[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/win32k-analysis-part-2/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 36 min read  
Related Products  
[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Shawn Westfall](https://unit42.paloaltonetworks.com/author/shawn-westfall/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 20, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [CVE-2021-1732](https://unit42.paloaltonetworks.com/tag/cve-2021-1732/)
  * [CVE-2022-21882](https://unit42.paloaltonetworks.com/tag/cve-2022-21882/)
  * [Microsoft Windows](https://unit42.paloaltonetworks.com/tag/microsoft-windows/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/?pdf=download&lg=en&_wpnonce=b82091c0d3 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/?pdf=print&lg=en&_wpnonce=b82091c0d3 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F&title=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F&text=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F "Share in Mastodon")

## Table of Contents

[Detailed analysis of CVE-2022-21882](#post-128506-_y0xnnzwfgrlm)  
[1. Find HMValidateHandle](#post-128506-_4u37vab0vanb)  
[2. Load NtUserConsoleControl and NtCallbackReturn](#post-128506-_yfe5i0sfp83t)  
[3. Find KernelCallbackTable and save a pointer to the user-mode callbacks xxxClientAllocWindowClassExtraBytes and xxxClientAllocWindowClassExtraBytes](#post-128506-_25jq2gtkga8v)  
[4. Define a couple of window classes](#post-128506-_1ykdt72ot841)  
[5. Groom the heap](#post-128506-_4k8elqoect3v)

## Table of Contents: Figures

[Figure 1. Call to FindHMValidateHandle function.](#Figure1)  
[Figure 2. IDA disassembly of the IsMenu function.](#Figure2)  
[Figure 3. Code snippet of FindHMValidateHandle.](#Figure3)  
[Figure 4. Lines 285-288 in the PoC.](#Figure4)  
[Figure 5. Lines 297-304 of the PoC.](#Figure5)  
[Figure 6. WinDbg output of the PEB.](#Figure6)  
[Figure 7. First 16 entries of the KernelCallbackTable.](#Figure7)  
[Figure 8. WinDbg memory dump of KernelCallbackTable + 0x3d0 where two functions of interest are located.](#Figure8)  
[Figure 9. Lines 312-325 of the PoC.](#Figure9)  
[Figure 10. Return value from calling HMValidateHandle on the first window created.](#Figure10)  
[Figure 11. Kernel-mode copy of the tagWND structure shared across user-mode and kernel-mode.](#Figure11)

#### Detailed analysis of CVE-2022-21882

##### 1. Find HMValidateHandle (as shown in Figure 1)

![Image 1 is a screenshot of a few lines of code. It is the call to the FindHMValidateHandle function.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-1.png) Figure 1. Call to FindHMValidateHandle function.

As mentioned earlier, exploit writers have historically used HmValidatehandle to leak the kernel address of objects whose handle is passed to the function. The function prototype is HMValidateHandle(HANDLE h, BYTE type), where the handle h is a handle to the object you are trying to validate, and type is a numeric constant representing the type of object.

For our purposes here, the type will be one that represents a window type 0x001. As of Windows 10 version 1803, this will return a user-mapped desktop heap pointer to the tagWND structure related to the window handle passed.

HMValidateHandle is not an exported function, so you can't just use GetProcAddress to resolve the function. Because of this, exploit authors typically resolve the IsMenu function within User32.dll and -- because the only function called by IsMenu is HMValidateHandle -- the exploit code will do a search for the first E8 opcode. The E8 opcode corresponds to a CALL instruction (the only call instruction in IsMenu).

Figure 2 shows the disassembly of the IsMenu function. We can see that the E8 opcode is the first and only opcode in the call to HMValidateHandle.
![Image 2 is a screenshot of the disassembly of the IsMenu function. It contains the first and only opcode in the call to HMValidateHandle.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-2.png) Figure 2. IDA disassembly of the IsMenu function.

In the PoC, the author defined a function at line 58 called FindHMValidateHandle that accomplishes what is described above. Figure 3 shows a code snippet from the FindHMValidateHandle function that searches IsMenu for the E8 opcode and saves this location as a pointer to the g\_pfnHMValidateHandle global variable. This will be used later to leak the user-mode mapped tagWND structure addresses.
![Image 3 is a screenshot of the code snippet of the FindHMValidateHandle.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-3.png) Figure 3. Code snippet of FindHMValidateHandle.

