< ciso
brief />
Tag Banner

All news with #privilege escalation tag

352 articles · page 3 of 18

Researcher Publishes FalconFlank PoC for CrowdStrike

🔒 A security researcher known as Chaotic Eclipse released a zero-day PoC called FalconFlank that enables local privilege escalation by abusing CrowdStrike Falcon's office malicious macros remediation. The researcher says the exploit works on fully updated Windows 11 25H2 and Windows Server 2025 systems with Falcon installed, and cautions defenders may need to add exclusions or obfuscate detection to test it. This release follows recent PoCs targeting Kaspersky and Microsoft Defender, with the researcher criticizing vendor engagement.
read more →

ValleyRAT backdoor concealed in signed adware

🛡️ Kaspersky attributes a campaign to Silver Fox that hides the ValleyRAT backdoor inside a legitimately signed Chinese adware installer, QN Wallpaper. The attackers use DLL sideloading to run a malicious libcef.dll within the signed QnWallpaper.exe, disable Windows Defender, add autorun entries, and escalate privileges with runas. ValleyRAT can steal keystrokes and screenshots, mark its process as critical to induce BSOD on termination, and contacts several C2 servers and domains.
read more →

Five critical WordPress plugin and theme flaws

🔒 Multiple critical vulnerabilities have been disclosed in popular WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. Reports from Wordfence and Patchstack describe issues ranging from authentication bypass and privilege escalation to arbitrary file writes and remote code execution. Affected versions span multiple releases and require immediate patching or mitigation to prevent complete site takeover.
read more →

ServiceNow patches three maximum severity platform flaws

🔒 ServiceNow has released patches for three maximum-severity vulnerabilities in its ServiceNow AI Platform that enable low-complexity code injection, SQL injection, and privilege escalation without user interaction. Cloud instances have been updated, and self-hosted customers are urged to patch immediately. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) could allow attackers to execute arbitrary code, alter or create instance data, and run arbitrary SQL against the database. ServiceNow also patched a high-severity sandbox escape (CVE-2026-6876); the vendor reports no known exploitation to date.
read more →

ServiceNow patches three critical AI Platform flaws

🔒 ServiceNow issued emergency patches for three maximum-severity vulnerabilities in its AI Platform, addressing code injection, SQL injection, and privilege escalation risks. The flaws (CVE-2026-18885, CVE-2026-18886, CVE-2026-74820) can be exploited by unauthenticated attackers with low complexity and no user interaction. The company also patched a high-severity sandbox escape (CVE-2026-6876) and urged customers to update self-hosted instances promptly.
read more →

Critical cPanel flaw allows root code execution

🛡️ cPanel released patches for a critical vulnerability (CVE-2026-65643) affecting domain parking and addon domain handling in cPanel & WHM that could let authenticated users create arbitrary files and achieve root code execution. The company published fixed builds across multiple release branches on August 27, 2026, and advised administrators to update immediately or enable automatic updates. The advisory names patched builds including a WP Squared release, omits DNSOnly, and provides no interim mitigation or CVSS score. Servers on end-of-life versions must upgrade to receive the fix.
read more →

GPUThor Rowhammer Breaks ECC on NVIDIA Ampere GPUs

🛡️ Academic researchers disclosed GPUThor, a Rowhammer attack that induces widespread bit flips on NVIDIA Ampere-class workstation GPUs with GDDR6, defeating recommended ECC mitigations and enabling denial-of-service and host privilege escalation. The University of Toronto team hammered DRAM banks for extended periods on multiple RTX A-series cards, producing up to 377,552 flips per gigabyte on an A5000. The exploit requires running an unprivileged CUDA kernel and the researchers advise avoiding cross-tenant GPU sharing, monitoring ECC counters, and restricting untrusted CUDA workloads.
read more →

GPUThor Rowhammer Bypasses NVIDIA ECC Protections

🛡️ Researchers from the University of Toronto disclosed GPUThor, a Rowhammer variant that defeats SECDED ECC on Ampere-class NVIDIA GPUs, enabling DoS and root privilege escalation. The attack achieves far higher bit-flip rates than prior GPU Rowhammer concepts by exploiting undocumented memory request coalescing and TRR behavior. Tested on RTX A4000–A6000 cards, GPUThor produced thousands of flips per GB and demonstrated both device resets and corrupted page tables leading to host root access. NVIDIA issued guidance recommending SYS-ECC, IOMMU/DMA isolation, telemetry monitoring, and restrictions on untrusted workloads.
read more →

Windows Defender driver can be repurposed for abuse

🛡️ Check Point Research found that Microsoft-signed Boot-Time Removal driver BTR.sys can be abused to perform kernel-level file and registry operations, potentially neutralizing security controls. The technique uses an undocumented encrypted transaction format rather than a conventional IOCTL interface and affects Windows versions from Windows 7 through Windows 11 25H2. CPR released a proof-of-concept tool, BTR_CLI, demonstrating extraction, transaction construction, and driver loading using the system's own copy of BTR.sys. Microsoft indicated the issue did not meet criteria for immediate servicing and noted the attack requires pre-existing privileges.
read more →

Protecting Windows Named Pipes from Local Abuse

🔒 Named pipes are commonly used for interprocess communication on Windows but should never be treated as implicitly trusted. Developers often assume local IPC is safe, yet different users, sessions, and privilege levels may run on the same machine. Servers must verify client identities, apply explicit DACLs, authorize each operation, and validate message contents to avoid privilege escalation, confused-deputy issues, and denial-of-service. Remote accessibility and predictable pipe names further increase risk, so implement strict limits, timeouts, and local-only protections.
read more →

