CISA warns of Microsoft Streaming bug exploited in malware attacks
ID: 7e9bb69e-9610-5798-9eb7-419dc3d52112
STIX ID: report--7e9bb69e-9610-5798-9eb7-419dc3d52112
Feed Name: Bleeping Computer
CISA directed U.S. federal agencies to urgently patch CVE-2023-29360, a Microsoft Streaming Service (MSKSSRV.SYS) local privilege escalation bug that can yield SYSTEM privileges; the flaw was patched in June 2023, a public PoC appeared in September, and CISA added it to its Known Exploited Vulnerabilities catalog. Check Point reported Raspberry Robin malware campaigns have exploited the vulnerability since August 2023, and organizations are advised to prioritize remediation to prevent active exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
