[![Logo](https://www.paloaltonetworks.com/wp-content/uploads/2021/07/PANW_Parent.png)](https://www.paloaltonetworks.com/)  
[![Unit42 Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/unit42-logo-white.svg)](https://unit42.paloaltonetworks.com/)  
Menu

* [Tools](https://unit42.paloaltonetworks.com/tools/)
* [ATOMs](https://unit42.paloaltonetworks.com/atoms/)
* [Security Consulting](https://www.paloaltonetworks.com/unit42)
* [About Us](https://unit42.paloaltonetworks.com/about-unit-42/)
* [**Under Attack?**](https://start.paloaltonetworks.com/contact-unit42.html)  
  English
* [English](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/)
* [Japanese](https://unit42.paloaltonetworks.com/ja/win32k-analysis-part-2/)
* [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research")
* [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/ "Threat Research")
* [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/ "Vulnerabilities")  
  [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

# Inside Win32k Exploitation: Analysis of CVE-2022-21882 and CVE-2021-1732

![Clock Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-clock.svg) 36 min read  
Related Products  
[![Cortex XDR icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/cortex_RGB_logo_Icon_Color.png)Cortex XDR](https://unit42.paloaltonetworks.com/product-category/cortex-xdr/ "Cortex XDR")

* ![Profile Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-profile-grey.svg)  
  By:
  
  * [Shawn Westfall](https://unit42.paloaltonetworks.com/author/shawn-westfall/)

* ![Published Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-calendar-grey.svg)  
  Published:June 20, 2023

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-category.svg)  
  Categories:
  
  * [Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/)
  * [Vulnerabilities](https://unit42.paloaltonetworks.com/category/vulnerabilities/)

* ![Tags Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-tags-grey.svg)  
  Tags:
  
  * [CVE-2021-1732](https://unit42.paloaltonetworks.com/tag/cve-2021-1732/)
  * [CVE-2022-21882](https://unit42.paloaltonetworks.com/tag/cve-2022-21882/)
  * [Microsoft Windows](https://unit42.paloaltonetworks.com/tag/microsoft-windows/)

* [![Download Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-download.svg)](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/?pdf=download&lg=en&_wpnonce=92524fc9d4 "Click here to download")

* [![Print Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-print.svg)](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/?pdf=print&lg=en&_wpnonce=92524fc9d4 "Click here to print")

Share![Down arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/down-arrow.svg)

* ![Link Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-share-link.svg)
* [![Link Email](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-sms.svg)](mailto:?subject=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732&body=Check%20out%20this%20article%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F "Share in email")
* [![Facebook Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-fb-share.svg)](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F "Share in Facebook")
* [![LinkedIn Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-linkedin-share.svg)](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F&title=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732 "Share in LinkedIn")
* [![Twitter Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-twitter-share.svg)](https://twitter.com/intent/tweet?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F&text=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732 "Share in Twitter")
* [![Reddit Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-reddit-share.svg)](https://www.paloaltonetworks.com//www.reddit.com/submit?url=https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F&ts=markdown "Share in Reddit")
* [![Mastodon Icon](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-mastodon-share.svg)](https://mastodon.social/share?text=Inside%20Win32k%20Exploitation:%20Analysis%20of%20CVE-2022-21882%20and%20CVE-2021-1732%20https%3A%2F%2Funit42.paloaltonetworks.com%2Fwin32k-analysis-part-2%2F "Share in Mastodon")

## Table of Contents

[14. Create a new process with System privileges and restore changes to modified structures](#post-128506-_35occalwmifn)  
[Analysis of the read64 Function](#post-128506-_7vhv0vcx9tf4)  
[Conclusion](#post-128506-_imj2wld0o8dl)

## Table of Contents: Figures

[Figure 56. Lines 206-266 of the PoC.](#Figure56)  
[Figure 57. Lines 355-385 of the PoC.](#Figure57)  
[Figure 58. Memory layout of the fake spmenu object.](#Figure58)  
[Figure 59. Function prototype for GetMenuBarInfo.](#Figure59)  
[Figure 60. PMENUBARINFO structure.](#Figure60)  
[Figure 61. Memory dump of ref\_g\_pMem5 after initialization.](#Figure61)  
[Figure 62. MSDN documentation for the RECT (rcbar) structure.](#Figure62)  
[Figure 63. Memory dump of pmbi after first call to GetMenuBarItem.](#Figure63)  
[Figure 64. Line 249 of the PoC.](#Figure64)  
[Figure 65. Line 261 of the PoC.](#Figure65)  
[Figure 66. Memory dump of pmbi after second call to GetMenuBarItem](#Figure66)  
[Figure 67. Memory dump showing address pointer Wnd1's parent TagWND structure.](#Figure67)

##### 14. Create a new process with System privileges and restore changes to modified structures

The remaining lines of the PoC (640 through 726) are simply creating a new process that inherits the current process' security token, which is now System. Then the previously modified structures are being reset to their original state to prevent a system crash in the event Windows accesses any of these structures in the future.

