[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/win32k-analysis-part-2/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 36 min read  
Related Products  
[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Shawn Westfall](https://unit42.paloaltonetworks.com/author/shawn-westfall/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 20, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [CVE-2021-1732](https://unit42.paloaltonetworks.com/tag/cve-2021-1732/)
  * [CVE-2022-21882](https://unit42.paloaltonetworks.com/tag/cve-2022-21882/)
  * [Microsoft Windows](https://unit42.paloaltonetworks.com/tag/microsoft-windows/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/?pdf=download&lg=en&_wpnonce=b82091c0d3 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/?pdf=print&lg=en&_wpnonce=b82091c0d3 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F&title=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F&text=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F "Share in Mastodon")

## Table of Contents

[6. Calculate offsets between windows](#post-128506-_j62n51pm0si6)  
[7. Call NtUserConsoleControl on lowest window address](#post-128506-_1vc6ug2if0ck)  
[8. Create a third (magic) window](#post-128506-_xddsw82ff6en)  
[9. Hook xxxClientAllocWindowClassExtraBytes with a malicious version that calls NtUserConsoleControl and NtCallbackReturn, then returns to the real xxxClientAllocWindowClassExtraBytes](#post-128506-_532yn1gc6kru)

## Table of Contents: Figures

[Figure 12. Lines 472-499 of the PoC.](#Figure12)  
[Figure 13. WinDBG dump of the HMValidateHandle return value (rax) for Wnd1.](#Figure13)  
[Figure 14. WinDBG dump of the HMValidateHandle return value (rax) for Wnd0.](#Figure14)  
[Figure 15. Line 501 of the PoC.](#Figure15)  
[Figure 16. Wnd0's pExtraBytes value before and after the call to NtUserConsoleControl.](#Figure16)  
[Figure 17. Creation of WndMagic.](#Figure17)  
[Figure 18. Memory layout just after creation of WndMagic.](#Figure18)  
[Figure 19. Lines 522-530 of the PoC.](#Figure19)  
[Figure 20. KernelCallbackTable before pointer overwrite.](#Figure20)  
[Figure 21. KernelCallbackTable after pointer overwrite.](#Figure21)  
[Figure 22. Lines 170-190 of the PoC.](#Figure22)  
[Figure 23. Line 496 of the PoC.](#Figure23)  
[Figure 24. Lines 151-164 of the PoC.](#Figure24)

##### 6. Calculate offsets between windows

Lines 472 through 499 (shown in Figure 12) simply determine which of the first two windows created have the lowest offset to the kernel desktop heap base. They then assign the tagWND pointers and tagWND.OffsetToDesktopHeap to variables tagged with \_min or \_max based on the window order in memory.
![Image 12 is a screenshot of lines 472 through 499 of the POC. It shows the pointers and how they are assigned to variables.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-12.png) Figure 12. Lines 472-499 of the PoC.

In this case, the first window created was not actually the lowest in memory, therefore it'll be referred to as Wnd1. The second window, which is lower in memory, will be referred to as Wnd0 from now on, to reflect their locations in memory.

Based on what's shown in Figure 13, you now know that the user-mode desktop heap must be at 0x15ba5028390 - 0x38390 or 0x15ba4ff0000.
![Image 13 is a screenshot of the WinDbg dump of HMValidateHandle return value for WND1.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-13.png) Figure 13. WinDBG dump of the HMValidateHandle return value (rax) for Wnd1.

If we take the tagWND.OffsetToDesktopHeap for Wnd1 and add it to the desktop heap address calculated above, you get 0x15ba4ff0000 + 0x2ad30 or 0x15ba501ad30. This is exactly what HMValidateHandle returned for the tagWND structure for Wnd0, as shown in Figure 14.
![Image 14 is a screenshot of the WinDbg dump of HMValidateHandle return value for WND0.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-14.png) Figure 14. WinDBG dump of the HMValidateHandle return value (rax) for Wnd0.

