Anywho this is Major Cassiel Montaya again. Second generation recombinant. Codename "Hipshot".
#atwow #recomsquad #originalcharacter #atwow #dejablue #recombinantmarine
Thread on our #DejaBlue analysis (CVE-2019-1181 and CVE-2019-1182). First off, read @[email protected]'s analysis here https://www.malwaretech.com/2019/08/dejablue-analyzing-a-rdp-heap-overflow.html. Marcus reverse engineered Microsoft's patch in rdpcorets.dll!DecompressUnchopper::Decompress and found a check for integer overflow. 1/n
In August 2019 Microsoft announced it had patched a collection of RDP bugs, two of which were wormable. The wormable bugs, CVE-2019-1181 & CVE-2019-1182 affect every OS from Windows 7 to Windows 10. There is some confusion about which CVE is which, though it’s possible both refer to the same …
#BlueKeep : deux autres #vulnérabilités découvertes au sein du #RDS de #Microsoft ! (#DeJaBlue)
Our research team have just finished analyzing #DeJaBlue.
It looks like Microsoft was vulnerable to a variant on the vulnerability we found last year in FreeRDP: https://cpr-zero.checkpoint.com/vulns/cprid-2006/
@[email protected] @[email protected]