## Analysis of the read64 Function

During the discussion of the read64 function, we'll be referring to the code in Figure 56. The code in this figure was cleaned up by eliminating white space.
![Image 56 is a screenshot of lines 206 through 266 of the POC. The white space that was previously in the section of code has been cleaned up. QWORD MyRead64(QWORD qwOestAddr) MENUBARINFO pmbi = O; pmbi.cbSize = sizeof(MENUBARINFO); if (g\_blslnit) else QWORD \*pTemp = memset(pTemp, ø, øx20e) ; QWORD qwBase = øxeoøoeø4øøøøøøøø; QWORD qwAdd = øxeøøøoeø8eøøøøeø8; for (int i = 0; i \< øx4ø; i++) *(pTemp + i) = qwBase + qwAdd*i; = (QWORD)pTemp; -3, 1, \&pmbi) ; g\_pmbi\_rcBar\_teft = pmbi. rcBar. left; øx2øø) ;](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/qword-myread64qword-qwoestaddr-menubarinfo-pmbi.png) Figure 56. Lines 206-266 of the PoC.

Before we analyze the read64 function, let's start by discussing the spmenu object. This object is important to discuss because this is where GetMenuBarInfo is pulling the information that is returned inside the pmbi structure. It's important to know the general layout of the spmenu object.

Unfortunately, Microsoft does not provide debugging symbols for any of the relevant structures here, so we'll have to rely on the PoC and some reverse engineering to identify important structure offsets and pointer relationships. If we look at the PoC code shown in Figure 57, where the fake spmenu was created (lines 355 through 385), we can begin to guess some important offsets and structure sizes of an spmenu object.
![Image 57 is a screenshot of lines 355 through 385 of the POC. A fake spmenu has been created.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-57.png) Figure 57. Lines 355-385 of the PoC.

Figure 58 shows a diagram of the fake spmenu layout based on the PoC code shown above.
![Image 58 is a diagram of the memory layout of the fake spmenu object. Rom left to right is g\_pMem4, g\_pMem3, g\_pMem1 and g\_pMem2.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-58.png) Figure 58. Memory layout of the fake spmenu object.

Also recall, in step 12 above, the legitimate spmenu for Wnd1 was replaced by g\_pMem4. As we can see in Figure 58, this contains a pointer to the larger fake spmenu that was set up in the code snippet in Figure 57 above.

At a high level, the read64 function takes a kernel address and returns the pointer located at that address. We need this functionality because, even though we can calculate the address of spmenu + 0x50 (0xfff8e82008218c0 + 0x50 = 0xfff8e8200821910) based on the leaked spmenu address, that address isn't what we need. It's the pointer located at that address that is required.

But since the leaked spmenu address is a kernel address, we cannot directly read the pointers within the spmenu structure from user-mode. The read64 function was designed to provide this capability.

Within the read64 function there are two calls to GetMenuBarInfo, an initialization flag (g\_bIsInit), a menubar information structure (pmbi), and an allocated memory chunk that is 0x200 bytes in size. We'll discuss each of these next.

The GetMenuBarInfo function allows for the retrieval of a specified window's (hwnd) menu bar information via the PMENUBARINFO (pmbi) structure. The function prototype for the GetMenuBarInfo function is shown in Figure 59.
![Image 59 is a screenshot of the function prototype for GetMenuBarInfo.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-59.png) Figure 59. Function prototype for GetMenuBarInfo.

The [GetMenuBarInfo](https://learn.microsoft.com/en-us/windows/win32/api/winuser/nf-winuser-getmenubarinfo) function takes four parameters. The first parameter (hwnd) is a handle to the window that owns the menu bar for which the information is being queried. The second parameter (idObject) is the menu object being queried. This can be one of three values: popup menu, menu bar or system menu. However, the PoC only uses -3 (0xFFFFFFFD), which corresponds to a menu bar.

The third parameter (idItem) indicates the item to retrieve information for. If this parameter is 0, the function retrieves information about the menu itself. If this parameter is 1, the function retrieves information about the first item on the menu, and so on.

