Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Microsoft Raises Alarm for New Windows Zero-Day Attacks
securityweek.com ^ | 6/8/2021 | Ryan Naraine

Posted on 06/08/2021 6:31:19 PM PDT by bitt

Microsoft’s Patch Tuesday will take on extra urgency this month with the news that at least six previously undocumented vulnerabilities are being actively exploited in the wild.

Details on the active attacks are scarce but clues from some of Microsoft’s newest bulletins suggest these were part of extremely targeted APT malware campaigns.

Kaspersky zero-day hunter Boris Larin, who was credited with reporting two of the in-the-wild discoveries -- CVE-2021-31955 and CVE-2021-31956 -- says the attacks were part of a sophisticated cross-browser exploit chain that also hit flaws in Google’s flagship Chrome browser.

“These attacks exploited a chain of Google Chrome and Microsoft Windows zero-day exploits. While we were not able to retrieve the exploit used for remote code execution (RCE) in the Chrome web browser, we were able to find and analyze an elevation of privilege (EoP) exploit that was used to escape the sandbox and obtain system privileges,” Larin explained.

According to Kaspersky, the two Windows flaws were chained to an exploit for a different Chrome vulnerability to plant high-end malware on specific targets running Windows. Kaspersky’s researchers believe they have traced the issue to a Chrome vulnerability that was shared -- and patched -- following the 2021 Pwn2Own marketing event.

In addition to the two flaws documented by Kaspersky, Microsoft is also calling urgent attention to CVE-2021-33739, CVE-2021-33742, CVE-2021-31199 and CVE-2021-31201, warning that all six of these bugs have been targeted by attackers before the availability of patches.

(Excerpt) Read more at securityweek.com ...


TOPICS:
KEYWORDS: microsoft; windows; windows10; windowspinglist; zerodayattacks
Navigation: use the links below to view more comments.
first 1-2021-28 next last

1 posted on 06/08/2021 6:31:19 PM PDT by bitt
[ Post Reply | Private Reply | View Replies]

To: dayglored; ShadowAce; Whenifhow; null and void; aragorn; EnigmaticAnomaly; kalee; Kale; ...

P


2 posted on 06/08/2021 6:32:05 PM PDT by bitt ( A murderer is less to fear. The traitor is the plague.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt

I hope someone translates this into techtard/ooga booga talk.


3 posted on 06/08/2021 7:06:51 PM PDT by little jeremiah (Mercy to the cruel is cruelty to the innocent)
[ Post Reply | Private Reply | To 2 | View Replies]

To: bitt

Translation: Use a browser with a very low user share that hackers won’t bother exploiting.


4 posted on 06/08/2021 7:11:33 PM PDT by KevinB (''... and to the Banana Republic for which it stands ...")
[ Post Reply | Private Reply | To 1 | View Replies]

To: KevinB

Demorats are setting us up for the internet blackout and blaming it on attacks by others because once the audit(s) are finished and leaks start coming out, they will want to shut the information train down.


5 posted on 06/08/2021 7:19:26 PM PDT by GYPSY286
[ Post Reply | Private Reply | To 4 | View Replies]

To: little jeremiah

Translation: “All your bank account are belong to us.”


6 posted on 06/08/2021 7:24:57 PM PDT by ProtectOurFreedom (“Investigating payoffs and corruption is a crime, but payoffs and corruption are not.” -- Democrats)
[ Post Reply | Private Reply | To 3 | View Replies]

To: bitt

Microsoft? Support Gates Inc?

No thanks.

I wish I could remember the last time my Mac had to update for “security” reasons.


7 posted on 06/08/2021 7:27:43 PM PDT by datura
[ Post Reply | Private Reply | To 1 | View Replies]

To: ProtectOurFreedom

Ah, that I can understand. I don’t do online banking; amisafe?


8 posted on 06/08/2021 7:32:13 PM PDT by little jeremiah (Mercy to the cruel is cruelty to the innocent)
[ Post Reply | Private Reply | To 6 | View Replies]

To: little jeremiah

Does anybody really know what time it is?


