• HOME
  • CODE RED
    • Red Teaming On-Demand
  • ASSURED
    • Continuous Intelligence-Led Penetration Testing
  • CyberSOC MTDR
    • Managed Threat Detection And Response (MTDR)
  • CUSTOMER LOGIN
    • e-Support Security Intelligence Dashboard
Kobalos Malware Targets High Performance Computer (HPC) Clusters
February 9, 2021
Multiple WordPress Plugin Vulnerabilities Affected One Million Websites
February 23, 2021
Published by PenTestBox™ CODE RED at February 17, 2021
Categories
  • Compliance
  • Security
Tags

Image credit by Pixabay

VTA-00358 – CVE-2021-1732: Local Privileges Escalation Vulnerability On Windows Win32k:

SuperPRO’s Recommendations:
1. Update to latest patch accordingly for Windows OS and Windows 2019 servers by referring to this link.
(https://msrc.microsoft.com/update guide/vulnerability/CVE-2021-1732).
2. Keep Microsoft Defender up to date.
3. Configure the IOC information provided below into your current network, perimeter and endpoint threat defense mechanisms e.g. Endpoint Advanced Threat Protection (ATP),  Network Firewall, Web Application Firewall (WAF), Email and Web Content Filtering Policies, where applicable.
4. To download and install OTX Endpoint Security. Subscribe to Provintell-Lab’s OTX pulses and scan endpoints for the presence of IOCs

The Story:

Microsoft has released a security advisory which is related to Microsoft Win32k under CVE-2021-1732. By exploiting this vulnerability, the attacker can take control of an infected system locally by privilege escalation. This vulnerability can let non-admin user to elevate themselves with system-level access.

Severity:
High

Attack Surfaces:
Endpoint OS

Tactics:
Privilege Escalation

Techniques:
Exploitation for Privilege Escalation

Indicator of Compromise (IOC) Detection:
https://otx.alienvault.com/pulse/60231c157099f297e915730a

References:
https://us-cert.cisa.gov/ncas/current-activity/2021/02/09/microsoft-warns-windows win32k-privilege-escalation

Contributed by: Mr22k

Share
0
PenTestBox™ CODE RED
PenTestBox™ CODE RED

Related posts

Image credit by Pixabay

February 9, 2021

Kobalos Malware Targets High Performance Computer (HPC) Clusters


Read more

Image credit by Pixabay

February 3, 2021

Pro-Ocean Cryptojacking Malware


Read more

Image credit by Pixabay

February 2, 2021

Zoom Phishing Email


Read more

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Quick Links

+ Home
+ PenTestBox™ CODE RED
+ PenTestBox™  ASSURED
+ CyberSOC MTDR
+ Join Us
+ Privacy Policy

PROVINTELL TECHNOLOGIES SDN BHD
PROVINTELL LAB SDN BHD

Block F, Unit 68-2,
Zenith Corporate Park, Jalan SS7/26,
47301 Petaling Jaya,
Selangor. Malaysia.
+603-7661 0891
+603-7661 0897
[email protected]

© 2021 All Rights Reserved, By Provintell Technologies Sdn Bhd.