All calls within the PoC use the value 1, therefore referring to the first item on the menu. The final parameter (pmbi) is the structure that stores the returned information. The structure is of the type [PMENUBARINFO](https://learn.microsoft.com/en-us/windows/win32/api/winuser/ns-winuser-menubarinfo) and is shown in Figure 60.
![Image of 60 is a screenshot of the PMENUBARINFO structure. It shows the 1 values referred to in the text.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-60.png) Figure 60. PMENUBARINFO structure.

Looking back at the read64 function, we can see that a PMENUBARINFO structure named pmbi is allocated. Then the g\_bIsInit flag is checked. The g\_bIsInit flag is set after the first call to GetMenuBarInfo.

Looking at the PoC (lines 246 through 252), we see that the first call to GetMenuBarInfo uses the value of pmbi.rcbar.left after the initial call to set up the global variable g\_pmbi\_rcBar\_left (line 249). Once this is done, the g\_bIsInit flag is set to true (line 252).

The PoC also allocates and creates an array that is 0x200 bytes in size. The array is then initialized in a for loop in a way that indexes each DWORD (32 bits). A partial dump of this memory is shown in Figure 61.
![Image 61 is a screenshot of the memory dump of ref\_g\_pMem5 after initialization. It is shown in an array format, with columns for offset, zero, four, eight, and C. Highlighted in blue in the first row are the cells for columns zero and four.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/4-8-00000-ox15ba4b7fc10-ox15ba4b7fc20-00000010.png) Figure 61. Memory dump of ref\_g\_pMem5 after initialization.

Finally, the global variable ref\_g\_pMem5 is set to point to this allocated memory. Recall that ref\_g\_pMem5 is part of the fake spmenu that the PoC code replaced the real spmenu of Wnd1 with (shown in [Figure 58](https://unit42.paloaltonetworks.com/win32k-analysis-part-2//7/#Figure58)).

We know that the GetMenuBarInfo function uses pmbi to store the requested menu bar information. Looking at the read64 function, the only pmbi members that are referenced are pmbi.rcbar.left (lines 249 and 265) and pmbi.rcbar.top (line 265). Therefore, to understand what is going on here, we need to identify how GetMenuBarInfo calculates these values. After reverse engineering the GetMenuBarInfo function, we determined the pmbi.rcbar values are calculated in the following way:

* pmbi.rcbar.left = pmbi\[0x4\] = ref\_g\_pmem5\[0x40\] + tagWND\[0x58\]
* pmbi.rcbar.top = pmbi\[0x8\] = ref\_g\_pmem5\[0x44\] + tagWND\[0x5c\]
* pmbi.rcbar.right = pmbi\[0xc\] = ref\_g\_pmem5\[0x40\] + g\_pmem5\[0x48\]
* pmbi.rcbar.bottom = pmbi\[0x10\] = ref\_g\_pmem5\[0x4c\] + pmbi\[0x8\]

We know which rcbar variable corresponds to which offsets in pmbi from Microsoft's MSDN documentation, shown in Figure 62.
![Image 62 is a screenshot of Microsoft’s RECT (rcbar) documentation for the structure.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-62.png) Figure 62. MSDN documentation for the RECT (rcbar) structure.

Therefore, based on the analysis above, after the first call to GetMenuItem, pmbi.rcbar is:

* pmbi.rcbar.left = 0x40 + 0x00 = 0x40
* pmbi.rcbar.right = 0x44 + 0x00 = 0x44
* pmbi.rcbar.top = 0x40 + 0x48 = 0x88
* pmbi.rcbar.bottom = 0x4c + 0x44 = 0x90

Figure 63 shows a memory dump of pmbi after the first call GetMenuBarItem, verifying our calculations above are correct.
![Image 63 is a screenshot of the memory dump of pmbi after the first call to GetMenuBarItem. It is shown in an array format. Highlighted in blue in the first row are the cells for 00000030 and 00000040.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/oxffff810ad8c84b80-00030-00000-000c-oxffff810ad.png) Figure 63. Memory dump of pmbi after first call to GetMenuBarItem.

Based on the above variables we know that at line 249 in the PoC, shown in Figure 64, g\_pmbi\_rcBar\_left is set equal to pmbi.rcbar.left or 0x40.
![Image 64 is a screenshot of line 249 of the POC: g\_pmbi\_rcBar\_left = pmbi.rcbar.left.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-64.png) Figure 64. Line 249 of the PoC.

