Microsoft announced on Friday that it is investigating details of an unpatched vulnerability in the Windows operating system. This flaw is located in the kernel of the operating system and was discovered by Israeli security researcher Gil Dabah, also known by the nickname ‘arkon’.
Danish security company Secunia announced on Friday that the mentioned vulnerability is found in the system component Win32k.sys. The vulnerability can be exploited by calling the application programming interface (API) GetClipboardData, which collects data from the clipboard. Hackers could exploit this vulnerability to execute arbitrary code at the kernel level of the operating system, which would further allow them to infect computers with malicious software or modify, steal, or delete any data on the computer. The vulnerability is present in several versions of Windows, including Windows XP SP3, Server 2003 R2, Vista, Windows 7, and Windows Server 2008 SP2. Microsoft has rated this vulnerability as important, which is one level below critical vulnerability because it cannot be exploited without physical access to the computer and a valid user account. (M.N.,www.cert.hr)