Connect with us

Tech

Microsoft users warned over privilege elevation flaw | Computer Weekly

Published

on

Microsoft users warned over privilege elevation flaw | Computer Weekly


Microsoft marked the penultimate Patch Tuesday of 2025 with an update lighter than of late, addressing a mere 63 common vulnerabilities and exposures (CVEs) across its product estate – a far cry from many of its recent drops averaging well over 100 – and a solitary zero-day flaw.

Tracked as CVE-2025-62215, this month’s single zero-day is an elevation of privilege (EoP) vulnerability in the Windows Kernel that sits at the core of Microsoft’s operating system. It carries a CVSS score of just 7.0, and is not rated critical in its severity, however, exploitation has been observed in the wild, although no public proof-of-concept has yet been released.

Ben McCarthy, lead cyber security engineer at Immersive, explained that the root cause of the issue stems from two combined weaknesses one a race condition in which more than one process tries to access shared data and change it concurrently, the other a double free memory management error.

“An attacker with low-privilege local access can run a specially crafted application that repeatedly attempts to trigger this race condition,” he explained. “The goal is to get multiple threads to interact with a shared kernel resource in an unsynchronised way, confusing the kernel’s memory management and causing it to free the same memory block twice.

“This successful double-free corrupts the kernel heap, allowing the attacker to overwrite memory and hijack the system’s execution flow.”

McCarthy added: “Organisations must prioritise applying the patch for this vulnerability. While a 7.0 CVSS score might not always top a patch list, the active exploitation status makes it a critical priority. A successful exploit grants the attacker System privileges, allowing them to completely bypass endpoint security, steal credentials, install rootkits, and perform other malicious actions. This is a critical link in an attacker’s post-exploitation playbook.”

In the real world, said Mike Walters, president and co-founder of Action1, there are three core business impacts that would potentially arise from a successful compromise via CVE-2025-62215. Walters highlighted the possibility of mass credential exposure arising from the compromise of critical file servers, lateral movement and ransomware deployment, and regulatory, financial and reputational harm from data leakage or other operational disruption.

“Exploitation is complex,” he noted, “but a functional exploit seen in the wild raises urgency, since skilled actors can reliably weaponise this in targeted campaigns.”

Also high on the agenda for November is CVE-2025-60724 an RCE vulnerability in Graphics Device Interface Plus (GDI+), which carries a CVSS score of 9.8. GDI+ is a relatively low-level component but is responsible for rendering 2D graphics, images and text and therefore provides core functionality multiple Microsoft applications – and countless third-party programs, too.

Adam Barnett, Rapid7 lead software engineer, said this was as close to a zero-day as it was possible to get and likely to affect just about every asset running Microsoft software.

“In the worst-case scenario, an attacker could exploit this vulnerability by uploading a malicious document to a vulnerable web service,” he said.

“The advisory doesn’t spell out the context of code execution, but if all the stars align for the attacker, the prize could be remote code execution as System via the network without any need for an existing foothold. While this vuln almost certainly isn’t wormable, it’s clearly very serious and is surely a top priority for just about anyone considering how to approach this month’s patches.”

Action1’s Walters added: “This is emergency-level: a network-reachable RCE with no user interaction and low attack complexity is among the most dangerous bugs. Server compromise, tenant impact in multi-tenant systems, and the potential for rapid mass exploitation make this a top priority. 

“Exploitation may take time to perfect because attackers must build reliable allocator and interpreter manipulations that bypass mitigations like CFG, ASLR, and DEP. Still, GDI+ and image parsing bugs have a history of being weaponised quickly.”

Critically acclaimed bugs

Finally, the docket for security teams this month includes four critical vulnerabilities, highlighted by Dustin Childs of Trend Micro’s Zero Day Initiative (ZDI). These are CVE-2025-30398, a third-party information disclosure flaw in Nuance PowerScribe 360; CVE-2025-60716, an EoP flaw in DirectX Graphics Kernel; CVE-2025-62199, an RCE flaw in Microsoft Office; and CVE-2025-62214, another RCE flaw in Visual Studio.