Line 261 of the PoC, shown in Figure 65, is subtracting the value of g\_pmbi\_rcBar\_left from qwDestAddr. We know that qwDestAddr is the input parameter to read64, or the address we are trying to dereference. Therefore, the PoC is subtracting 0x40 from this address and assigning it to ref\_g\_pMem5.
![Image 65 is a screenshot of line 261 of the POC. It starts with \*(QWORD \*)ref\_g\_pMem5.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/word-image-128506-65.png) Figure 65. Line 261 of the PoC.

At first this may seem confusing, but based on how GetMenuBarInfo calculates pmbi, we know that the first two values of pmbi are taken from ref\_g\_pMem5\[0x40\] and ref\_g\_pMem5\[0x44\]. Therefore, if we want to dereference qwDestAddr by calling GetMenuBarInfo by using pmbi.rcbar.left and pmbi.rcbar.top, we need to account for the fact that GetMenuBarInfo references ref\_g\_pMem5\[0x40\] and ref\_g\_pMem5\[0x44\] to calculate these values. This is what line 261 of the PoC is doing.

**NOTE** : We need to use both pmbi.rcbar.left and pmbi.rcbar.top because each value is only 32 bits and we need to store a 64-bit value.

Now that ref\_g\_pMem5 points to qwDestAddr - 0x40, the next call to GetMenuBarInfo will result in the following values:

* ref\_g\_pMem5 = qwDestAddr - 0x40
* pmbi.rcbar.left = qwDestAddr (low order bits)
* pmbi.rcbar.right = qwDestAddr (high order bits)

Figure 66 shows a memory dump of pmbi after the second call to GetMenuBarItem. We can see that pmbi\[0x4\] does indeed contain the lower order bits of qwDestAddr and pmbi\[0x8\] contains the high order bits of qwDestAddr.
![Image 66 is a screenshot of the memory dump of PMBI after the second call to GetMenuBarItem. It is shown in an array format. Highlighted in blue in the first row are the cells for 00000030 and 008437e0.](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/oxffff810ad8c84b80-ffff.png) Figure 66. Memory dump of pmbi after second call to GetMenuBarItem.

We already know that spmenu + 0x50 is supposed to point to the parent tagWND structure, and we can see from Figure 67, 0xffff8e82008427e0 is in fact the parent tagWND structure of Wnd1.
![Image 67 is a screenshot of the memory dump of showing address pointer Wnd1’s parent tagWND structure. It is shown in an array format. Highlighted in blue in the first row is the cell for 0000000000050330. oxffff8e82008437ee 0000000000000005 oxffff8e82008437f0 ffff8e8202cc0010 ffffd40ff34ea4b0 oxffff8e820084380e ffff8e82008437ee ffff8e8201038390](https://unit42.paloaltonetworks.com/wp-content/uploads/2023/06/oxffff8e82008437ee-0000000000000005-oxffff8e8200.png) Figure 67. Memory dump showing address pointer Wnd1's parent TagWND structure.

We can now see that any call to read64 will return a dereferenced address located at the input parameter qwDestAddr, successfully providing an arbitrary read primitive.

## Conclusion

This concludes the two part series on Win32k. In part one, we covered how to use the Win32 API to create GUI objects such as windows and menus. We then covered the user-mode and kernel-mode data structures that are used to manage these objects and how they have changed over the years to help optimize and secure the transition between user-mode and kernel-mode.

In part two we analyzed a recent vulnerability (CVE-2022-21882) and how this vulnerability can be exploited to elevate privileges. We discussed the inner workings of a public PoC to demonstrate what is required today to evade the protections Microsoft has worked so hard to implement over the last 20 years.

We showed how CVE-2022-21882 was similar to CVE-2021-1732 and why the patch for CVE-2021-1732 wasn't sufficient to prevent CVE-2022-21882. Finally, we discussed how the exploit used the GetMenuBarItem function (in conjunction with a fake menu structure) to provide the arbitrary read primitive required to locate and copy the System token for privilege escalation.

***[Back to Top](https://unit42.paloaltonetworks.com/win32k-analysis-part-2/)***
Back to top

### Tags

* [CVE-2021-1732](https://unit42.paloaltonetworks.com/tag/cve-2021-1732/ "CVE-2021-1732")
* [CVE-2022-21882](https://unit42.paloaltonetworks.com/tag/cve-2022-21882/ "CVE-2022-21882")
* [Microsoft Windows](https://unit42.paloaltonetworks.com/tag/microsoft-windows/ "Microsoft Windows")  
  [Threat Research Center](https://unit42.paloaltonetworks.com "Threat Research") [Next: Android Malware Impersonates ChatGPT-Themed Applications](https://unit42.paloaltonetworks.com/android-malware-poses-as-chatgpt/ "Android Malware Impersonates ChatGPT-Themed Applications")

