“This vulnerability represents a classic DLL hijacking scenario with a challenging timing element,” John Ostrowski of Compass Security said to Cyber Security News. Cyber Security News is a Dedicated News Platform For Cyber News, Cyber Attack News, Hacking News & Vulnerability Analysis. The vulnerability affects Windows 11 systems with the “Mobile devices” feature, which allows users to link their phones to use the phone’s camera as a webcam. The vulnerability, tracked as CVE-2025-24076, exploits a weakness in Windows 11’s “Mobile devices” feature through a sophisticated DLL hijacking technique. Researchers found that the file CrossDevice.Streaming.Source.dll, located in the user-modifiable %PROGRAMDATA%\CrossDevice\ directory, is loaded first by a regular user process and then by a high-privileged system process. A critical vulnerability in Windows 11 allowed attackers to escalate from a low-privileged user to full system administrator rights in just 300 milliseconds. Users are strongly encouraged to apply the latest Windows security updates to mitigate these vulnerabilities. Gurubaran is a co-founder of Cyber Security News and GBHackers On Security.
This Cyber News was published on cybersecuritynews.com. Publication date: Wed, 16 Apr 2025 05:40:23 +0000