Source link

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Tech

Samsung Bets Big On Art With Its New OLED and Frame TVs

Published

on

Samsung Bets Big On Art With Its New OLED and Frame TVs


Samsung has pulled the wrapping off some of its most anticipated TVs for 2026, including its latest art-forward TVs, The Frame and The Frame Pro, and its premium OLED TVs, which include three series available in sizes from 42 inches up to a massive 83 inches.

Here’s the lowdown on Samsung’s latest TV releases for 2026, including what I am excited about from the brand this year.

Proper Framing

Samsung’s Frame TVs, which use a matte screen to display art when you’re not watching your favorite shows and movies, will be offered in new sizes for 2026, and include an upgrade to its glare-resistant screen technology.

The new Frame Pro leads things off as Samsung’s top-performing option in the series. The TV continues to be “the only Art TV with wireless transmission,” letting you send audio and video wirelessly from a Blu-ray player or gaming console from up to 30 feet away when connected to its wireless box. Samsung claims its glare-reduction tech has once again improved this year, which further refines the TV’s ability to look more like a painting on the wall than a blank glass screen. It’s also got a maximum 144 Hz display refresh rate for smoother PC gaming (modern consoles cap at 120 Hz).

Other upgrades include Samsung’s NQ4 AI Gen3 Processor for improved overall picture performance and quicker response times, as well as a new Micro HDMI port that will support HDMI eARC for connecting a soundbar or speaker system. Sizes include a 55-inch model (pricing and availability yet to come), alongside 65-, 75-, and 85-inch displays.

Courtesy of Samsung

The regular Frame model will share in Samsung’s new glare-reduction tech, while adding new back stoppers for simpler cable connection. Otherwise, Samsung has yet to disclose any other major performance details about it. Software will be identical: Both Frame TVs will have access to Samsung’s Art Store, of course, which offers subscribers up to 5,000 works from over 800 artists for a $5 monthly subscription fee. If you don’t want to pay up, Samsung’s Art Store Streams provides 30 new curated works each month with your TV purchase.

To outfit your Frame or Frame Pro, you’ve got multiple bezel options this year designed to take it from TV vibes to artwork, including Modern Brown, Modern Teak, Modern White, and Sand Gold options. The Frame Pro can be matched with more options than the standard model, with choices from Deco TV Frames.

While pricing and availability for the regular Frame have yet to be announced, here is the current pricing for the new Frame Pro at launch:



Source link

Continue Reading

Tech

‘Uncanny Valley’: Iran’s Threats on US Tech, Trump’s Plans for Midterms, and Polymarket’s Pop-up Flop

Published

on

‘Uncanny Valley’: Iran’s Threats on US Tech, Trump’s Plans for Midterms, and Polymarket’s Pop-up Flop


Kate Knibbs: So, you went twice?

Makena Kelly: Yes, Kate. I went twice.

Kate Knibbs: I missed that.

Zoë Schiffer: Wait, is the Pentagon Pizza thing a joke about the pizza predicting the war?

Makena Kelly: Yeah.

Zoë Schiffer: Oh, my God.

Makena Kelly: Because they had these Pentagon pizza trackers up. When I returned the second night, yes, I came back the second night. Everything was working for the most part. There were still some screens that were turned off, but I never saw any actual Bloomberg terminals. There were some monitory Bloomberg type terminal things that it looked like Polymarket had developed themselves, but the real $50,000 Bloomberg terminal was nowhere to be found. And yeah, the second night, again, it was mostly people looking to gawk at the event, except I did find a couple of people who placed some bets on platforms like Polymarket and Kalshi. One was named William, and he said he was a member of the military, wouldn’t give me his full name. And he last year got involved in this for the first time by putting in, I think, all of his tax return into Oklahoma City sports betting.

Makena Kelly, archival audio: So, you used Kalshi?

William, archival audio: Yes.

Makena Kelly, archival audio: When did you first start using the service?

