Researchers have found more ways to exploit versions of Windows 10

Microsoft Store in Windows 10
(Image credit: Microsoft)

Cybersecurity researchers from Numen have found more ways to exploit older versions of Windows 10

Earlier this week, the company’s experts published a proof-of-concept (PoC) exploit for a flaw known to be used by threat actors in the wild. The vulnerability is tracked as CVE-2023-29336, and carries a severity rating of 7.8. 

Threat actors abusing it can elevate low-privilege users to SYSTEM privileges, granting them the ability to run arbitrary code on target endpoints. It affects the Win32k subsystem which handles the communication between input hardware and components such as screen output and graphics. 

Older versions affected

The flaw was initially discovered by researchers from Avast, which said hackers used it in zero-day attacks. Now, Numen’s PoC shows how the exploit can be leveraged in Windows Server 2016, too. 

While older versions of Windows 10, Windows Server, and Windows 8, are vulnerable, newer versions, such as Windows 11, are immune, it was said. 

Microsoft patched the vulnerability last month, with the Patch Tuesday May 2023 cumulative update. 

"While this vulnerability seems to be non-exploitable on the Win11 system version, it poses a significant risk to earlier systems," Numen said. "Exploitation of such vulnerabilities has a notorious track record.” The researchers argue that it doesn’t take a highly experienced hacker to leverage the flaw either. 

IT teams worried about being targeted through this flaw should keep a close eye on offset reads and writes in memory, or related window objects, for anything out of the ordinary. That, the researchers say, is one of the biggest indicators of compromise in this case, and suggests local privilege escalation.

"Apart from diligently exploring different methods to gain control over the first write operation using the reoccupied data from freed memory, there is typically no need for novel exploitation techniques," reads the report.

IT teams are advised to apply Microsoft’s patch as soon as possible.

Via: BleepingComputer

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Avast cybersecurity
An unpatched Windows zero-day flaw has been exploited by 11 nation-state attackers
A digital representation of a lock
Security experts are being targeted with fake malware discoveries
A person at a laptop with a cybersecure lock symbol floating above it.
Parallels Desktop has some worrying security flaws for Mac users
Representational image of a cybercriminal
Microsoft discovers five potentially damaging attacks against its own software
Representational image of a cybercriminal
Microsoft just patched a host of worrying security issues, so update now
A hacker wearing a hoodie sitting at a computer, his face hidden.
Microsoft patches three worrying security flaws in its latest critical update, so update now
Latest in Software & Services
TinEye website
I like this reverse image search service the most
A person in a wheelchair working at a computer.
Here’s a free way to find long lost relatives and friends
A white woman with long brown hair in a ponytail looks down at her computer in a distressed manner. She is holding her forehead with one hand and a credit card with the other
This people search finder covers all the bases, but it's not perfect
That's Them home page
Is That's Them worth it? My honest review
woman listening to computer
AWS vs Azure: choosing the right platform to maximize your company's investment
A person at a desktop computer working on spreadsheet tables.
Trello vs Jira: which project management solution is best for you?
Latest in News
Zotac Gaming RTX 5090 Graphics Card
Nvidia Blackwell stock woes are compounded by price hikes as more RTX 5090 GPUs soar in pricing, and I’m sick and tired of it all at this point
A collage of Elizabeth Olsen's Scarlet Witch and Tatiana Maslany's She-Hulk
Marvel fans are already tired of Doomsday and Secret Wars cast gossip as two more superheroes get linked with roles in the next two Avengers movies
Four operators survey Verdansk. One holds a sniper rifle, one binoculars, another holds is landing with their parachute, while the last wears a skull mask
New Call of Duty: Warzone trailer shows a beautiful rebuilt Verdansk, but some fans want more: 'it won't be the same unfortunately'
An Apple Music pink/pixellated poster advertising DJ with Apple Music
DJ with Apple Music lands, allowing subscribers to build and mix DJ sets directly from its +100 million-song catalog
The Meta Quest 3 and controllers on their charging station which is itself on a wooden desk next to a lamp
Forget Android XR, I've got my eyes on Vivo's new Meta Quest 3 competitor as it could be the most important VR headset of 2025
Samsung Galaxy S25 from the front
The Now Bar on Samsung One UI 7 is about to get a lot more useful – and could soon match Live Activities on iOS