Feb. 29, 2024, 11:19 a.m. | info@thehackernews.com (The Hacker News)

The Hacker News thehackernews.com

The notorious Lazarus Group actors exploited a recently patched privilege escalation flaw in the Windows Kernel as a zero-day to obtain kernel-level access and disable security software on compromised hosts.
The vulnerability in question is CVE-2024-21338 (CVSS score: 7.8), which can permit an attacker to gain SYSTEM privileges. It was resolved by Microsoft earlier this month as part

access attacker attacks can compromised cve cve-2024-21338 cvss cvss score escalation exploited flaw hackers kernel lazarus lazarus group privilege privilege escalation privilege escalation flaw privileges question score security security software software system system privileges vulnerability windows windows kernel zero-day

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC