On Wednesday, February 27th, we reported two 0-day vulnerabilities — previously publicly-unknown vulnerabilities — one affecting Google Chrome and another in Microsoft Windows that were being exploited together.
To remediate the Chrome vulnerability (CVE-2019-5786), Google released an update for all Chrome platforms on March 1; thisZaloguj lub Zarejestruj się aby zobaczyć!was pushed through Chrome auto-update. We encourage users to verify that Chrome auto-update has alreadyZaloguj lub Zarejestruj się aby zobaczyć!to 72.0.3626.121 or later.
The second vulnerability was in Microsoft Windows. It is a local privilege escalation in the Windows win32k.sys kernel driver that can be used as a security sandbox escape. The vulnerability is a NULL pointer dereference in win32k!MNGetpItemFromIndex when NtUserMNDragOver() system call is called under specific circumstances.
Zaloguj
lub
Zarejestruj się
aby zobaczyć!