A patched Windows attack surface is still exploitable
ID: b98ea859-3cff-511a-b134-f84b8b8a5f75
STIX ID: report--b98ea859-3cff-511a-b134-f84b8b8a5f75
Feed Name: Securelist by Kaspersky
Date Published: 2024-03-14
Date Updated: 2026-04-29
Author: Elsayed Elrefaei, Ashraf Refaat, Kaspersky GERT
This report analyzes a class of Windows local privilege‑escalation vulnerabilities (multiple CVEs including CVE‑2022‑22047, CVE‑2022‑37989, CVE‑2022‑29104, CVE‑2022‑41073, CVE‑2023‑36874, CVE‑2023‑35359) that abuse impersonation and the device map to remap the system root (C:\) to a writable ‘fake’ root, allowing unprivileged accounts to gain NT AUTHORITY\SYSTEM; it documents in‑the‑wild PoCs and packed exploits, affected services (CSRSS, WER, BITS, File History, Print Spooler), patch mitigations (changes to ObpLookupObjectName/ObpUseSystemDeviceMap and stopping impersonation before loading external resources), and practical detection indicators such as writable C:\-mirror folders, modified WinSxS manifests (LoadFrom or path traversal), and created symbolic links under RPC Control.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
