HomeSecurityMalware tries to exploit new Windows Installer zero-day

Malware tries to exploit new Windows Installer zero-day

Malicious actors have already begun testing a proof-of-concept exploit targeting a new Microsoft Windows Installer zero-day, which was publicly disclosed by security researcher Abdelhamid Naceri over the weekend.

Windows Installer

See also: Patch released for Microsoft Exchange RCE exploit

“Talos has already identified malware samples that attempt to exploit this vulnerability,” said Jaeson Schultz, Technical Lead for Cisco's Talos Security Intelligence & Research Group.

However, according to Nick Biasini, head of Outreach at Cisco Talos, these exploit attempts are part of low-volume attacks, likely focused on exploit testing and adaptations.

"During our research, we examined recent malware samples and were able to identify several that were already attempting to leverage the exploit," Biasini said.

«Given the low volume, these are likely people working on proof of concept code or testing it for future campaigns. This is just further evidence of how quickly attackers work to exploit a publicly available exploit.»

The vulnerability in question is a local privilege escalation bug that was found as a workaround in a patch that Microsoft during Patch Tuesday for November 2021, to address a flaw identified as CVE-2021-41379.

See also: New Windows zero-day allows administrator privileges

zero day

On Sunday, Naceri published a working proof-of-concept exploit for this new zero-day, saying it works on all supported versions of Windows.

If successfully exploited, this bypass gives attackers SYSTEM privileges on updated devices running the latest versions of Windows, including Windows 10, Windows 11, and Windows Server 2022.

SYSTEM privileges are the highest user rights available to Windows users and make it possible to execute any operating system command.

By exploiting this flaw, attackers with limited access to compromised systems can easily escalate their privileges to achieve lateral spread within the victim's network.

See also: FBI: Sophisticated group exploits a zero-day in FatPipe VPNs

A Microsoft spokesperson said the following regarding the issue: "We are aware of the disclosure and will do whatever is necessary to keep our customers safe and protected. An attacker using the methods described would already have access and the ability to execute code on the targeted victim's computer."

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS