CISA has added a serious Windows kernel to the List of Known Exploitable Vulnerabilities (KEV).

CISA is warning federal agencies to secure their systems against a serious Windows kernel vulnerability, which is already being used in attacks.
The vulnerability is tracked as CVE-2024-35250 and allows local attackers to gain SYSTEM privileges, in the context of low-sophistication attacks that do not require user interaction.
See also: Vulnerabilities in Mullvad VPN allow hackers to execute malicious code
Microsoft had released a security advisory for the vulnerability in June, but it did not provide many details. The DEVCORE, which found the vulnerability and reported it to Microsoft, explains that the vulnerable system component is the Microsoft Kernel Streaming Service (MSKSSRV.SYS).
On the first day of this year's Pwn2Own Vancouver hacking competition , security researchers at DEVCORE used a vulnerability in the Windows kernel to compromise a fully updated Windows 11 system.
Microsoft fixed the bug with the release of Patch Tuesday June 2024.Four months later, a proof-of-concept exploit was released on GitHub.
"An attacker who successfully exploited this vulnerability could gain SYSTEM privileges," Microsoft said.
DEVCORE has published a video demo of the proof-of-concept exploit it used to hack a Windows 11 23H2 device.
See also: Vulnerability in Curl allows hackers to access sensitive data
CISA added the vulnerability to its list of known exploitable vulnerabilities and is urging federal agencies to secure their networks within three weeks, specifically by January 6.

While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching this vulnerability.
The KEV catalog is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.
Overall, CISA is a great help in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, governments , and local authorities, to improve the security of digital systems.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
See also: Critical vulnerabilities in Dell products allow compromise
The exploitation of the above Windows kernel vulnerability highlights the importance of regular updates and implementing additional security measures. These measures include strong and unique passwords for all accounts, antivirus programs, backups of important data, firewalls, VPNs, intrusion prevention systems, etc.
Source: www.bleepingcomputer.com