### Table of Contents

* 

### Related Articles

* [Windows Shortcut (LNK) Malware Strategies](https://unit42.paloaltonetworks.com/lnk-malware/ "article - table of contents")
* [Stealthy .NET Malware: Hiding Malicious Payloads as Bitmap Resources](https://unit42.paloaltonetworks.com/malicious-payloads-as-bitmap-resources-hide-net-malware/ "article - table of contents")
* [Uncovering .NET Malware Obfuscated by Encryption and Virtualization](https://unit42.paloaltonetworks.com/malware-obfuscation-techniques/ "article - table of contents")

## Related Vulnerabilities Resources

![Pictorial representation of a group of people interacting with a dynamic 3D holographic display of colorful, undulating data waves on a table.](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/09/11_Myth-Busting_Overview_1920x900-786x368.jpg)  
[![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2025/08/Insights-icon-white.svg)Insights](https://unit42.paloaltonetworks.com/category/insights/) August 4, 2026 [#### The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/)

* [AI](https://unit42.paloaltonetworks.com/tag/ai/ "AI")

* [Frontier AI](https://unit42.paloaltonetworks.com/tag/frontier-ai/ "Frontier AI")

* [Vulnerability Exploitation](https://unit42.paloaltonetworks.com/tag/vulnerability-exploitation/ "Vulnerability Exploitation")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/frontier-ai-vulnerability-burst/ "The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software")  
  ![Pictorial representation of AI-enabled autonomous cyberattacks. A digital illustration depicting abstract, interconnected data streams in vibrant colors on a dark blue background](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/AdobeStock_992950050-3-782x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 30, 2026 [#### Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/)

* [ChatGPT](https://unit42.paloaltonetworks.com/tag/chatgpt/ "ChatGPT")

* [Claude code](https://unit42.paloaltonetworks.com/tag/claude-code/ "Claude code")

* [CVEs](https://unit42.paloaltonetworks.com/tag/cves/ "CVEs")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/ "Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks")  
  ![Pictorial representation of three zero-day vulnerabilities in Siemens ROX II OT switches. Digital illustration of a global network featuring interconnected lines and nodes over a map of the world, highlighted with neon lights and digital elements.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/07/03_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) July 17, 2026 [#### Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/)

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2025-40947](https://unit42.paloaltonetworks.com/tag/cve-2025-40947/ "CVE-2025-40947")

* [CVE-2025-40948](https://unit42.paloaltonetworks.com/tag/cve-2025-40948/ "CVE-2025-40948")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/siemens-rox-ii-zero-day-vulnerabilities/ "Three Steps to the Terminal: A Siemens ROX II Zero-Day Trilogy")  
  ![Pictorial representation of PAN-OS CVE-2026-0257. A vibrant city skyline at night, with tall skyscrapers and glowing digital beams extending into the sky, suggesting advanced technology and connectivity.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/06/07_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) June 9, 2026 [#### Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/)

* [CVE-2026-0257](https://unit42.paloaltonetworks.com/tag/cve-2026-0257/ "CVE-2026-0257")

* [Vulnerability](https://unit42.paloaltonetworks.com/tag/vulnerability/ "vulnerability")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/active-exploitation-of-pan-os-cve-2026-0257/ "Threat Brief: Active Exploitation of PAN-OS CVE-2026-0257")  
  ![Pictorial representation of CVE-2026-30300. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/06_Vulnerabilities_1920x900-3-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 6, 2026 [#### Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution](https://unit42.paloaltonetworks.com/captive-portal-zero-day/)

* [CVE-2026-0300](https://unit42.paloaltonetworks.com/tag/cve-2026-0300/ "CVE-2026-0300")

* [EarthWorm](https://unit42.paloaltonetworks.com/tag/earthworm/ "EarthWorm")

* [PAN-OS](https://unit42.paloaltonetworks.com/tag/pan-os/ "PAN-OS")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/captive-portal-zero-day/ "Threat Brief: Exploitation of PAN-OS Captive Portal Zero-Day for Unauthenticated Remote Code Execution")  
  ![Pictorial representation of a severe Linux vulnerability. Close-up of a woman wearing glasses and focusing intently on a computer screen.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/05/05_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) May 5, 2026 [#### Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/)

* [Containers](https://unit42.paloaltonetworks.com/tag/containers/ "Containers")

* [CVE-2026-31431](https://unit42.paloaltonetworks.com/tag/cve-2026-31431/ "CVE-2026-31431")