William, archival audio: Probably when I got my tax return back.

Makena Kelly, archival audio: OK.

William, archival audio: So, I filed my taxes pretty early and I was like, “Oh, sweet. I got my tax return. What am I going to do with it?” So, I was like, “I’m going to just put it on Kalshi.”

Makena Kelly: He said that he goes up and down 100 dollars, but he hasn’t made any major winnings. Some of the stuff that we’ve heard. Some people making crazy insider bets making millions and millions of dollars. This is just a guy who was interested in this and just plays it for fun, it sounds like.

Brian Barrett: Kate, what do you see when you see a pop-up like this and Polymarket trying to—is it an attempt to legitimize itself to just a marketing stunt? And how does it tie into what you’re seeing with these companies anyway, that there’s the explosive growth that they’ve got trying to reach out to so many people and getting so many people hooked on what they’re offering?

Kate Knibbs: I mean, this particular event definitely seems like a very bald effort to woo DC-based journalists, if nothing else. One thing that Makena said sort of encapsulates what’s going on right now, the thing about the guys in the Palantir hoodies. So, I think it was the same week that this bar opened. Polymarket announced a partnership with Palantir and Palantir is helping them protect the integrity of their sports market. So, Palantir is going to be basically attempting to help Polymarket catch insider traders and market manipulators in all the sports games, which is kind of wild. I actually asked Polymarket last week whether they had any other deals with Palantir when I was trying to get them to say anything about whether they were investigating the Iran bets that have been raising a lot of eyebrows. And they said that Palantir was only helping them with sports, which I thought was freaking weird. And it speaks to how they’re rapidly expanding, but doing so in this really messy ad hoc way that doesn’t really make a lot of sense. Because I was like, “If you’re going to get Palantir involved, why wouldn’t you have them do this geopolitical stuff instead of March Madness?” Yeah, wild, wild times.



Source link

Continue Reading

Tech

The Google Pixel 10 Is $150 Off

Published

on

The Google Pixel 10 Is 0 Off


On the hunt for a new Android smartphone? Amazon currently has the 128GB Pixel 10 in Obsidian marked down to just $649, $150 off its usual price. It’s one of our favorite Android smartphones, particularly for users who take a lot of photos.

  • Photograph: Julian Chokkattu

  • Photograph: Julian Chokkattu

  • Photograph: Julian Chokkattu

Google

Pixel 10, Pixel 10 Pro, and Pixel 10 Pro XL

The biggest advantage to a Pixel over other Android smartphones is that you get the latest features from Google as soon as they’re available, often before other brands implement them. There are special camera modes that let you stitch together multiple group shots, or help you improve the angle and lighting with helpful tips. You’ll also find novel features like real-time translations and spam call screening, and Google even figured out how to let you AirDrop files with iOS users.

All of that functionality is powered by some of the better hardware you can find in an Android phone. The Pixel 10 sports a 6.3-inch OLED display with a 120Hz refresh rate for gaming and smoother scrolling. The Tensor G5 is a step up from the 10a’s Tensor G4 chip, and sports 12 GB of memory for better performance. They even support Qi2 wireless charging, making them compatible with existing MagSafe accessories.

While the Pixel 10a will satisfy most folks, the Pixel 10 offers a variety of upgrades over the more basic model, most of which pertain to the cameras and image processing. The rear camera has a proper 5X optical zoom, letting you nail those nature shots without scaring the wildlife, and the front camera sports auto-focus, which will make your big group selfies less of a headache. Oddly, the battery is actually a bit smaller in the Pixel 10, but neither disappointed us when it came to longevity.

If you’re sold on the Pixel 10, I spotted the discounted $649 price point for the 128 GB model in both Obsidian and Lemongrass, or $749 in Indigo. If you need more storage, the Obsidian and Frost colors were both marked down to $749 for the upgraded 256 GB version. If you’re wondering what other Android smartphones we like, make sure to check out our in-depth guide with picks from Google, Samsung, and OnePlus.



Source link

Continue Reading

Trending