This part of the PoC is simply doing this math and assigning the tagWND pointers and offsets to the desktop heap to the following tracking variables:

* kernel\_desktop\_heap\_base\_offset1
* kernel\_desktop\_heap\_base\_offset2
* kernel\_desktop\_heap\_base\_offset\_Min
* tagWndMin\_offset\_0x128
* tagWndMin\_offset\_0x128
* kernel\_desktop\_heap\_base\_offset\_Min
* hWndMin
* hWndMax

##### 7. Call NtUserConsoleControl on lowest window address

Next, the author calls NtUserConsoleControl (line 501 of the PoC, shown in Figure 15) on hWndMin (Wnd0).
![Image 15 is line 501 of the POC. It is g\_pfnNtUserConsoleControl(6, \&hWndMin, 0x10);](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-15.png) Figure 15. Line 501 of the PoC.

This converts Wnd0 into a console window and, as a result, changes the tagWND.pExtraBytes from a user-mode address pointer to an offset. Windows will then treat this offset as an offset to the kernel-mode desktop heap base. It does this because NtUserConsoleControl adds 0x800 to the tagWND.dwExtraFlag value, which tells the window manager this window is a console window and it should treat the pExtraBytes field as an offset from the kernel desktop heap base address.

Wnd0's tagWND structure before and after the call to NtUserConsoleControl is shown in Figure 16.
![Image 16 is a screenshot of Wnd0’s pExtraBytes value before and after the call to NtUserConsoleControl. Two areas of the code are highlighted by yellow rectangles.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-16.png) Figure 16. Wnd0's pExtraBytes value before and after the call to NtUserConsoleControl.

The tagWND.pExtraBytes has changed from the user-mode virtual address 0x15ba4b74370 to the kernel-mode desktop heap offset 0x2ae80. The tagWND.dwExtraFlag has changed from 0x100100018 to 0x100100818, which is 0x100100018 + 0x800.

Now that the tagWND.dwExtraFlag indicates a kernel offset to the kernel-mode desktop heap, the offset in tagWND.pExtraBytes will now point at the kernel desktop heap plus the offset, or 0xffff8e8201000000 + 0x2ae80 = 0xffff8e820102ae80. This address is meaningless at the moment, but its use will be explained in more detail in step 9.

##### 8. Create a third (magic) window

A third window is created next. This window belongs to the magicClass class that was registered in step 4 above. It is also given the name somewnd, just like the first two windows, Wnd0 and Wnd1. This window will be referred to as WndMagic from now on.

The call to CreateWindowExW is shown in Figure 17.
![Image of 17 is a screenshot of the call to CreateWindowExW. This is in the magicClass.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-17.png) Figure 17. Creation of WndMagic.

After creating the WndMagic window, the memory layout for all of the windows in our specific example is shown in the diagram in Figure 18. Notice that Wnd0's tagWND.dwExtraFlag (0x100100818 versus 0x10010018) indicates that the tagWND.pExtraBytes (0x2ae80) is now an offset into the kernel desktop heap.

In the diagram, you can see that Wnd0's kernel tagWND structure and the user-mode copy both indicate the same offset within the kernel desktop heap, while the other two tagWND structures pExtraBytes point to memory in user land.
![Image 18 is a diagram of the memory layout just after the creation of WNDMagic. On the left-hand side is the user land and its layout, and on the right-hand side is the kernel land.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-18.png) Figure 18. Memory layout just after creation of WndMagic.

**NOTE** : You can see that the order in which windows are created doesn't imply order in memory. Wnd0 in this case was the second window created, and it lies at the lowest address, while WndMagic is the second lowest despite being created last. It would be interesting to see if increasing the number of initial windows created in step 5 would make the window memory layout more predictable and alleviate the math required in step 6 to determine the memory order of each window.

##### 9. Hook xxxClientAllocWindowClassExtraBytes with a malicious version that calls NtUserConsoleControl and NtCallbackReturn, then returns to the real xxxClientAllocWindowClassExtraBytes

After the creation of WndMagic, the code shown in Figure 19 is executed (lines 522 through 530 in the PoC).
![Image 19 is a screenshot of lines 522 through 530 of the POC. It is what is executed after the creation of WndMagic.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-19.png) Figure 19. Lines 522-530 of the PoC.