* [Kubernetes](https://unit42.paloaltonetworks.com/tag/kubernetes/ "Kubernetes")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/cve-2026-31431-copy-fail/ "Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years")  
  ![Pictorial representation of CVE-2023-33538. Abstract image of a glowing red Wi-Fi symbol on a circuit board, with intricate patterns and a futuristic appearance.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/04/04_Vulnerabilities_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) April 16, 2026 [#### A Deep Dive Into Attempted Exploitation of CVE-2023-33538](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/)

* [Botnet](https://unit42.paloaltonetworks.com/tag/botnet/ "botnet")

* [Command injection](https://unit42.paloaltonetworks.com/tag/command-injection/ "Command injection")

* [CVE-2023-33538](https://unit42.paloaltonetworks.com/tag/cve-2023-33538/ "CVE-2023-33538")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/exploitation-of-cve-2023-33538/ "A Deep Dive Into Attempted Exploitation of CVE-2023-33538")  
  ![Pictorial representation of BeyondTrust vulnerability CVE-2026-1731. Digital art depicting a stylized mountain range with vibrant blue and red hues. The peaks are accentuated by glowing particles and an abstract, starry backdrop, creating a futuristic landscape.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/14_Overview_1920x900-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 19, 2026 [#### VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/)

* [Bash](https://unit42.paloaltonetworks.com/tag/bash/ "bash")

* [CVE-2026-1731](https://unit42.paloaltonetworks.com/tag/cve-2026-1731/ "CVE-2026-1731")

* [PowerShell](https://unit42.paloaltonetworks.com/tag/powershell/ "PowerShell")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/beyondtrust-cve-2026-1731/ "VShell and SparkRAT Observed in Exploitation of BeyondTrust Critical Vulnerability (CVE-2026-1731)")  
  ![](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/02/AdobeStock_1020436911-786x440.jpeg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/07/top-threats.svg)High Profile Threats](https://unit42.paloaltonetworks.com/category/top-cyberthreats/) February 17, 2026 [#### Critical Vulnerabilities in Ivanti EPMM Exploited](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/)

* [CVE-2026-1281](https://unit42.paloaltonetworks.com/tag/cve-2026-1281/ "CVE-2026-1281")

* [CVE-2026-1340](https://unit42.paloaltonetworks.com/tag/cve-2026-1340/ "CVE-2026-1340")

* [Ivanti](https://unit42.paloaltonetworks.com/tag/ivanti/ "Ivanti")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/ivanti-cve-2026-1281-cve-2026-1340/ "Critical Vulnerabilities in Ivanti EPMM Exploited")  
  ![Pictorial representation of CVE-2025-0921. Digital illustration of a map of North America with interconnected glowing lines and dots symbolizing network connections across the continent.](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/01/06_Vulnerabilities_1920x900-2-1-786x368.jpg)  
  [![category icon](https://unit42.paloaltonetworks.com/wp-content/uploads/2024/06/icon-threat-research.svg)Threat Research](https://unit42.paloaltonetworks.com/category/threat-research/) January 30, 2026 [#### Privileged File System Vulnerability Present in a SCADA System](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/)

* [CVE-2025-0921](https://unit42.paloaltonetworks.com/tag/cve-2025-0921/ "CVE-2025-0921")

* [Privilege escalation](https://unit42.paloaltonetworks.com/tag/privilege-escalation/ "privilege escalation")

* [SCADA](https://unit42.paloaltonetworks.com/tag/scada/ "SCADA")  
  [Read now ![Right arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-right-arrow-withtail.svg)](https://unit42.paloaltonetworks.com/iconics-suite-cve-2025-0921/ "Privileged File System Vulnerability Present in a SCADA System")

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)

* ![Slider arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/slider-arrow-left.svg)  
  ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg) ![Enlarged Image]()  
  ![Newsletter](https://unit42.paloaltonetworks.com/wp-content/uploads/2026/03/unit42-footer-subscribe-desktop.png)  
  ![UNIT 42 Small Logo](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/palo-alto-logo-small.svg) Get updates from Unit 42

## Peace of mind comes from staying ahead of threats. Subscribe today.

Your Email

Subscribe for email updates to all Unit 42 threat research.  
By submitting this form, you agree to our [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use "Terms of Use") and acknowledge our [Privacy Statement.](https://www.paloaltonetworks.com/legal-notices/privacy "Privacy Statement")

This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply.

