Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Zero-day exploit (CVE-2018-8453) used in targeted attacks

released on 2018-10-10 @ 10:51:48 AM
Yesterday, Microsoft published their security bulletin, which patches CVE-2018-8453, among others. It is a vulnerability in win32k.sys discovered by Kaspersky Lab in August. We reported this vulnerability to Microsoft on August 17, 2018. Microsoft confirmed the vulnerability and designated it CVE-2018-8453. So far, we detected a very limited number of attacks using this vulnerability. The victims are located in the Middle East. CVE-2018-8453 is a Use-After-Free inside win32kfull!xxxDestroyWindow that resembles an older vulnerability — CVE-2017-0263. CVE-2017-0263 was originally deployed by the Sofacy APT, together with a PostScript exploit, back in 2017.