Microsoft sent out a patch Tuesday that sought to fix two vulnerabilities that are actively being exploited in Windows. The first, targeting Windows 7 users, was made public last week by Google security engineer Clement Lecigne. He warned that the vulnerability could be used in conjunction with a Chrome to take over Windows systems and advised users to upgrade to Windows 10.

The second flaw was identified by Kaspersky Lab saying they have identified a new exploit vulnerability in Windows, which they believe has been used in targeted attacks by at least two threat actors.
The exploit targets Windows 8 and Windows 10, using a vulnerability in the Microsoft Windows graphics subsystem to achieve local privilege escalation. This gives the attacker complete control over the victim's computer.
The exploited vulnerability was detected by Kaspersky Lab's “Automatic Exploit Prevention”.
Kaspersky Lab products detect the exploit as:
HEUR:Exploit.Win32.Generic
HEUR:Trojan.Win32.Generic
PDM:Exploit.Win32.Generic
Kaspersky researchers who discovered the bug, Vasiliy Berdnikov and Boris Larin, state in a blog: “In February 2019, automatic exploit prevention (AEP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led us to the discovery of a vulnerability in win32k.sys.”
They add: “CVE-2019-0797 is a rare condition that exists in the win32k driver due to a lack of proper synchronization between the undocumented NtDCompositionDiscardFrame and NtDCompositionDestroyConnection systems.”
This is the fourth consecutive exploited Local Privilege Escalation vulnerability in Windows that Kaspersky has recently discovered.
Researchers believe that the identified exploit could be used by various threat actors, such as FruityArmor and SandCat.
