Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks
Five Paragon Partition Manager BioNTdrv.sys driver vulnerabilities were found by Microsoft, one of which was exploited by ransomware gangs in zero-day attacks to obtain Windows SYSTEM rights.
The 'Bring Your Own susceptible Driver' (BYOVD) assaults, in which threat actors install the kernel driver on a targeted system in order to raise privileges, took advantage of the susceptible drivers.
A CERT/CC warning states that an attacker with local access to a device can use these flaws to escalate privileges or create a denial-of-service (DoS) situation on the victim's computer.
Additionally, even if Paragon Partition Manager is not installed read more about Ransomware gangs exploit Paragon Partition Manager bug in BYOVD attacks.
Get up to date on the latest cybersecurity news and e...