Microsoft Defender driver can be abused for kernel ops

🔒 Check Point Research demonstrated that Microsoft Defender's boot-time remediation driver, BTR.sys, can be repurposed to perform arbitrary kernel-level file and registry operations on Windows 7 through Windows 11 25H2 without exploiting a software flaw. The researcher published a proof-of-concept tool, BTR_CLI, and presented results at Black Hat USA 2026 and DEF CON 34, showing the driver can delete or move protected binaries and schedule actions for the next reboot. The technique requires administrative privileges (SeLoadDriverPrivilege) and leverages the driver's embedded RC4-encrypted protocol, making the component difficult to block without disrupting Defender. Check Point reported no evidence of real-world abuse and shared detection indicators and mitigation guidance focused on restricting SeLoadDriverPrivilege.
read more →

CISA: Windows Task Host Flaw Now Exploited by Ransomware

🔒 CISA confirmed ransomware gangs are exploiting a high-severity Windows Task Host privilege escalation flaw, tracked as CVE-2025-60710, which Microsoft patched in November 2025. The vulnerability affects Windows 11 and Windows Server 2025 and allows local attackers with basic permissions to escalate to SYSTEM. Although Microsoft has not detailed active attacks, CISA added the flaw to its Known Exploited Vulnerabilities list and urged federal agencies to apply mitigations promptly.
read more →

UNISOC modem isolation flaw risks kernel RCE

🔒 SSD Secure Disclosure researchers revealed a UNISOC modem firmware vulnerability that lets modem-level code execution reach Android kernel space by exploiting improper isolation between modem and kernel memory. The team demonstrated a full exploit chain, including a VoLTE-triggered final stage, and tested it on devices such as the Realme C33. No vendor firmware fix from UNISOC has been reported, leaving OEM updates as the primary mitigation.
read more →

Certighost: Privilege Risks in Your Certificate Authority

🔒 Certighost (CVE-2026-54121) demonstrates how a standard domain user can coerce an Enterprise CA to issue a Domain Controller certificate via AD CS "chase" behavior. The flaw allows an attacker to obtain PKINIT authentication as a DC, perform DCSync, and escalate to domain compromise. Microsoft patched the issue on July 14, 2026; mitigate by patching, restricting CA outbound access, and reducing MachineAccountQuota.
read more →

Microsoft works on patch for Defender ShieldBreak zero-day

🛡️ Microsoft confirmed it is developing a security update to address a new Microsoft Defender zero-day called "ShieldBreak," disclosed by researcher "Nightmare Eclipse" after the August 2026 Patch Tuesday. The PoC reportedly allows local attackers with limited permissions to escalate to SYSTEM on patched Windows 10, Windows 11, and Windows Server, and has been tracked as CVE-2026-69414. Microsoft stated it is investigating and will provide a quality security update, while the researcher publicly disclosed the exploit amid a dispute over disclosure and bounties.
read more →

Microsoft patches LegacyHive Windows zero‑day

🛡️ Microsoft released patches addressing the Windows zero-day dubbed LegacyHive, disclosed after July 2026 Patch Tuesday. The flaw was revealed by a researcher using the "Nightmare Eclipse" handle, who published a proof-of-concept after the updates; the exploit requires additional credentials, limiting easy weaponization. Microsoft tracked the issue as CVE-2026-62832 and describes the bug as improper link resolution in the Windows User Profile Service that can allow local privilege escalation. ACROS Security also issued unofficial mitigations prior to Microsoft's August fixes.
read more →

SCCM attack chain exploited with $58 certificate

🛡️ Researchers at XM Cyber demonstrated how a standard domain user can chain multiple flaws in Microsoft System Center Configuration Manager (SCCM) to achieve remote code execution on the primary site server. The attack combines a broken AdminService authorization, a path-traversal bug called CabSlip, weak signature validation exploitable with a low-cost commercial certificate, and an unsigned DLL load in the SMS Executive service. Microsoft patched the initial authorization flaw (CVE-2026-47301) in July, but additional fixes are expected in ConfigMgr 2609.
read more →

Researcher posts Defender patch bypass PoC

🛡️ A researcher known as Nightmare Eclipse published a proof-of-concept called ShieldBreak that appears to bypass Microsoft’s recent patch for CVE-2026-50656, enabling attackers with any initial access to escalate to system-level privileges. Security experts warn the PoC could erode trust in patches and stress defense-in-depth measures such as application allowlisting, tightened admin rights, and hunting for MsMpEng.exe spawning system shells. Independent confirmations and community detections are emerging, though Microsoft has not yet provided a formal response.
read more →

Researchers reveal Plug and Pwn USB installation exploit

🛡️ Security researchers disclosed a new "Plug and Pwn" attack that abuses Windows Plug and Play to trick the OS into installing vendor packages as NT AUTHORITY\SYSTEM. Using USB emulation and RDP USB redirection, attackers can force Windows to load signed but vulnerable co-installers, services, or drivers and escalate to SYSTEM without user interaction. Some chains require no logged-in user and one variant works remotely over RDP; mitigations like DisableCoInstallers reduce risk but do not eliminate the attack surface.
read more →

Adobe issues urgent patches for critical ColdFusion flaws

🔒 Adobe released security updates to address multiple critical vulnerabilities in ColdFusion, Commerce, and Campaign Classic. Several flaws carry maximum or near-maximum CVSS scores and could enable arbitrary code execution or privilege escalation. Updates for ColdFusion and Campaign Classic are rated Priority 1, and on-premise Campaign Classic customers must patch promptly; Adobe-hosted instances are already remediated.
read more →