A security researcher posted an exploit for a recently fixed elevation of privilege issue in the Windows Telephony service with the identifier CVE-2024-26230. This vulnerability is with a CVSS score of 7. 8, presents a clear danger, whereby the attackers get SYSTEM privileges on the vulnerable systems in operation due to a use-after-free flaw in the telephony service. Vulnerability stems from the fact that the service is processing objects with the ‘‘GOLD’’ magic value and with the help of it creates a dangling pointer that can be successfully exploited to perform a use-after-free attack. The problem is located in the ClientRequest method of the Windows Telephony Service – the global variable “gaFuncs” is used to dispatch the requests. These functions describe and manipulate various objects; they are NewObject function that creates objects and inserts them into the Global Handle Table. But for the objects with the “GOLD” discriminant, the service that frees it does not properly verify if it belongs to the given context handle in order to free it. This oversight can be exploited by creating two context handles resulting in use-after free condition. A researcher k0shl of Cyber Kunlun created an exploit for this vulnerability and used a new approach for the bypassing of the eXtended Flow Guard (XFG) on Windows 11. The risk posed by exploiting this vulnerability is high, and after its exploitation the attacker gains full control over the affected system. With SYSTEM privileges, persons or groups with ill intentions can run any code of their choice including viruses, corrupt data as well as transfer bulky data outside the network without being intercepted, and create rootkits. Microsoft addressed this vulnerability in their April 2024 security updates.
A critical security vulnerability was discovered in Fortra's GoAnywhere Managed File Transfer (MFT) product, labeled CVE-2025-10035, with a CVSS score of 10.0. This is a bug ab...
Upscale jeweler Tiffany and Company has reported a data breach that exposed the personal data of 2,590 American customers. The breach included unauthorized access to an external sy...
A severe security flaw, CVE-2023-49564, has been found in Nokia's CloudBand Infrastructure Software (CBIS 22) and Nokia Container Services (NCS 22.12). The vulnerability, score...