News

Vulnerability Analysis Report - CVE-2024-22830

Kernel drivers are critical components of modern operating systems, such as Windows. They have higher privileges than even the administrator user and are therefore a prime target for hackers. Attackers often try to exploit vulnerabilities in the drivers to gain complete control of the system. 

To prevent these attacks, Microsoft requires drivers to be approved and digitally signed. This means that only trusted drivers can be loaded into the system's kernel. Although this design reduces the risk of malicious code executing in the kernel, attackers still find ways around this restriction. For instance, by exploiting vulnerabilities in legitimately signed drivers. 

One type of attack that exploits these vulnerabilities is called 'Bring Your Own Vulnerable Driver' (BYOVD). In this case, attackers distribute a legitimate but vulnerable driver on the target system and use it to obtain the privileges needed to perform malicious actions, such as disabling antivirus programmes. These attacks, which require administrator privileges, are often used after the system has already been compromised. 

Recently, our Malware Lab discovered and described a vulnerability, called CVE-2024-22830, in the ACE-BASE.sys kernel driver, used by an 'anti-cheat' solution for some popular online games.  

The Lab reported the problem directly to Microsoft and contributed to the open source LOLDrivers project to report the risk to the community. 

If you wish to learn more, here is the link to our full report.

In addition, you can subscribe to the specific mailing list Cyber Studios by Tinexta Defence, to receive updates on upcoming research: https://tinextadefence.it/mailing-list-cyber-studios/

Share:

Degree in Business Administration from the University of Naples 'Federico II' with an MBA in Business Management achieved with high merit in 2008 by winning a scholarship provided by Invitalia S.p.A. from which she was selected in the first months of attendance as the best MBA profile.

After a brief experience in Invitalia S.p.A., he immediately held increasingly important roles in the management of Administration, Finance and Control of companies operating in the defence sector, theInformation Technology, of Cyber and National Security. In addition, she was Treasury Manager in companies operating in theEnergy.

He obtained an Executive Master in Finance (EMF) at SDA Bocconi in 2020, with a specialisation in Corporate Finance & Control and, in 2022, a further specialisation track in Asset, Wealth Management also at SDA Bocconi.

For over five years it has been the Chief Financial Officer of the Defence Tech Group, whose listing process he followed on the Euronext Growth Milan segment of Borsa Italiana.

From 2017 to 2024, she was a member of the boards of directors of all the legal entity of the Defence Tech Group with delegated powers over their financial management and from October 2021 to October 2024 was a Board Member of the Holding Company.

It is currently also Investor Relations Manager of the listed Defence Tech and follows all ESG issues of the Group.

In July 2021, she was recognised by Federmanager as one of the best talents under 44 at national level, receiving an important award as Young Manager 2020.