It appears you have not yet registered with our community. To register please click here...

 
Go Back [M] > Madshrimps > WebNews
Ancient driver bug could hit Windows machines Ancient driver bug could hit Windows machines
FAQ Members List Calendar Search Today's Posts Mark Forums Read


Ancient driver bug could hit Windows machines
Reply
 
Thread Tools
Old 23rd July 2021, 07:44   #1
[M] Reviewer
 
Stefan Mileschin's Avatar
 
Join Date: May 2010
Location: Romania
Posts: 153,575
Stefan Mileschin Freshly Registered
Default Ancient driver bug could hit Windows machines

High severity

Insecurity experts have released technical details on a high-severity privilege-escalation flaw in HP printer drivers - also used by Samsung and Xerox, which impacts hundreds of millions of Windows machines.

If exploited, cyberattackers could bypass security products; install programs; view, change, encrypt or delete data; or create new accounts with more extensive user rights, become elected US president.

The bug known by CVE-2021-3438 or just 3438 to its mates, has been installed for more than 16 years and never caused anyone any problems. However, researchers at SentinelOne uncovered it this year and it now carries an 8.8 out of 10 rating on the CVSS scale, making it high-severity.

According to researchers, the vulnerability exists in a function inside the driver that accepts data sent from User Mode via Input/Output Control (IOCTL); it does so without validating the size parameter. As the name suggests, IOCTL is a system call for device-specific input/output operations. "This function copies a string from the user input using 'strncpy' with a size parameter that is controlled by the user", according to SentinelOne's analysis, released on Tuesday. "Essentially, this allows attackers to overrun the buffer used by the driver." Thus, unprivileged users can elevate themselves into a SYSTEM account, allowing them to run code in kernel mode, since the vulnerable driver is locally available to anyone, according to the firm.

https://fudzilla.com/news/53265-anci...ndows-machines
Stefan Mileschin is offline   Reply With Quote
Reply


Similar Threads
Thread Thread Starter Forum Replies Last Post
Windows 10 used on 900 million machines Stefan Mileschin WebNews 0 26th September 2019 16:38
Windows 10 update machines is churning out more bugs Stefan Mileschin WebNews 0 30th November 2018 14:51
Windows metadata bug has been waiting to cripple older machines Stefan Mileschin WebNews 0 29th May 2017 10:24
Windows 10 on nearly a quarter of machines Stefan Mileschin WebNews 0 4th January 2017 20:47
Ancient Windows printer flaw exposes you to malware Stefan Mileschin WebNews 0 15th July 2016 08:36
Steam Machines are slower gaming systems than Windows PCs Stefan Mileschin WebNews 0 16th November 2015 08:40
Windows has the ancient hole from hell Stefan Mileschin WebNews 0 14th April 2015 12:13
NVIDIA Releases 296.10 GeForce Driver, Introduces Windows 8 Driver Support Stefan Mileschin WebNews 0 14th March 2012 08:59
Run XP Mode on Windows 7 Machines Without Hardware Virtualization jmke WebNews 0 17th February 2010 16:35
Convert Physical Machines to Virtual Machines for Free jmke WebNews 0 31st January 2007 15:59

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off


All times are GMT +1. The time now is 16:26.


Powered by vBulletin® - Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO