Tag
#privilege escalation
20 published stories tagged with privilege escalation.
Lazarus Group exploits Windows kernel vulnerability to escalate privileges via fake job offers
Lazarus Group is exploiting a Windows kernel vulnerability to escalate privileges and deploy backdoors via fake job offers.
Critical Windows kernel flaw exploitation drives massive Microsoft security patch release
Microsoft has released a massive update addressing 398 security flaws, including one critical vulnerability currently being exploited in the wild.
Reduced safeguards in OpenAI's new GPT-5.6-Cyber model facilitate easier exploit development
Attackers are increasingly using exposed identities to navigate through complex network environments, moving from one domain to another via privilege escalation.
Attackers exploit identity choke points to escalate privileges and traverse security domains
Identity exposure is creating new ways for attackers to move between different environments. By targeting specific choke points, actors can escalate privileges across domains.
Exploiting TrueConf vulnerabilities allows attackers to replace legitimate installers with malicious files
Security researchers have identified a specific pattern of activity involving the threat actor Head Mare, which targets flaws within TrueConf software.
Mapping identity exposure pathways reveals critical choke points for cross-domain lateral movement
Identity exposure is creating new ways for attackers to move between different security domains.
Adversaries can manipulate LLM memory by poisoning recommendation data via Ask AI buttons
Attackers are increasingly exploiting gaps in identity management to facilitate cross-domain privilege escalation.
Authenticated users can escalate privileges to administrative control via cPanel database renaming flaw
An authenticated user can escalate privileges to full administrative control within cPanel and WHM by exploiting a flaw in database renaming.
Local users could gain root privileges on Ubuntu desktop systems via snap-confine flaw
A flaw discovered in `snap-confine`, a core component used by Canonical's `snapd`, enables local attackers to bypass security sandboxes.
Non-admin users can escalate privileges to administrator via Windows User Profile Service flaw
A zero-day vulnerability in the Windows User Profile Service, dubbed LegacyHive, allows non-admin users to escalate privileges to administrative levels.
Brief: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation
Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.
Defender Guidance: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation
Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.
Detection Notes: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation
Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.
Risk Brief: Acer PredatorSense Named Pipe Misconfiguration Enables SYSTEM Privilege Escalation
Acer PredatorSense versions 3.00.3136 through 3.00.3196 contain a local privilege escalation vulnerability caused by a misconfigured Windows named pipe.
Brief: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160
NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.
Defender Guidance: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160
NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.
Detection Notes: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160
NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.
Risk Brief: NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160
NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\SYSTEM through registry manipulation.
CVE-2026-31431 Copy Fail Linux Kernel Flaw Enables Local Root Privilege Escalation
CVE-2026-31431 is a high-impact Linux kernel privilege escalation vulnerability affecting algif_aead. Defenders should patch kernels, apply vendor mitigations, and prioritize shared systems and container hosts.
NAVER MYBOX Explorer for Windows Privilege Escalation Fixed in Version 3.0.11.160
NAVER MYBOX Explorer for Windows before 3.0.11.160 contains an improper privilege check that can allow a local attacker to escalate privileges to NT AUTHORITY\\SYSTEM through registry manipulation.