Intelligence View
Critical Security Flaws Discovered in Intel, ASUS, Acer Apps for Windows
Security researchers at SafeBreach discovered critical vulnerabilities in a trio of apps that typically come pre-loaded on Windows devices. The applications are developed by Intel, ASUS, and Acer, all of which pre-install their software…
The applications are developed by Intel, ASUS, and Acer, all of which pre-install their software on their computers running Microsoft’s operating system.
In the case of ASUS, the vulnerability affects the ASLDR Service in ASUS ATK Package, allowing attackers to drop malicious payloads by abusing the signed service. They can eventually obtain persistence to load malware at system boot, but also exploit the flaw for execution and evasion, an in-depth look at the flaw explains.
“The root cause of this unquoted search path vulnerability happens because the command line doesn’t contain a quoted string between the path of the executable and the argument - so the CreateProcessAsUser function tries to split it by itself ...
SOCIAL SHARE CARD GENERATOR