As revealed via a bug report, the researchers, Mateusz Jurczyk and Sergei Glazunov, identified the flaw that allows elevated privileges to an attacker, thereby allowing the adversary to execute code on the target device.
The Windows Kernel Cryptography Driver (cng.sys) exposes a \Device\CNG device to user-mode programs and supports a variety of IOCTLs with non-trivial input structures. It constitutes a locally accessible attack surface that can be exploited for privilege escalation (such as sandbox escape).While the researchers tested the exploit on Windows 10, they believe that the bug exists since Windows 7. It means all users with their devices running on Windows 7 to the latest builds of Windows 10 are vulnerable to exploitation.
As disclosed by Ben Hawkes via a tweet, this bug (CVE-2020-17087) can become serious when exploited together with the Chrome zero-day (CVE-2020-15999) disclosed last week.
https://twitter.com/benhawkes/status/1322206828202127360
- benhawkes
We have evidence that this bug is being used in the wild. Therefore, this bug is subject to a 7 day disclosure deadline.Eventually, they disclosed the vulnerability after the deadline, even though it still awaits a fix.
However, they have confirmed that a fix will be available by November 10, 2020.