June 30, 2023, 12:20 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

 


January 2023 Windows Updates brought a fix for CVE-2023-21541,
a local privilege elevation in Task Scheduler. The vulnerability was reported to Microsoft by Ben Lincoln of Bishop Fox.

In April, Ben published a detailed analysis of this issue, which allowed us to reproduce the issue and create a micropatch for Windows computer that haven't received an official fix from Microsoft.

The
vulnerability is easy to understand: if a scheduled task contains an environment variable in its executable path, …

analysis april ben bishop fox cve fix fox issue january local micropatch microsoft privilege scheduler task task scheduler updates vulnerability windows windows updates

Application Security Assurance Associate

@ DTCC | Tampa, FL, United States

Threat Hunter II

@ Microsoft | Hyderabad, Telangana, India

Staff Cyber Security Engineer (Application Security, Emerging Platforms)

@ NBCUniversal | Englewood Cliffs, NEW JERSEY, United States

Cyber Security Senior Cyber Security Engineer

@ Sopra Steria | Noida, Uttar Pradesh, India

Data Protection and Privacy Manager

@ Future PLC | London, England, United Kingdom

RSOC Manager

@ The University of Texas at Austin | AUSTIN, TX