Microsoft's patch for a zero-day privilege escalation Windows bug in June did not fix the vulnerability, which could still be exploited with some adjustments
Back in June, Microsoft released a fix for a vulnerability in the Windows operating system that enabled attackers to increase … Source: Google Project Zero .
The original issue was an arbitrary pointer dereference which allowed the attacker to control the src and dest pointers to a memcpy. The “fix” simply changed the pointers to offsets, which still allows control of the args to the memcpy.
In May, Kaspersky (@oct0xor) discovered CVE-2020-0986 in Windows splwow64 was exploited itw as a 0day. Microsoft released a patch in June, but that patch didnt fix the vuln. After reporting that bad fix in Sept under a 90day deadline, it's still not fixed. https://bugs.chromium.o…
A good question: What happens when incentives to fix vulnerabilities become internally misapplied or mistranslated (due, possibly, to competing internal incentives) and fail to solve the original problem? https://twitter.com/...
Google hackers disclose exploit for an UNPATCHED Windows #vulnerability (CVE-2020-0986) that was exploited as 0-day in the wild, for which #Microsoft issued an incomplete patch and then failed to patch it again under the 90-day deadline. Read — https://thehackernews.com/... #info…