Vulnerable driver allowed cybercriminals to bypass Windows security
Security company Crowdstrike writing now that the cybercriminal gang Scattered Spiders’ activity is exploiting an old vulnerability (CVE-2015-2291) in MITRE’s CVE program to inject its own malicious drivers into the Intel Ethernet Diagnostics Driver for Windows (iqvw64.sys). This could allow the attackers to overload the system and or run arbitrary code with kernel privileges in … Read more