| Thread Tools |
23rd July 2021, 07:44 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,575
| Ancient driver bug could hit Windows machines High severity Insecurity experts have released technical details on a high-severity privilege-escalation flaw in HP printer drivers - also used by Samsung and Xerox, which impacts hundreds of millions of Windows machines. If exploited, cyberattackers could bypass security products; install programs; view, change, encrypt or delete data; or create new accounts with more extensive user rights, become elected US president. The bug known by CVE-2021-3438 or just 3438 to its mates, has been installed for more than 16 years and never caused anyone any problems. However, researchers at SentinelOne uncovered it this year and it now carries an 8.8 out of 10 rating on the CVSS scale, making it high-severity. According to researchers, the vulnerability exists in a function inside the driver that accepts data sent from User Mode via Input/Output Control (IOCTL); it does so without validating the size parameter. As the name suggests, IOCTL is a system call for device-specific input/output operations. "This function copies a string from the user input using 'strncpy' with a size parameter that is controlled by the user", according to SentinelOne's analysis, released on Tuesday. "Essentially, this allows attackers to overrun the buffer used by the driver." Thus, unprivileged users can elevate themselves into a SYSTEM account, allowing them to run code in kernel mode, since the vulnerable driver is locally available to anyone, according to the firm. https://fudzilla.com/news/53265-anci...ndows-machines |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Windows 10 used on 900 million machines | Stefan Mileschin | WebNews | 0 | 26th September 2019 16:38 |
Windows 10 update machines is churning out more bugs | Stefan Mileschin | WebNews | 0 | 30th November 2018 14:51 |
Windows metadata bug has been waiting to cripple older machines | Stefan Mileschin | WebNews | 0 | 29th May 2017 10:24 |
Windows 10 on nearly a quarter of machines | Stefan Mileschin | WebNews | 0 | 4th January 2017 20:47 |
Ancient Windows printer flaw exposes you to malware | Stefan Mileschin | WebNews | 0 | 15th July 2016 08:36 |
Steam Machines are slower gaming systems than Windows PCs | Stefan Mileschin | WebNews | 0 | 16th November 2015 08:40 |
Windows has the ancient hole from hell | Stefan Mileschin | WebNews | 0 | 14th April 2015 12:13 |
NVIDIA Releases 296.10 GeForce Driver, Introduces Windows 8 Driver Support | Stefan Mileschin | WebNews | 0 | 14th March 2012 08:59 |
Run XP Mode on Windows 7 Machines Without Hardware Virtualization | jmke | WebNews | 0 | 17th February 2010 16:35 |
Convert Physical Machines to Virtual Machines for Free | jmke | WebNews | 0 | 31st January 2007 15:59 |
Thread Tools | |
| |