Security News > 2021 > February > Google shares PoC exploit for critical Windows 10 Graphics RCE bug

Project Zero, Google's 0day bug-hunting team, shared technical details and proof-of-concept exploit code for a critical remote code execution bug affecting a Windows graphics component.
The Project Zero researchers discovered the vulnerability, tracked as CVE-2021-24093, in a high-quality text rendering Windows API named Microsoft DirectWrite.
Impacts Windows 10 versions up to 20H2. The security flaw impacts multiple Windows 10 and Windows Server releases up to version 20H2, the latest released version.
After the 90-day disclosure deadline, Project Zero published a proof-of-concept exploit code that can be used to reproduce the bug in browsers running on fully-patched Windows 10 1909 systems.
"It reproduces the crash shown above on a fully updated Windows 10 1909, in all major web browsers. The font itself has been subset to only include the faulty glyph and its dependencies."
In November, Microsoft also fixed a Windows kernel zero-day bug actively exploited in targeted attacks and publicly disclosed by Project Zero one month earlier.
News URL
Related news
- Hackers exploit critical Aviatrix Controller RCE flaw in attacks (source)
- Windows 10 KB5049981 update released with new BYOVD blocklist (source)
- Critical SimpleHelp Flaws Allow File Theft, Privilege Escalation, and RCE Attacks (source)
- Microsoft ends support for Office apps on Windows 10 in October (source)
- Critical Flaws in WGS-804HPT Switches Enable RCE and Network Exploitation (source)
- Windows 11 24H2 now also offered to all eligible Windows 10 PCs (source)
- Cisco warns of denial of service flaw with PoC exploit code (source)
- Cisco fixes ClamAV vulnerability with available PoC and critical Meeting Management flaw (source)
- January Windows 10 preview update force installs new Outlook (source)
- Hackers exploit critical unpatched flaw in Zyxel CPE devices (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-02-25 | CVE-2021-24093 | Unspecified vulnerability in Microsoft products Windows Graphics Component Remote Code Execution Vulnerability | 0.0 |