Kaspersky finds zero-day exploit in Windows OS used in targeted attack
The exploit based on this vulnerability allowed attackers to gain higher privileges on the attacked machine and avoid protection mechanisms in the Google Chrome browser.
Zero-day vulnerabilities are previously unknown bugs in the software, which, if found by criminals first, enable them to operate unnoticed for a long time, inflicting serious and unexpected damage. Regular security solutions do not identify the system infection nor can they protect users from a yet-to-be-recognized threat.
The new Windows vulnerability was found by Kaspersky researchers thanks to yet another zero-day exploit. Back in November 2019, Kaspersky’s Exploit Prevention technology, which is embedded in most of the company’s products, was able to detect a zero-day exploit in Google Chrome. This exploit allowed attackers to execute arbitrary code on a victim’s machine. Upon further research of this operation, which the experts called ‘WizardOpium’, another vulnerability was discovered, this time in Windows OS.
It emerged that the newly discovered Windows zero-day elevation of privileges (EoP) exploit (CVE-2019-1458) was embedded into a previously discovered Google Chrome exploit. It was used to gain higher privileges in the infected machine as well as to escape the Chrome process sandbox – a component built to protect the browser and the victim’s computer from malicious attacks.
Detailed analysis of the EoP exploit showed that the abused vulnerability belongs to the win32k.sys driver. The vulnerability could be abused on the latest patched versions of Windows 7 and even on a few builds of Windows 10 (new versions of Windows 10 have not been affected).
“This type of attack requires vast resources; however, it gives significant advantages to the attackers and as we can see, they are happy to exploit it. The number of zero-days in the wild continues to grow and this trend is unlikely to go away. Organizations need to rely on the latest threat intelligence available at hand and have protective technologies that can proactively find unknown threats such as zero-day exploits”, – comments Anton Ivanov, security expert at Kaspersky.
Kaspersky products detect this exploit with next verdict PDM:Exploit.Win32.Generic.The vulnerability was reported to Microsoft and patched on December 10, 2019.