Tag Archive for: escalation

Zero-day privilege escalation disclosed for Android

Zero-day privilege escalation disclosed for Android

Enlarge (credit: portal gda / Flickr)

Researchers have disclosed a zero-day vulnerability in the Android operating system that gives a major boost to attackers who already have a toe-hold on an affected device.

The privilege-escalation flaw is located in the V4L2 driver, which Android and other Linux-based OSes use to capture real-time video. The vulnerability results from a “lack of validating the existence of an object prior to performing operations on the object,” researchers with Trend Micro’s Zero Day Initiative said in a blog post published Wednesday. Attackers who already have untrusted code running with low privileges on a device can exploit the bug to access privileged parts of the Android kernel. The severity score is rated a 7.8 out of a possible 10 points.

Modern OSes have become increasingly hard to compromise in recent years thanks to exploitation mitigations that prevent untrusted code from interacting with hard drives, kernels, and other sensitive resources. Hackers have responded by chaining two or more exploits together. A buffer overflow, for instance, may allow an attacker to load malicious code into memory, and a privilege-escalation flaw gives the code the privileges it needs to install a persistent payload.

Read 6 remaining paragraphs | Comments

Biz & IT – Ars Technica

Android Zero-Day Bug Opens Door to Privilege Escalation Attack, Researchers Warn – Threatpost

Android Zero-Day Bug Opens Door to Privilege Escalation Attack, Researchers Warn  Threatpost

The zero-day vulnerability could enable privilege escalation, and is not part of Google’s Android September security update.

“android security news” – read more

Microsoft’s Patch Tuesday fixes zero-day exploit and privilege escalation vulnerability

  1. Microsoft’s Patch Tuesday fixes zero-day exploit and privilege escalation vulnerability  TechSpot
  2. Zero-Day Attack Exploits Windows via Malicious Word Doc  BankInfoSecurity.com
  3. Microsoft patches Internet Explorer zero-day ‘Double Kill’  TechTarget
  4. Adobe Security Bulletin – Adobe Support  Adobe Support
  5. Full coverage

zero day exploit – read more

Zero Day Weekly: ISC hacked, SS7 mobile security, Windows privilege escalation – ZDNet


ZDNet

Zero Day Weekly: ISC hacked, SS7 mobile security, Windows privilege escalation
ZDNet
Welcome to Zero Day's Week In Security, our roundup of notable security news items for the week ending January 2, 2015. Covers enterprise, controversies, reports and more. This week the Internet Systems Consortium site was hacked, a Lizard Squad …

“mobile security” – read more