logo

CISA warns of Microsoft Streaming bug exploited in malware attacks

ID: 7e9bb69e-9610-5798-9eb7-419dc3d52112

STIX ID: report--7e9bb69e-9610-5798-9eb7-419dc3d52112

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-03-01

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA directed U.S. federal agencies to urgently patch CVE-2023-29360, a Microsoft Streaming Service (MSKSSRV.SYS) local privilege escalation bug that can yield SYSTEM privileges; the flaw was patched in June 2023, a public PoC appeared in September, and CISA added it to its Known Exploited Vulnerabilities catalog. Check Point reported Raspberry Robin malware campaigns have exploited the vulnerability since August 2023, and organizations are advised to prioritize remediation to prevent active exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.