Invalid captcha!
Subscribe ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg) ![loader](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-loader.svg)  
{#footer} Products and Services

* [AI-Powered Network Security Platform](https://www.paloaltonetworks.com/network-security)

* [Secure AI by Design](https://www.paloaltonetworks.com/ai-security)

* [Prisma AIRS](https://www.paloaltonetworks.com/ai-security/prisma-airs)

* [AI Access Security](https://www.paloaltonetworks.com/sase/ai-access-security)

* [Cloud Delivered Security Services](https://www.paloaltonetworks.com/network-security/security-subscriptions)

* [Advanced Threat Prevention](https://www.paloaltonetworks.com/network-security/advanced-threat-prevention)

* [Advanced URL Filtering](https://www.paloaltonetworks.com/network-security/advanced-url-filtering)

* [Advanced WildFire](https://www.paloaltonetworks.com/network-security/advanced-wildfire)

* [Advanced DNS Security](https://www.paloaltonetworks.com/network-security/advanced-dns-security)

* [Enterprise Data Loss Prevention](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Enterprise IoT Security](https://www.paloaltonetworks.com/network-security/enterprise-device-security)

* [Medical IoT Security](https://www.paloaltonetworks.com/network-security/medical-device-security)

* [Industrial OT Security](https://www.paloaltonetworks.com/network-security/ot-security-solution)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [Next-Generation Firewalls](https://www.paloaltonetworks.com/network-security/next-generation-firewall)

* [Hardware Firewalls](https://www.paloaltonetworks.com/network-security/hardware-firewall-innovations)

* [Software Firewalls](https://www.paloaltonetworks.com/network-security/software-firewalls)

* [Strata Cloud Manager](https://www.paloaltonetworks.com/network-security/strata-cloud-manager)

* [SD-WAN for NGFW](https://www.paloaltonetworks.com/network-security/sd-wan-subscription)

* [PAN-OS](https://www.paloaltonetworks.com/network-security/pan-os)

* [Panorama](https://www.paloaltonetworks.com/network-security/panorama)

* [Secure Access Service Edge](https://www.paloaltonetworks.com/sase)

* [Prisma SASE](https://www.paloaltonetworks.com/sase)

* [Application Acceleration](https://www.paloaltonetworks.com/sase/app-acceleration)

* [Autonomous Digital Experience Management](https://www.paloaltonetworks.com/sase/adem)

* [Enterprise DLP](https://www.paloaltonetworks.com/sase/enterprise-data-loss-prevention)

* [Prisma Access](https://www.paloaltonetworks.com/sase/access)

* [Prisma Browser](https://www.paloaltonetworks.com/sase/prisma-browser)

* [Prisma SD-WAN](https://www.paloaltonetworks.com/sase/sd-wan)

* [Remote Browser Isolation](https://www.paloaltonetworks.com/sase/remote-browser-isolation)

* [SaaS Security](https://www.paloaltonetworks.com/sase/saas-security)

* [AI-Driven Security Operations Platform](https://www.paloaltonetworks.com/cortex)

* [Cloud Security](https://www.paloaltonetworks.com/cortex/cloud)

* [Cortex Cloud](https://www.paloaltonetworks.com/cortex/cloud)

* [Application Security](https://www.paloaltonetworks.com/cortex/cloud/application-security)

* [Cloud Posture Security](https://www.paloaltonetworks.com/cortex/cloud/cloud-posture-security)

* [Cloud Runtime Security](https://www.paloaltonetworks.com/cortex/cloud/runtime-security)

* [Prisma Cloud](https://www.paloaltonetworks.com/prisma/cloud)

* [AI-Driven SOC](https://www.paloaltonetworks.com/cortex)

* [Cortex XSIAM](https://www.paloaltonetworks.com/cortex/cortex-xsiam)

* [Cortex XDR](https://www.paloaltonetworks.com/cortex/cortex-xdr)

* [Cortex XSOAR](https://www.paloaltonetworks.com/cortex/cortex-xsoar)

* [Cortex Xpanse](https://www.paloaltonetworks.com/cortex/cortex-xpanse)

* [Unit 42 Managed Detection \& Response](https://www.paloaltonetworks.com/unit42/respond/managed-detection-response)

* [Managed XSIAM](https://www.paloaltonetworks.com/cortex/managed-xsiam)

* [Next-Generation Identity Security](https://www.paloaltonetworks.com/idira)

* [Privileged Access Management](https://www.paloaltonetworks.com/idira/human/privileged-access-management)

* [Identity and Access Management](https://www.paloaltonetworks.com/idira/human/identity-and-access-management)

* [Endpoint Privilege Manager](https://www.paloaltonetworks.com/idira/human/endpoint-privilege-manager)

* [Identity Governance](https://www.paloaltonetworks.com/idira/human/identity-governance)

