Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Windows 0-day exploit CVE-2019-1458 used in Operation WizardOpium

released on 2019-12-11 @ 09:34:06 AM
In November 2019, Kaspersky technologies successfully detected a Google Chrome 0-day exploit that was used in Operation WizardOpium attacks. During our investigation, we discovered that yet another 0-day exploit was used in those attacks. The exploit for Google Chrome embeds a 0-day EoP exploit (CVE-2019-1458) that is used to gain higher privileges on the infected machine as well as escaping the Chrome process sandbox. The exploit is very similar to those developed by the prolific 0-day developer known as ‘Volodya’.