{"id":8867,"date":"2021-07-21T09:04:53","date_gmt":"2021-07-21T13:04:53","guid":{"rendered":"https:\/\/www.technewsday.com\/?p=8867"},"modified":"2021-07-23T13:29:47","modified_gmt":"2021-07-23T17:29:47","slug":"two-new-vulnerabilities-found-in-windows-and-linux","status":"publish","type":"post","link":"https:\/\/technewsday.com\/staging\/two-new-vulnerabilities-found-in-windows-and-linux\/","title":{"rendered":"Two New Vulnerabilities Found In Windows and Linux"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Two new vulnerabilities- one in Windows and the other in Linux &#8211; have been discovered recently, and these vulnerabilities allow hackers to bypass a vulnerable system and access sensitive resources.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">One vulnerability allows the hacker access to low privileged OS resources where code can be executed or sensitive data can be read; a second vulnerability increases the execution of code or file access to OS resources reserved for password storage or other sensitive operations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The researcher found that the contents of the security account manager- the database that stores user accounts and security descriptors for users on the local computer- could be read by users even if they had limited system privileges.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">This made it possible to obtain cryptographically protected password data, find the password that installed Windows, obtain the computer keys for the Windows data protection API- which can be used to decrypt private encryption keys&#8211;and create an account on the affected machine.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The result is that the local user ends up with privileges up to the system, the highest level in Windows.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">A Microsoft representative said that company officials would investigate the vulnerability and take appropriate action as needed, which is being tracked as CVE-2021-36934.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The exploit described comes with significant overhead, particularly around 1 million nested directories.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The attack also requires about 5GB of storage and 1 million inodes. Despite these complications, a Qualys representative described the PoC as &#8220;extremely reliable&#8221; and said it only takes about three minutes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Linux users should check with the distributor if patches are available to fix the vulnerability. Windows users should wait for advisories from Microsoft and security experts.<\/p>\n\n\n<p>For more information, read the <a href=\"https:\/\/arstechnica.com\/gadgets\/2021\/07\/separate-eop-flaws-let-hackers-gain-full-control-of-windows-and-linux-systems\/\" target=\"_blank\" rel=\"noopener\">original story<\/a> in Arstechnica.<\/p>","protected":false},"excerpt":{"rendered":"<p>Two new vulnerabilities were recently discovered in Windows and Linux.<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[16],"tags":[242,224],"class_list":["post-8867","post","type-post","status-publish","format-standard","hentry","category-security","tag-linux","tag-windows"],"acf":[],"_links":{"self":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/8867","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/comments?post=8867"}],"version-history":[{"count":6,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/8867\/revisions"}],"predecessor-version":[{"id":8901,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/posts\/8867\/revisions\/8901"}],"wp:attachment":[{"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/media?parent=8867"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/categories?post=8867"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/technewsday.com\/staging\/wp-json\/wp\/v2\/tags?post=8867"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}