacy lets a low-privilege user modify an admin’s registry hive through the Windows User Profile Service, potentially escalating to admin rights when the admin logs in; Microsoft is investigating amid a record patch release, and researchers recommend defenses like a detection script and monitoring registry activity.

New LegacyHive PoC Sparks Windows Privilege Escalation Talk After Patch Tuesday
technology1 month ago

New LegacyHive PoC Sparks Windows Privilege Escalation Talk After Patch Tuesday

Security researcher Chaotic Eclipse released LegacyHive, a PoC for a Windows User Profile Service privilege-escalation vulnerability. The PoC reportedly requires an extra standard credential and a third username (potentially an admin) and, if successful, mounts the target user hive in the current user classes root; the exploit is claimed to work on all supported Windows editions, including the July 2026 Patch Tuesday versions. The disclosure comes amid a disputed back-and-forth with Microsoft, ongoing Defender flaws, and a wave of Patch Tuesday fixes, notably for SharePoint Server, with CISA listing several flaws as actively exploited. The piece highlights growing turbulence around Patch Tuesday disclosures in 2026.

RoguePlanet Privilege Escalation in Defender Finally Patched, No Action Needed
security1 month ago

RoguePlanet Privilege Escalation in Defender Finally Patched, No Action Needed

Microsoft issued security updates addressing RoguePlanet, a privilege-escalation flaw in the Microsoft Malware Protection Engine (mpengine.dll) that could spawn a SYSTEM shell. The fix arrives in Defender engine version 1.1.26060.3008 with defense-in-depth hardening. Disclosed by Chaotic Eclipse, RoguePlanet can be exploited on Windows systems with the June 2026 Patch Tuesday and works regardless of real-time protection. Microsoft says no customer action is required beyond automatic updates.

Ubiquiti rolls out fixes for critical UniFi vulnerabilities across core apps
technology1 month ago

Ubiquiti rolls out fixes for critical UniFi vulnerabilities across core apps

Ubiquiti released patches across UniFi Connect, Talk, Access, Protect, and UniFi OS to fix several critical flaws that could allow privilege escalation or remote command execution. The updates address multiple CVEs (e.g., CVE-2026-50746 for Connect; CVE-2026-50747 for Talk; CVE-2026-50748 and CVE-2026-54400 for Access; CVE-2026-55115 for Protect; CVE-2026-54402 and CVE-2026-55116 for OS) with fixed versions listed for each product. While there’s no confirmed exploitation in the wild, the U.S. CISA has flagged some UniFi OS flaws as weaponized, and historical activity like the MooBot botnet operation involved compromised Edge OS routers. Admins should upgrade to the patched releases to mitigate risk.

Bad Epoll: Tiny Timing Window Lets Unprivileged Users Root Linux and Android
technology1 month ago

Bad Epoll: Tiny Timing Window Lets Unprivileged Users Root Linux and Android

A newly disclosed Linux kernel vulnerability, Bad Epoll (CVE-2026-46242), is a use-after-free race in the epoll subsystem that can let a non-privileged user gain root on Linux desktops, servers, and Android. The attacker exploits a six-instruction timing window to corrupt kernel memory, with broader reach via Chrome’s sandbox and Android support; a upstream patch is available (a6dc643c6931) and backports are expected for 6.4+ kernels, while older 6.1-based Android devices may be unaffected. A public PoC exists, but there’s no evidence of widespread exploitation yet.

Two Actively Exploited Defender Flaws Prompt Auto-Patch Rollout
security3 months ago

Two Actively Exploited Defender Flaws Prompt Auto-Patch Rollout

Microsoft warns that Defender is under active exploitation due to a privilege-escalation flaw (CVE-2026-41091) and a separate denial-of-service flaw (CVE-2026-45498). Updates are delivered automatically via Defender Antimalware Platform versions 1.1.26040.8 and 4.18.26040.7, and systems with Defender disabled are not affected. CISA has added both flaws to its Known Exploited Vulnerabilities catalog, with a June 3, 2026 patch deadline for Federal Civilian Executive Branch agencies. The article also references older Microsoft CVEs that have been added to KEV in recent weeks.

PoC Unleashes PinTheft Linux LPE, Unlocks Root Access
cybersecurity3 months ago

PoC Unleashes PinTheft Linux LPE, Unlocks Root Access

A proof-of-concept exploit named PinTheft has been published for a Linux kernel local privilege escalation, leveraging an RDS zerocopy double-free flaw to gain root access under specific kernel configurations. The PoC demonstrates a novel way to steal references via io_uring and overwrite in-memory pages, underscoring ongoing Linux kernel security challenges. Admins should apply latest patches or blacklist vulnerable modules to mitigate risk.

Nine-Year-Old Linux Kernel Bug Lets Local Users Root on Major Distros
security3 months ago

Nine-Year-Old Linux Kernel Bug Lets Local Users Root on Major Distros

Qualys disclosed CVE-2026-46333, a nine-year-old Linux kernel privilege-escalation flaw in __ptrace_may_access() that can let an unprivileged local user read /etc/shadow, access SSH private keys, and execute commands as root on Debian, Fedora, and Ubuntu; a PoC is available, patches have been released, and mitigations include updating the kernel or setting kernel.yama.ptrace_scope=2 and rotating host keys.

Public PoC Unleashes Windows 'MiniPlasma' Privilege-Escalation to SYSTEM
cyber-security-news3 months ago

Public PoC Unleashes Windows 'MiniPlasma' Privilege-Escalation to SYSTEM

A publicly released PoC for the Windows 'MiniPlasma' zero-day privilege-escalation flaw lets unprivileged users gain SYSTEM privileges by exploiting the Cloud Filter driver’s HsmOsBlockPlaceholderAccess race condition and writing to the .DEFAULT hive. The bug traces to CVE-2020-17103 (originally patched in 2020 by Microsoft) but the PoC shows the flaw remains exploitable; Nightmare-Eclipse released the exploit on GitHub on May 13, 2026, after May Patch Tuesday, increasing risk as weaponized code circulates and affects all Windows versions. Organizations should monitor Microsoft’s response and apply patches when available.