ESET Research
ESET Research
@ESETresearch
Sep 13 • 2 months ago • 4 tweets • Read on X
AI Summary

A new Windows security flaw, found in Windows 8.1 and Server 2012 R2, allows hackers to get higher access levels. It was used in the wild since March 2023 through backdoors. The issue is a use-after-free bug in the Win32k driver, caused by a tricky race condition. Microsoft just released patches to fix it.

has discovered a zero day exploit abusing -2025-24983 vulnerability in Windows Kernel to elevate privileges (). First seen in the wild in March 2023, the exploit was deployed through backdoor on the compromised machines. 1/4

Tweet image 1

The exploit targets Windows 8.1 and Server 2012 R2. The vulnerability affects OSes released before Windows 10 build 1809, including still supported Windows Server 2016. It does not affect more recent Windows OSes such as Windows 11. 2/4

The vulnerability is a use after free in Win32k driver. In a certain scenario achieved using the API, the structure gets dereferenced one more time than it should, causing UAF. To reach the vulnerability, a race condition must be won. 3/4

The patches were released today. Microsoft advisory with security update details is available here: 4/4

Missing some Tweet in this thread? You can try to Update

More Threads by @ESETresearch

A new AI-powered ransomware called PromptLock has been found. It uses OpenAI's GPT model locally to create malicious scr...
6 tweets • 3 months ago
Read Thread
This thread reveals Operation AkaiRyū, a new cyberattack targeting Europe, especially involving diplomatic groups linke...
8 tweets • 4 months ago
Read Thread

Unroll Another Thread

Convert any Twitter threads to an easy-to-read article instantly

Have you tried our Twitter bot?

You can now unroll any thread without leaving Twitter/X. Here's how to use our Twitter bot to do it.

  • Give us a follow on Twitter. follow us
  • Drop a comment, mentioning us @unrollnow on the thread you want to Unroll.
  • Wait For Some Time, We will reply to your comment with Unroll Link.
UnrollNow Twitter Bot
Modal Image
0:00 / 0:00