Tag

#Privilege Escalation

20 published stories tagged with Privilege Escalation.

highExploited VulnerabilitiesAug 12, 2026·4 min read

Lazarus Group exploits Windows kernel vulnerability to escalate privileges via fake job offers

Lazarus Group is exploiting a Windows kernel vulnerability to escalate privileges and deploy backdoors via fake job offers.

highExploited VulnerabilitiesAug 11, 2026·2 min read

Critical Windows kernel flaw exploitation drives massive Microsoft security patch release

Microsoft has released a massive update addressing 398 security flaws, including one critical vulnerability currently being exploited in the wild.

highExploited VulnerabilitiesAug 11, 2026·2 min read

Reduced safeguards in OpenAI's new GPT-5.6-Cyber model facilitate easier exploit development

Attackers are increasingly using exposed identities to navigate through complex network environments, moving from one domain to another via privilege escalation.

highData BreachesAug 10, 2026·2 min read

Attackers exploit identity choke points to escalate privileges and traverse security domains

Identity exposure is creating new ways for attackers to move between different environments. By targeting specific choke points, actors can escalate privileges across domains.

highAPT / Nation-StateAug 10, 2026·2 min read

Exploiting TrueConf vulnerabilities allows attackers to replace legitimate installers with malicious files

Security researchers have identified a specific pattern of activity involving the threat actor Head Mare, which targets flaws within TrueConf software.

highData BreachesAug 7, 2026·2 min read

Mapping identity exposure pathways reveals critical choke points for cross-domain lateral movement

Identity exposure is creating new ways for attackers to move between different security domains.

highExploited VulnerabilitiesAug 6, 2026·2 min read

Adversaries can manipulate LLM memory by poisoning recommendation data via Ask AI buttons

Attackers are increasingly exploiting gaps in identity management to facilitate cross-domain privilege escalation.

criticalExploited VulnerabilitiesAug 4, 2026·2 min read

Authenticated users can escalate privileges to administrative control via cPanel database renaming flaw

An authenticated user can escalate privileges to full administrative control within cPanel and WHM by exploiting a flaw in database renaming.

highDefensive GuidanceJul 22, 2026·2 min read

Local users could gain root privileges on Ubuntu desktop systems via snap-confine flaw

A flaw discovered in `snap-confine`, a core component used by Canonical's `snapd`, enables local attackers to bypass security sandboxes.

highExploited VulnerabilitiesJul 21, 2026·3 min read

Non-admin users can escalate privileges to administrator via Windows User Profile Service flaw

A zero-day vulnerability in the Windows User Profile Service, dubbed LegacyHive, allows non-admin users to escalate privileges to administrative levels.

highVulnerabilityMay 8, 2026·4 min read

Brief: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation

Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.

highVulnerabilityMay 8, 2026·4 min read

Defender Guidance: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation

Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.

highVulnerabilityMay 8, 2026·4 min read

Detection Notes: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation

Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.

highVulnerabilityMay 8, 2026·4 min read

Risk Brief: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation

Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.

highVulnerabilityMay 8, 2026·4 min read

Brief: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160

NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.

highVulnerabilityMay 8, 2026·4 min read

Defender Guidance: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160

NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.

highVulnerabilityMay 8, 2026·4 min read

Detection Notes: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160

NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.

highVulnerabilityMay 8, 2026·4 min read

Risk Brief: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160

NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.

criticalVulnerabilityMay 8, 2026·8 min read

CVE-2026-31431 Copy Fail Linux Kernel Flaw Enables Local Root Privilege Escalation

CVE-2026-31431 is a high-impact Linux kernel privilege escalation vulnerability affecting algif_aead. Defenders should patch kernels, apply vendor mitigations, and prioritize shared systems and container hosts.

highVulnerabilityMay 8, 2026·4 min read

NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160

NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\\SYSTEM through registry manipulation.