Microsoft

Extend Rights: Microsoft Messed Up Security Update

According to its own information, Microsoft fixed a bug with June Patch Day that could be used by unauthorized persons to extend rights. Now, however, the researcher who discovered the vulnerability reports that the fix is ​​incomplete.

The security gap is about the possible bypassing of security functions of Windows TCP/IP drivers, whereby an attacker would be able to assign further rights to himself and then, for example, load any malicious code onto his victim’s system. The vulnerability is based on a local attack vector with little chance of exploitation, so an attacker must first have direct access to a PC. However, such a problem should not remain unfixed.

Patch is available

The vulnerability was reported to Microsoft by Google Project Zero on March 24th. The company finally confirmed that the June 8 patch update rolled out a fix. Details on the vulnerability can be found in CVE-2021-31970, where Microsoft also appreciates the Google Project Zero report. At the same time, it was confirmed that it is a local attack vector on various operating systems, including Windows 8.1, Windows 10, and Windows Server 2016.

In further investigations of the available update, however, the researcher James Forshaw found that the patch mitigates the exploit of the proof of concept (PoC), but does not really fix the underlying problem and is, therefore, incomplete reports Neowin. The security researcher simply developed a new PoC to show that the exploit is still possible and reported it again to Microsoft on June 18. Since the original 90-day period expired on June 23 without the bug being fully resolved, the exploit is now being published.

Recent Posts

Navigating the Digital Frontier: How Mobile Proxy Infrastructure Empowers Modern Technology Journalism and Enterprise Data Mining

For tech analysts, software engineers, and digital journalists tracking real-time market shifts on platforms like…

5 hours ago

Decoupling Digital Identity: How Modern App Ecosystems Rely on Virtual Telecommunications Architecture

Modern mobile security models treat phone numbers as default digital passports, forcing tech consumers and…

6 hours ago

Top Extended Detection and Response Platforms for Large Enterprises: A Vendor Comparison Guide

Large enterprises have a lot of security data, but identifying the signals that truly matter…

6 hours ago

5 Lab Methods Scientists Use to Find What’s Really in Tap Water

A glass of tap water reveals little about its chemical makeup. Clear water may still…

1 day ago

Medical Technology Leadership Programs and Industry Collaborators: The Essential Resource Roundup

In today’s healthcare landscape, collaboration between academic programs and corporate leaders fuels both technological innovation…

2 days ago

Smartphone ban: Italy will soon pay for distracted pedestrians

Italy is cracking down on cell phone use in traffic and will soon be targeting…

2 days ago