3 years, 9 months ago

Kaspersky reports that highly targeted attacks are using Microsoft Windows and Chrome zero-days

Experts at Kaspersky, earlier this year, had discovered several highly targeted attacks against multiple companies utilising a previously undiscovered chain of Microsoft Windows and Google Chrome zero-day exploits. The two exploited vulnerabilities in the Microsoft Windows OS kernel were Elevation of Privilege vulnerability CVE-2021-31956 and Information Disclosure vulnerability CVE-2021-31955. While Kaspersky researchers couldn’t retrieve remote execution code for the exploit, they suggested that attackers may have used CVE-2021-21224 vulnerability, related to a Type Mismatch bug in the V8. They also discovered and analysed the second exploit in the Microsoft Windows OS kernel which had two vulnerabilities.

Firstpost

Discover Related