First, the memory protections for the KernelCallbackTable entries for xxxClientAllocWindowClassExtraBytes and xxxClientFreeWindowClassExtraBytes are being changed from PAGE\_READONLY (0x2) to PAGE\_EXECUTE\_READWRITE (0x40) through a call to VirtualProtect. Next you can see the kernel callback table pointer entries for xxxClientAllocWindowClassExtraBytes and xxxClientFreeWindowClassExtraBytes are being overwritten with pointers to the attacker defined functions g\_newxxxClientAllocWindowClassExtraBytes and g\_newxxxClientFreeWindowClassExtraBytes respectively.

Figure 20 shows the KernelCallbackTable before the function pointers have been overwritten.
![Image 20 is a screenshot of the KernelCallbackTable before the function pointers are overwritten.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-20.png) Figure 20. KernelCallbackTable before pointer overwrite.

Figure 21 shows the KernelCallbackTable after hooking both functions.
![Image 21 is the KernelCallbackTable after both functions are hooked and the pointers are overwritten.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-21.png) Figure 21. KernelCallbackTable after pointer overwrite.

Now that the legitimate functions have been successfully hooked with the malicious functions g\_newxxxClientAllocWindowClassExtraBytes and g\_newxxxClientFreeWindowClassExtraBytes, anytime the legitimate functions are called, execution will be directed to the g\_new functions.

To understand why someone would want to hook these functions, it's helpful to understand what the legitimate functions do. The real xxxClientAllocWindowClassExtraBytes function takes the tagWND.cbWndExtra value as a parameter, and then it allocates that number of bytes to the desktop heap. The pointer to the allocation is then returned, via a call to NtCallbackReturn (this will be important later), and is stored in the tagWND.pExtraBytes field of the windows structure.

If you can hook xxxClientAllocWindowClassExtraBytes, you know -- at the very least -- you can control the pointer address that is written to the tagWND.pExtraBytes field of the referenced window to one of your choosing. However, this address pointer would be a user-mode pointer, which doesn't really do much good if the objective is to gain code execution in the kernel to escalate privileges by stealing the System token. Therefore, something else will be needed to enable access to kernel memory, and this will be discussed shortly.

Figure 22 shows the malicious g\_newxxxClientAllocWindowClassExtraBytes function definition.
![Image 22 is a screenshot of lines 170 through 190 of the POC. Included is the malicious g\_newxxxClientAllocWindowClassExtraBytes function definition.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-22.png) Figure 22. Lines 170-190 of the PoC.

The primary purpose of the g\_newxxxClientAllocWindowClassExtraBytes function is to call NtUserConsoleControl to change the currently referenced window handle to that of a console window. As discussed in step 7, console windows do not manage the extra bytes field within the user-mode copy of the desktop heap, but are instead managed directly within the kernel desktop heap. Because of this, the tagWND.pExtraBytes field of a console window is treated as an offset into the kernel desktop heap versus a user-mode desktop heap pointer.

Because NtUserConsoleControl is not normally within the call stack of the legitimate xxxClientAllocWindowClassExtraBytes function, Windows does not expect, nor programmatically account for, the changes that NtUserConsoleControl makes to the tagWND.dwExtraFlag (addition of 0x800) and tagWND.pExtraBytes fields. This results in a type confusion bug (CVE-2022-21882) that leads to an unexpected kernel memory access.

Because standard GUI windows are initialized with a user-mode desktop heap pointer in the pExtraBytes field and the window manager is now treating this value as an offset into the kernel desktop heap, the value of this field must be changed. The new value should reflect a useful offset value from the kernel desktop heap base as opposed to the much larger pointer value that currently exists.

When the real xxxClientAllocWindowClassExtraBytes function is done allocating the requested memory, it passes a pointer to the allocated memory to the NtCallbackReturn function to return execution to the kernel. This ultimately results in the pointer to the pExtraBytes memory allocation being stored in the tagWND.pExtraBytes field.