##### 2. Load NtUserConsoleControl and NtCallbackReturn

Both NtUserConsoleControl and NtCallbackReturn functions are abused to trigger CVE-2022-21882 and CVE-2021-1732. Both of these functions are undocumented and reside in win32u.dll and ntdll.dll respectively. Lines 285 through 288 in the PoC (shown in Figure 4) resolve these functions and save pointers to them for later use.
![Image 4 is a screenshot of lines 285 through 288 in the POC. These lines resolve the aforementioned functions and save pointers to them for later use.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-4.png) Figure 4. Lines 285-288 in the PoC.

Descriptions of the NtUserConsoleControl and NtCallbackReturn functions are detailed in steps 7 and 9 respectively.

##### 3. Find KernelCallbackTable and save a pointer to the user-mode callbacks xxxClientAllocWindowClassExtraBytes and xxxClientAllocWindowClassExtraBytes

The code in lines 297 through 304 (shown in Figure 5) is locating the KernelCallbackTable and saving the address pointers of the legitimate xxxClientAllocWindowClassExtraBytes and xxxClientFreeWindowClassExtraBytes functions to local variables. In order to hook xxxClientAllocWindowClassExtraBytes and xxxClientFreeWindowClassExtraBytes (explained in step 9), pointers to each function need to be found. This is because both of these functions are user-mode callbacks and not exported for use within the Windows API.
![Image 5 is a screenshot of lines 297 through 304 of the POC. They locate the KernelCallbackTable and save address pointers.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-5.png) Figure 5. Lines 297-304 of the PoC.

The KernelCallbackTable is located by parsing the process environment block (PEB). Offset 0x58 in the PEB contains a pointer to the KernelCallbackTable.

**NOTE** : The GS\[0x60\]register contains a pointer to the PEB on Windows x64 systems, which is why the code is referring to \_\_readgsqword(0x60u). The KernelCallbackTable is a table that contains a pointer mapping to all of the kernel callback functions used by the Windows kernel. The KernelCallbackTable entry in the PEB is shown using WinDbg (the dt nt!\_peb @$peb command was used to dump the current PEB).

Based on the WinDbg output shown in Figure 6, you can see that the PEB+0x58 contains a pointer to the KernelCallbackTable address.
![Image 6 is a screenshot of the WinDbg output. It contains a pointer to KernelCallbackTable.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-6.png) Figure 6. WinDbg output of the PEB.

The first few entries of the kernel callback are shown in Figure 7.
![Image 7 is a screenshot of the first 16 entries of the KernelCallbackTable.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-7.png) Figure 7. First 16 entries of the KernelCallbackTable.

The PoC is saving two pointers (offsets 0x3d8 and 0x3e0) into the KernelCallbackTable, to g\_oldxxxClientAllocWindowClassExtraBytes and g\_oldxxxClientFreeWindowClassExtraBytes respectively.

The KernelCallbackTable+0x3d8 contains a pointer to xxxClientAllocWindowClassExtraBytes and the next entry (0x3e0) contains a pointer to xxxClientFreeWindowClassExtraBytes. This is shown in Figure 8.
![Image 8 is a screenshot of the memory dump by WinDbg of KernelCallbackTable + 0x3d0.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-8.png) Figure 8. WinDbg memory dump of KernelCallbackTable + 0x3d0 where two functions of interest are located.

##### 4. Define a couple of window classes

The code in Figure 9 (lines 312 through 325) should look familiar. As covered in [part one of this blog series](https://unit42.paloaltonetworks.com/win32k-analysis-part-1/), it is defining two window classes and registering one of the two (wndClass). One is given the class name normalClass, while the other one is given the class name of magicClass.

It also appears that the magic window class is given a random cbWndExtra value. This will be used later to differentiate between the two window classes when calling the hooked functions, and it will be analyzed in more detail later.
![Image 9 a screenshot of lines 312 through 325 of the POC. Highlighted in yellow are two instances of g\_nRandom.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-9.png) Figure 9. Lines 312-325 of the PoC.

##### 5. Groom the heap

Lines 413 through 467 in the PoC define a do/while loop that creates 10 windows of the normalClass class type. Each of the windows is given the window name somewnd.

