A critical vulnerability has been identified in the Bonjour service, specifically mDNSResponder.exe , which is used in privilege escalation attacks. This vulnerability affects both macOS and Windows systems , potentially allowing attackers to escalate privileges on a targeted system.
See also: Atlassian Confluence vulnerability used for crypto-mining attacks

Bonjour, a zero-configuration networking protocol developed by Apple, uses Multicast DNS (mDNS) to facilitate the discovery of devices and services on local networks.
The vulnerability in Bonjour arises from the way this service handles certain network requests, allowing privilege escalation attacks. An attacker could exploit this weakness by crafting malicious network requests targeting the mDNSResponder service, potentially gaining unauthorized access to higher privilege levels on the system.
The vulnerability can be exploited remotely, as it does not require prior authentication. Attackers can manipulate the service to escalate privileges by sending specially crafted multicast DNS queries, according to analysis by SecureLayer7. This makes the vulnerability particularly dangerous, as it can be executed without any initial access to the system.
See also: Traccar GPS: Vulnerabilities allow remote attacks
The exploit involves sending a malicious mDNS query payload that takes advantage of the service's mishandling of incoming requests.

The execution flow is simple: The attacker sends the malicious query to the mDNSResponder, which processes it incorrectly, potentially leading to the execution of arbitrary code with elevated privileges.
The consequences of exploiting this vulnerability could be serious. An attacker with elevated privileges could:
- It has access to sensitive data, bypassing security measures.
- Modify critical system settings, causing possible system outages.
- Develop further attacks within the network, using the compromised system as a base.
See also: Xeon Sender: New tool for SMS phishing and spam attacks
Privilege escalation attacks, such as in the case of Bonjour, are a type of cyber threat where an attacker gains increased access to resources normally protected by an application or user. These attacks typically come in two main forms: vertical and horizontal escalation. In vertical escalation, the attacker exploits vulnerabilities to gain higher privileges, such as a simple user gaining administrative privileges. In contrast, horizontal escalation involves an attacker exploiting flaws to gain access to the privileges of other users without gaining additional privileges. Mitigating the risk of privilege escalation attacks requires strong security measures, including regular software updates, diligent patch management, and strict access control policies to limit unnecessary privilege grants.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
