Security News > 2021 > March > Working Windows and Linux Spectre exploits found on VirusTotal

Working Windows and Linux Spectre exploits found on VirusTotal
2021-03-01 23:05

Working exploits targeting Linux and Windows systems not patched against a three-year-old vulnerability dubbed Spectre were found by security researcher Julien Voisin on VirusTotal.

Voisin found the two working Linux and Windows exploits on the online VirusTotal malware analysis platform.

Unprivileged users can use the exploits to dump LM/NT hashes on Windows systems and the Linux /etc/shadow file from the targeted devices' kernel memory.

The linked exploits were uploaded on VirusTotal last month as part of a larger package, an Immunity Canvas 7.26 installer for Windows and Linux.

The company announced that CANVAS would provide security professionals and penetration testers with access to working Spectre exploits within months after the vulnerability was disclosed.

As Voisin said, the exploits will break if the machine it's executed on runs a patched Linux or Windows version.


News URL

https://www.bleepingcomputer.com/news/security/working-windows-and-linux-spectre-exploits-found-on-virustotal/

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Linux 17 385 1515 1178 679 3757
Virustotal 2 0 17 3 1 21