April 19, 2023, 4:40 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

 

February 2023 Windows Updates brought a fix for CVE-2023-21800,
a vulnerability in Windows Installer that allows a local low-privileged attacker to run their code as Local System. The
vulnerability was reported to Microsoft  by Adrian Denkiewicz with Doyensec. Adrian subsequently wrote an article detailing the vulnerability, which allowed us to reproduce it and create a patch for our users.

The
vulnerability is in one sense a typical symbolic link issue, the types of which we've been seeing …

article code cve escalation february fix installer issue link local local privilege escalation low microsoft patch privilege privileged privilege escalation run system types updates vulnerability windows windows updates

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Cloud Security Engineer

@ City National Bank of Florida | Miami, FL, United States

Principal Security Engineer

@ VIANT | New York City

Associate Detection & Response Analyst

@ Rapid7 | VA Arlington 22203