logo

Windows kernel bug now exploited in attacks to gain SYSTEM privileges

ID: 42a1dc02-b240-5caa-8871-84f6a58a25a8

STIX ID: report--42a1dc02-b240-5caa-8871-84f6a58a25a8

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2024-12-16

Date Updated: 2026-03-27

Author: Sergiu Gatlan

...
...

CISA has added two actively exploited, high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2024-35250, a Windows kernel privilege-escalation in MSKSSRV.SYS (used in a Pwn2Own demonstration and patched by Microsoft), and CVE-2024-20767, an Adobe ColdFusion unauthenticated path traversal/RCE with public proof-of-concept code and many internet-exposed servers; federal agencies are mandated to apply mitigations under BOD 22-01.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.