Threat Advisory

Windows Kernel Streaming Vulnerabilities Expose Critical Security Risks

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: High
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The Windows Kernel Streaming architecture has revealed several security vulnerabilities in handling audio and video device data in kernel mode, particularly within MSKSSRV, ksthunk, and portcls.sys components. These vulnerabilities, including CVE-2024-30089, CVE-2024-35250, CVE-2024-38054, CVE-2024-38055, CVE-2024-38056, CVE-2024-38057, and CVE-2024-30084, highlight issues like unchecked memory boundaries and insufficient validation of user-supplied data. Exploiting these flaws can lead to out-of-bounds memory access, allowing unauthorized modifications in the kernel memory space, potentially leading to system compromise.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

The Windows Kernel Streaming architecture has revealed several security vulnerabilities in handling audio and video device data in kernel mode, particularly within MSKSSRV, ksthunk, and portcls.sys components. These vulnerabilities, including CVE-2024-30089, CVE-2024-35250, CVE-2024-38054, CVE-2024-38055, CVE-2024-38056, CVE-2024-38057, and CVE-2024-30084, highlight issues like unchecked memory boundaries and insufficient validation of user-supplied data. Exploiting these flaws can lead to out-of-bounds memory access, allowing unauthorized modifications in the kernel memory space, potentially leading to system compromise.[emaillocker id="1283"]

 

  • CVE-2024-30089 - CVSS 7.8: Reference counting flaw in MSKSSRV allows memory corruption by mismanaging access control to system resources.
  • CVE-2024-35250 - CVSS 8.5: UnserializePropertySet in ks.sys lacks proper validation, enabling the bypass of security checks, facilitating privilege escalation.
  • CVE-2024-38054 - CVSS 8.0: ksthunk.sys fails in bounds checking, causing out-of-bounds write, risking kernel memory manipulation.
  • CVE-2024-38055 - CVSS 7.3: portcls.sys’s Pin setup does not validate buffer size accurately, leading to potential data leaks or tampering.
  • CVE-2024-38056 - CVSS 7.0: Unchecked data formats in portcls.sys can result in buffer overflows, endangering kernel stability.
  • CVE-2024-38057 - CVSS 7.5: ksthunk.sys’s IOCTL handler misses boundary checks, enabling malicious payloads to affect kernel functionality.
  • CVE-2024-30084 - CVSS 7.2: Flaws in Kernel Streaming service data handlers expose a potential pathway for privilege escalation through improper data controls.

 

The identified vulnerabilities within the Windows Kernel Streaming components underscore the risks posed by insufficient validation in low-level audio-visual data processing. These flaws allow potential attackers to exploit unchecked memory access, leading to privilege escalation and system compromise.

RECOMMENDATION:

We strongly recommend you update Microsoft products as addressed in this security update:

REFERENCES:

The following reports contain further technical details:
https://cybersecuritynews.com/poc-exploit-windows-kernel-mode-drivers/

[/emaillocker]
crossmenu