Just prior to g\_newxxxClientAllocWindowClassExtraBytes calling NtCallbackReturn, qwRet is set to the value of kernel\_desktop\_heap\_base\_offset\_Min which, if you remember from earlier (step 6, Figure 12), is Wnd0's tagWND.OffsetToDesktopHeap value. Figure 23 shows the code in the PoC that assigns kernel\_desktop\_heap\_base\_offset\_Min to Wnd0's tagWND.OffsetToDesktopHeap.
![Image 23 is line 496 of the POC starting with kernel\_desktop\_heap\_base\_offset\_Min.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-23.png) Figure 23. Line 496 of the PoC.

To recap, the call to NtUserConsoleControl results in the pExtraBytes field being interpreted as an **offset** into the kernel. The call NtCallbackReturn overwrites the window's pExtraBytes field with an **offset** to Wnd0's tagWND.OffsetToDesktopHeap. Therefore, it is now possible to change a window's pExtraBytes field to point to the kernel address of Wnd0's tagWND structure. This is assuming we can find a function that calls the user-mode callback xxxClientAllocWindowClassExtraBytes, which will be discussed in more detail in the next step.

Figure 24 shows the code (lines 151 through 164) for the second hooked function, g\_newxxxClientFreeWindowClassExtraBytes.
![Image 24 is a screenshot of lines 151 through 164 of the POC. Highlighted in brown is g\_nRandom.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-24.png) Figure 24. Lines 151-164 of the PoC.

The reason this function is hooked is because calls to NtUserConsoleControl subsequently make a call to xxxClientFreeWindowClassExtraBytes. However, after going through all of the trouble to set the tagWND.dwExtraFlag and tagWND.pExtraBytes to values that will facilitate the exploit by hooking xxxClientAllocWindowClassExtraBytes, it would be counterproductive to have these values freed by a call to xxxClientFreeWindowClassExtraBytes.

To avoid this, the real function has been hooked and the malicious function compares the random value g\_nRandom to the parameter passed to g\_newxxxClientAllocWindowClassExtraBytes, which is the tagWND.cbExtraBytes field. WndMagic's tagWND.cbExtraBytes was set to this value earlier in the PoC (see step 4), therefore the comparison is using this value to ensure the real xxxClientFreeWindowClassExtraBytes is not called during any references to the WndMagic window.

If the value matches, then g\_newxxxClientFreeWindowClassExtraBytes simply returns 1. If the value does not match, execution is redirected to g\_oldxxxClientAllocWindowClassExtraBytes, or the real xxxClientAllocWindowClassExtraBytes function.

This is likely an error on the part of the author since it would make more sense to redirect control back to the intended function (xxxClientFreeWindowClassExtraBytes) through a call to g\_oldxxxClientFreeWindowClassExtraBytes. This call was defined as a pointer to the real xxxClientFreeWindowClassExtraBytes in line 304 of the PoC.

This error does not affect the success of the PoC exploit because the hooked functions are never called with other windows as inputs. Now we move on to steps 10-11.

***Continue Reading ➠ [Section 4 -- Detailed Analysis, Steps 10-11](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/4)***

***[Back to Top](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/)***
Back to top

### Tags

* [CVE-2021-1732](https://unit42.paloaltonetworks.com/tag/cve-2021-1732/ "CVE-2021-1732")
* [CVE-2022-21882](https://unit42.paloaltonetworks.com/tag/cve-2022-21882/ "CVE-2022-21882")
* [Microsoft Windows](https://unit42.paloaltonetworks.com/tag/microsoft-windows/ "Microsoft Windows")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Android Malware Impersonates ChatGPT-Themed Applications](https://unit42.paloaltonetworks.com/android-malware-poses-as-chatgpt/ "Android Malware Impersonates ChatGPT-Themed Applications")

### Table of Contents

* 

### Related Articles

* [Windows Shortcut (LNK) Malware Strategies](https://unit42.paloaltonetworks.com/lnk-malware/ "article - table of contents")
* [Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources](https://unit42.paloaltonetworks.com/malicious-payloads-as-bitmap-resources-hide-net-malware/ "article - table of contents")
* [Uncovering .NET Malware Obfuscated by Encryption and Virtualization](https://unit42.paloaltonetworks.com/malware-obfuscation-techniques/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