* [Workforce Password Management](https://www.paloaltonetworks.com/idira/human/workforce-password-management)

* [Agentic Identities](https://www.paloaltonetworks.com/idira/agentic)

* [Secrets Management](https://www.paloaltonetworks.com/idira/machine/secrets-management)

* [Unified Secrets Governance](https://www.paloaltonetworks.com/idira/machine/unified-secrets-governance)

* [Application Credentials Delivery](https://www.paloaltonetworks.com/idira/machine/application-credentials-delivery)

* [Vendor Privileged Access](https://www.paloaltonetworks.com/idira/human/vendor-privileged-access)

* [Threat Intel and Incident Response Services](https://www.paloaltonetworks.com/unit42)

* [Prepare for Emerging Risks](https://www.paloaltonetworks.com/unit42/prepare-for-emerging-risks/continuous-frontier-ai-defense)

* [Strengthen Your Defenses](https://www.paloaltonetworks.com/unit42/strengthen-your-defenses)

* [Build Your Security Strategy](https://www.paloaltonetworks.com/unit42/build-your-security-strategy)

* [Understand the Adversary](https://www.paloaltonetworks.com/unit42/threat-intelligence)

* [Respond to a Cyber Attack](https://www.paloaltonetworks.com/unit42/respond)  
  Company

* [About Us](https://www.paloaltonetworks.com/about-us)

* [Careers](https://jobs.paloaltonetworks.com/en/)

* [Contact Us](https://www.paloaltonetworks.com/company/contact-sales)

* [Corporate Responsibility](https://www.paloaltonetworks.com/about-us/corporate-responsibility)

* [Customers](https://www.paloaltonetworks.com/customers)

* [Investor Relations](https://investors.paloaltonetworks.com/)

* [Location](https://www.paloaltonetworks.com/about-us/locations)

* [Newsroom](https://www.paloaltonetworks.com/company/newsroom)  
  Popular Links

* [Blog](https://www.paloaltonetworks.com/blog/)

* [Communities](https://www.paloaltonetworks.com/communities)

* [Content Library](https://www.paloaltonetworks.com/resources)

* [Cyberpedia](https://www.paloaltonetworks.com/cyberpedia)

* [Event Center](https://events.paloaltonetworks.com/)

* [Manage Email Preferences](https://start.paloaltonetworks.com/preference-center)

* [Products A-Z](https://www.paloaltonetworks.com/products/products-a-z)

* [Product Certifications](https://www.paloaltonetworks.com/legal-notices/trust-center/certifications)

* [Report a Vulnerability](https://www.paloaltonetworks.com/security-disclosure)

* [Sitemap](https://www.paloaltonetworks.com/sitemap)

* [Tech Docs](https://docs.paloaltonetworks.com/)

* [Unit 42](https://unit42.paloaltonetworks.com/)

* [Do Not Sell or Share My Personal Information](https://panwedd.exterro.net/portal/dsar.htm?target=panwedd)
  ![Palo Alto Networks Logo](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/pan-logo-dark.svg)

* [Privacy](https://www.paloaltonetworks.com/legal-notices/privacy)

* [Trust Center](https://www.paloaltonetworks.com/legal-notices/trust-center)

* [Terms of Use](https://www.paloaltonetworks.com/legal-notices/terms-of-use)

* [Documents](https://www.paloaltonetworks.com/legal)

Copyright © 2026 Palo Alto Networks. All Rights Reserved

* [![Youtube](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/youtube-black.svg)](https://www.youtube.com/user/paloaltonetworks)
* [![Podcast](https://www.paloaltonetworks.com/content/dam/pan/en_US/images/icons/podcast.svg)](https://www.paloaltonetworks.com/podcasts/threat-vector)
* [![Facebook](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/facebook-black.svg)](https://www.facebook.com/PaloAltoNetworks/)
* [![LinkedIn](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/linkedin-black.svg)](https://www.linkedin.com/company/palo-alto-networks)
* [![Twitter](https://www.paloaltonetworks.com/etc/clientlibs/clean/imgs/social/twitter-x-black.svg)](https://twitter.com/PaloAltoNtwks)
* EN  
  Select your language  
  ![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg) ![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg) ![Close button](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/close-modal.svg)

### Default Heading

Read the article ![Right Arrow](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/right-arrow.svg)  
Seekbar

![Play](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-play-icon.svg) ![Pause](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/player-pause-icon1.svg)  
![Volume](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-volume.svg)  
Volume
![Minimize](https://unit42.paloaltonetworks.com/wp-content/themes/unit42-v6/dist/images/icons/icon-minimize.svg)
