Another week, another report of Microsoft exploits revealed. We get more of these news than one gets app updates on their mobile device. Cybersecurity researchers have revealed two exploits that could possibly allow attackers to gain system privileges on Windows systems. Even ones that were patched. In the piece from TechSpot, mentioned three but one of which I discussed on this week’s Lazy Geeks podcast.
The first one is “Download More RAM”. This vulnerability allows one to bypass Windows 11 security, giving one system privileges without physically being at the terminal, which is usually the case. It accesses the system by exploiting the lack of write protection on consumer memory modules.
“The vulnerability allows anybody to remotely rewrite the Serial Presence Detect configuration chip that notifies the computer about the amount of installed RAM in the system,”TechSpot reports. “Attackers can take advantage of this vulnerability to transmit fake information to the computer, tricking it into believing that it has twice as much RAM installed as it actually does.”
It creates a backdoor into memory by getting around security and access control mechanisms used by the OS and processor. This exploit could allow a hacker to re-enable old drivers (with known exploits). Disable anti-malware software, and even bypass kernal-level anti-cheat systems used in video games among various others.
Two Windows exploits found, or just Monday
“Presented at DEF CON 34 in Las Vegas, the vulnerability can be exploited without admin privileges and without a logged-in user,” the site reports. “In their proof-of-concept demo, the researchers also showed that the attack can be performed remotely over RDP without connecting any physical USB hardware to the target device.”
Every day,it seems that more and more exploits with Windows systems are revealed. Microsoft hasn’t been very good at taking research firms claims seriously, they have to reveal them to the public. Yes, it pisses off Microsoft, in the case of the Shieldbreak exploit, which I covered in the podcast. Since Microsoft never took it seriously, there is no other way to get around it. As I said in the episode, when Microsoft said they wanted to win customers back. By make it better, they didn’t mean for you.
Leave a Reply