EXECUTIVE SUMMARY:
The Windows Kernel Streaming architecture has revealed several security vulnerabilities in handling audio and video device data in kernel mode, particularly within MSKSSRV, ksthunk, and portcls.sys components. These vulnerabilities, including CVE-2024-30089, CVE-2024-35250, CVE-2024-38054, CVE-2024-38055, CVE-2024-38056, CVE-2024-38057, and CVE-2024-30084, highlight issues like unchecked memory boundaries and insufficient validation of user-supplied data. Exploiting these flaws can lead to out-of-bounds memory access, allowing unauthorized modifications in the kernel memory space, potentially leading to system compromise.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY:
The Windows Kernel Streaming architecture has revealed several security vulnerabilities in handling audio and video device data in kernel mode, particularly within MSKSSRV, ksthunk, and portcls.sys components. These vulnerabilities, including CVE-2024-30089, CVE-2024-35250, CVE-2024-38054, CVE-2024-38055, CVE-2024-38056, CVE-2024-38057, and CVE-2024-30084, highlight issues like unchecked memory boundaries and insufficient validation of user-supplied data. Exploiting these flaws can lead to out-of-bounds memory access, allowing unauthorized modifications in the kernel memory space, potentially leading to system compromise.[emaillocker id="1283"]
The identified vulnerabilities within the Windows Kernel Streaming components underscore the risks posed by insufficient validation in low-level audio-visual data processing. These flaws allow potential attackers to exploit unchecked memory access, leading to privilege escalation and system compromise.
RECOMMENDATION:
We strongly recommend you update Microsoft products as addressed in this security update:
REFERENCES:
The following reports contain further technical details:
https://cybersecuritynews.com/poc-exploit-windows-kernel-mode-drivers/