Windows kernel bug now exploited in attacks to gain SYSTEM privileges
ID: 42a1dc02-b240-5caa-8871-84f6a58a25a8
STIX ID: report--42a1dc02-b240-5caa-8871-84f6a58a25a8
Feed Name: Bleeping Computer
Threat Score
CISA has added two actively exploited, high-severity vulnerabilities to its Known Exploited Vulnerabilities catalog: CVE-2024-35250, a Windows kernel privilege-escalation in MSKSSRV.SYS (used in a Pwn2Own demonstration and patched by Microsoft), and CVE-2024-20767, an Adobe ColdFusion unauthenticated path traversal/RCE with public proof-of-concept code and many internet-exposed servers; federal agencies are mandated to apply mitigations under BOD 22-01.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
