#PowerFall

Incident/Operation

2020-09-02 • Operation PowerFall: CVE-2020-0986 and variants

Operation PowerFall was a targeted attack disclosed in August 2020 that chained two previously unknown vulnerabilities: remote code execution in Internet Explorer 11 and local privilege escalation on current Windows 10 builds. The privilege-escalation stage exploited CVE-2020-0986, an arbitrary pointer-dereference flaw in the Windows GDI Print and Print Spooler API. By manipulating the printing host process, the exploit achieved arbitrary code execution at medium integrity, escaped the browser sandbox, and completed a browser-to-system compromise chain on affected Windows hosts.

Tagged Reports

« Back