The exploit author creates 10 windows (0 through 9) and then, subsequently, deletes windows 2 through 9. This is likely an attempt to groom the heap to ensure that the magic window, created later, will be allocated just after the two remaining windows in this portion of the PoC. However, as we'll see later in the case of this execution example, the magic window is allocated in between the first two.

During the creation of each window, the author is storing the handle to each window in an array called arrhwndNoraml\[\]. Next, a pointer to each window's tagWND structure is stored in another array called arrEntryDesktop\[\]. As described earlier, this is done by calling HMValidateHandle, which you now know returns a pointer to the window's user-mode copy of each tagWND structure.

Figure 10 shows the return value (rax) after the first call to HMValidateHandle (i.e., after creating the first window).
![Image 10 is a screenshot of the return value from calling HMValidateHandle on the first window created. The return value is rax.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-10.png) Figure 10. Return value from calling HMValidateHandle on the first window created.

Some labels have been added to the tagWND structure that will be important during the analysis of the PoC. Take note that the tagWND.cbWNDExtra value is 32 (0x20), which is exactly what was declared during the normalClass registration in Figure 9 above.

Also, take note of the tagWND.dwExtraFlags. This value is what will change during the call to NtUserConsoleControl, and will indicate that the value in the tagWND.pExtraBytes field is an offset into the kernel rather than a user-mode address. However, you can clearly see it is a user-mode address (0x0000015ba4b73fb0) immediately after the window is created.

The kernel-mode desktop tagWND structure for the same window is shown in Figure 11. It was found by statically analyzing the CreateWindowEXW function to find where the memory was allocated and breaking on this point during execution.

You can see the tagWND structure in the kernel is in fact the same as the one returned in user-mode after calling HMValidateHandle. As mentioned before, the user-mode desktop heap is simply a copy of the kernel-mode desktop heap, which is what is actually used by Win32k to manage windows.

As we'll see later, there is actually a parent tagWND structure located in the kernel. The parent structure is where all pertinent kernel addresses are stored, and Microsoft has ensured any user-mode access to window structures is done through the user-mode safe tagWND structures. Because Microsoft has gone through great lengths to obscure kernel pointer leaks from user-mode applications, only the user-mode desktop heap addresses are accessible from user-mode, and a method will need to be used to bypass this restriction a little later.
![Image 11 is a screenshot of the kernel mode copy of the tagWND structure that is shared across user mode and kernel mode.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-11.png) Figure 11. Kernel-mode copy of the tagWND structure shared across user-mode and kernel-mode.

It's important to note that tagWND.OffsetToDesktopHeap becomes more clear once you see the actual addresses where the tagWND structures reside. Above, the tagWND.OffsetToDesktopHeap value is 0x38390, while the kernel tagWND address is 0xffff8e8201038390. If you subtract the tagWND.OffsetToDesktopHeap value from the tagWND address you are able to determine the address of the kernel desktop heap, 0xffff8e8201000000. The same goes for the user-mode tagWND structures as well.

Later on, once an arbitrary write primitive has been obtained, these offsets will be used to aid in navigating the kernel memory space. We are now moving into Section 3, where we will continue with steps 6-9.

***Continue Reading ➠ [Section 3 -- Detailed Analysis, Steps 6-9](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/3)***

***[Back to Top](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/)***
Back to top

### Tags

* [CVE-2021-1732](https://unit42.paloaltonetworks.com/tag/cve-2021-1732/ "CVE-2021-1732")
* [CVE-2022-21882](https://unit42.paloaltonetworks.com/tag/cve-2022-21882/ "CVE-2022-21882")
* [Microsoft Windows](https://unit42.paloaltonetworks.com/tag/microsoft-windows/ "Microsoft Windows")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Android Malware Impersonates ChatGPT-Themed Applications](https://unit42.paloaltonetworks.com/android-malware-poses-as-chatgpt/ "Android Malware Impersonates ChatGPT-Themed Applications")

### Table of Contents

* 

### Related Articles

* [Windows Shortcut (LNK) Malware Strategies](https://unit42.paloaltonetworks.com/lnk-malware/ "article - table of contents")
* [Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources](https://unit42.paloaltonetworks.com/malicious-payloads-as-bitmap-resources-hide-net-malware/ "article - table of contents")
* [Uncovering .NET Malware Obfuscated by Encryption and Virtualization](https://unit42.paloaltonetworks.com/malware-obfuscation-techniques/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