9 posted on 06/08/2021 8:03:58 PM PDT by ProtectOurFreedom (“Investigating payoffs and corruption is a crime, but payoffs and corruption are not.” -- Democrats)
[ Post Reply | Private Reply | To 8 | View Replies]

To: ProtectOurFreedom

“Does anybody really know what time it is?”
-
25 or 6 to 4.


10 posted on 06/08/2021 8:18:40 PM PDT by Repeal The 17th (Get out of the matrix and get a real life.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: bitt

Hypothetically, what would need to happen for use of Microsoft software being used for anything critical to be properly viewed as a national security vulnerability?


11 posted on 06/08/2021 8:44:27 PM PDT by coloradan (They're not the mainstream media, they're the gaslight media. It's what they do. )
[ Post Reply | Private Reply | To 1 | View Replies]

To: Repeal The 17th

We are dating ourselves! ;>)


12 posted on 06/08/2021 9:33:38 PM PDT by ProtectOurFreedom ("Pour les vaincre il faut de l'audace, encore de l'audace, toujours de l'audace")
[ Post Reply | Private Reply | To 10 | View Replies]

To: bitt

I wonder if any of these issues are the cause of the problems that started in my laptop last Sunday. I’m getting lots of warning windows saying, “Windows Defender has blocked this program ...” Also, I have lost use of the taskbar on the bottom of the screen - no volume control, no search, no response to Start button.

I took it to Staples today for analysis. They couldn’t find problem; suggested a new computer and warned against trying to recover my files to load onto new unit. I see a memorial service in the near future for my Toshiba Satellite (sigh).


13 posted on 06/08/2021 9:33:49 PM PDT by mouske
[ Post Reply | Private Reply | To 1 | View Replies]

To: bitt; Abby4116; afraidfortherepublic; aft_lizard; AF_Blue; AppyPappy; arnoldc1; ATOMIC_PUNK; ...
Windows 10 Update... PING!

You can find all the Windows Ping list threads with FR search: just search on keyword "windowspinglist".

Thanks to bitt for the ping!

14 posted on 06/08/2021 9:39:11 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 2 | View Replies]

To: little jeremiah

A better translation: “All American homes need a real firewall and dump the brainless ones being used.”


15 posted on 06/08/2021 9:42:04 PM PDT by Zathras
[ Post Reply | Private Reply | To 3 | View Replies]

To: KevinB
> Translation: Use a browser with a very low user share that hackers won’t bother exploiting.

One of the reasons I use Firefox by default, and the others only when necessary.

16 posted on 06/08/2021 9:44:47 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 4 | View Replies]

To: datura
> I wish I could remember the last time my Mac had to update for “security” reasons.

As a fellow Mac user, may I respectfully suggest that you aren't paying enough attention, or perhaps have notifications turned off. MacOS gets security updates fairly regularly. Not as often as Windows, but that's in part because Apple batches them up after a couple months instead of the second Tuesday of every month. MacOS updates are usually big because they wrap a lot of fixes into them.

Please don't fall into complacency just because you aren't running Windows. MacOS and Linux aren't flawless -- all software, all operating systems, all applications, all have security issues.

17 posted on 06/08/2021 9:52:07 PM PDT by dayglored ("Listen. Strange women lying in ponds distributing swords is no basis for a system of government.")
[ Post Reply | Private Reply | To 7 | View Replies]

To: Repeal The 17th

[[“Does anybody really know what time it is?”
-
25 or 6 to 4.]]

i coulda swore it was blue- but what do i know? I don’t even know what time it is


18 posted on 06/08/2021 10:00:39 PM PDT by Bob434
[ Post Reply | Private Reply | To 10 | View Replies]

To: mouske

If you get a new one, don’t trash the one you have now, upgrade it to Linux ;)


19 posted on 06/09/2021 1:56:33 AM PDT by Bikkuri (If you're conservative, you're an "extremist." If you're liberal, you're an "activist.")
[ Post Reply | Private Reply | To 13 | View Replies]

To: bitt

“Networked computers? That’s a thing?” — Bill Gates


20 posted on 06/09/2021 2:07:51 AM PDT by martin_fierro (< |:)~)
[ Post Reply | Private Reply | To 1 | View Replies]


Navigation: use the links below to view more comments.
first 1-2021-28 next last

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson