#hotmail#s775 Microsoft has been blocking e mails to MS freemailer like Hotmail… , allegedly due to IP reputation with error s775. Some educational institutions are affected.
⚠️ Splunk Enterprise for Windows Vulnerability Let Attackers Gain SYSTEM Access
Source: https://t.co/h6juGcG2ah
Splunk has disclosed a high-severity vulnerability in Splunk Enterprise for Windows that allows a low-privileged local user to escalate their privileges to SYSTEM level through a DLL search-order hijacking attack.
The vulnerability exists in Splunk Enterprise for Windows versions below 10.2.0, 10.0.3, 9.4.8, 9.3.9, and 9.2.12.
An attacker who holds low-privileged access to a Windows system running Splunk Enterprise can exploit this flaw by creating a directory on the system drive where Splunk is installed and placing a malicious DLL inside it.
When the Splunk Enterprise service restarts, the application may inadvertently load that rogue DLL due to its insecure library search order.
Since the service runs with SYSTEM-level privileges, the injected code inherits those elevated rights, effectively granting the attacker full control over the host machine.
#cybersecuritynews
I believe the core vulnerability here is the "loading of the (outdated) IE engine via OLE object" attack vector. For that reason, Microsoft's decision to patch/mitigate it by completely blocking this specific object ({EAB22AC3-30C1-11CF-A7EB-0000C05BAE0B}) was the right move.
That being said, as also discussed with @wdormann, I think this new zero-day is a variant of @yorickkoster's technique published in 2018 (https://t.co/WnqgNkoqvy). It is based on that technique, but this 0day is more dangerous (an improved version) because it doesn't require the victim to double-click on the object - instead, it activates automatically when the document is opened via a RTF format.
#CVE-2026-21509
https://t.co/5QPRcWnras