Security News > 2020 > October > Windows kernel zero-day vulnerability used in targeted attacks

Windows kernel zero-day vulnerability used in targeted attacks
2020-10-30 13:38

Project Zero, Google's 0day bug-hunting team, today disclosed a zero-day elevation of privileges vulnerability found in the Windows kernel and actively exploited in targeted attacks.

The Windows kernel bug zero-day can be exploited by local attackers for privilege escalation according to Project Zero security researchers Mateusz Jurczyk and Sergei Glazunov.

Project Zero also provides a proof-of-concept exploit that can be used to crash vulnerable Windows devices even for default system configurations.

According to Ben Hawkes, technical team lead of Google's Project Zero security research team, the ongoing attacks that exploit CVE-2020-17087 in the wild are not focused on targets associated with the U.S. election.

Last week, Google also fixed an actively exploited zero-day vulnerability found by Project Zero researchers in the Google Chrome web browser.


News URL

https://www.bleepingcomputer.com/news/security/windows-kernel-zero-day-vulnerability-used-in-targeted-attacks/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2020-11-11 CVE-2020-17087 Incorrect Calculation of Buffer Size vulnerability in Microsoft products
Windows Kernel Local Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-131
7.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Kernel 3 0 8 4 1 13