Skip to content

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology
  • Vulnerability

The SNEK Initiative Drops “Eris”: New Post-Exploit Framework Abuses Windows Fax Service for SYSTEM Root

by Nam Phong · May 19, 2026

A novel exploitation framework designed to escalate execution privileges within the Windows environment, designated as Eris, has emerged in the public domain. The architect of the project asserts that the methodology facilitates the spawning of an interactive command terminal endowed with full systemic authority within an active user session, achieved by manipulating the native Windows Fax Service.

The Eris execution chain operates through a bifurcated sequence. In the introductory phase, the software orchestrates an evasion of the Windows User Account Control (UAC) interface by exploiting the legacy Silent Cleanup task scheduling mechanism. Having successfully secured elevated privileges, the payload modifies the system registry to register a counterfeit virtual fax device provider and reconfigures the Fax Service initialization parameters to mandate execution under the Local System security context. Upon the subsequent recycling of the service daemon, it processes the malicious payload, ultimately delivering a command shell maintaining absolute system privileges.

The creator of the framework characterizes the initial UAC bypass as a prerequisite “sacrifice,” an operational catalyst without which the core architecture of the second-tier attack vector cannot be initialized.

Validating the operational efficacy of Eris necessitates an environment equipped with the g++ compiler from the MinGW-w64 software suite or an active MSYS2 deployment. The project repository encapsulates the source code for two discrete components: the core payload library and the primary executable loader binary. Once compiled and executed by an operator, the toolkit yields an elevated terminal session.

Furthermore, the developer has distributed compiled, standalone binaries tailored for practitioners seeking to forgo manual compilation routines.

The integration architecture of Eris targets localized deployment scenarios, functioning on the presumption that an adversary has already established a primary foothold within the system architecture. Security analysts classify utilities of this typology as post-exploitation instruments, routinely weaponized by network interlopers to achieve persistent infrastructure dominance and facilitate lateral movement across enterprise Windows environments.

Related coverage

  • ENDLESSDOORS: Hidden Remote Control Found in Zbtlink Router Firmware
  • iCloud Private Relay IP Leak: Three WebKit Flaws Expose Real User IP Addresses
  • AI Agents Go Rogue: Mythos 5 and GPT-5.6 Sol Escape Cyber Testbed, Target Real GitHub
  • Critical N-central Vulnerability Exploited in MSP Attacks
  • Google Password Manager Passkey Bypasses Uncovered

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Tags: Active Session TakeoverEris Exploitlocal privilege escalationMinGW-w64 CompilationPost-Exploitation ToolRegistry HijackSilent Cleanup TaskThe SNEK InitiativeUser Account Control BypassWindows Fax Service

Follow:

  • Next story Suspected Iranian Hackers Breach US Gas Station Fuel Monitoring Systems
  • Previous story VulnCheck Warns of Active Cisco Zero-Day and Massive Server Exploitation Wave

  • Recent Posts
  • Popular Posts
  • Tags
  • ENDLESSDOORS hidden backdoor in Zbtlink router firmware discovered by VulnCheck using rctl remote control Linux component masquerading as kernel threads with root access

    Vulnerability

    ENDLESSDOORS: Hidden Remote Control Found in Zbtlink Router Firmware

    August 7, 2026

  • iCloud Private Relay IP leak via three WebKit vulnerabilities DNS prefetch WebAuthn WebTransport bypassing proxy on iOS iPadOS macOS Safari and third-party browsers

    Vulnerability

    iCloud Private Relay IP Leak: Three WebKit Flaws Expose Real User IP Addresses

    August 7, 2026

  • Malware bypassing DNS security by connecting directly to C2 IP addresses Phorpiex SectopRAT Mozi botnet ZT-IP firewall detection Unit 42

    Malware

    45% of Malware C2 Traffic Bypasses DNS by Connecting Directly to IP Addresses

    August 7, 2026

  • Tactical police unit responding to coordinated swatting attacks with emergency vehicles

    Cyber Security

    FBI Warns of Coordinated Swatting Attacks Nationwide

    August 7, 2026

  • Tails 7.10.1 emergency patch for CVE-2026-64560 Linux kernel POSIX CPU timer race condition allowing Tor Browser privilege escalation and user deanonymization

    Linux

    Tails 7.10.1: Emergency Patch for CVE-2026-64560 That Could Deanonymize Users

    August 7, 2026

  • VMware vCenter vulnerability CVE-2026-59309 and CVE-2026-59310 rated CVSS 9.8 authentication bypass

    Vulnerability Report

    VMware vCenter CVE-2026-59309 and CVE-2026-59310 Rated CVSS 9.8

    July 29, 2026

  • OpenSUSE Leap 15.4 Beta releases, Linux distributions

    Linux

    OpenSUSE Leap 15.4 Beta releases, Linux distributions

    May 30, 2020

  • Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    Linux

    Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    March 1, 2019

  • GhostBSD 23.10.1 released, FreeBSD distribution

    Linux

    GhostBSD 23.10.1 released, FreeBSD distribution

    May 1, 2020

  • Solus 4.4 Fortitude releases, Linux distribution

    Linux

    Solus 4.4 Fortitude releases, Linux distribution

    January 26, 2020

  • AI AI security Android Apple APT BOTNET CISA cloud security Critical Infrastructure cryptocurrency cyberattack cybercrime Cyber Espionage cybersecurity Cybersecurity 2026 data breach Github google hacking Infosec InfoSec 2026 Infostealer Linux Linux Kernel malware Microsoft network security open source Penetration Testing phishing privacy privilege escalation Prompt Injection ransomware RCE remote code execution security Social Engineering supply chain attack Tech News 2026 threat intelligence vulnerability windows Windows 11 zero-day
  • Home
  • About Us
  • Contact Us
  • DMCA NOTICE
  • Privacy Policy

Information Security News © 2026. All Rights Reserved.

Powered by  - Designed with Hueman Pro