Skip to content

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology

Information Security News

  • Home
  • Cyber Security
  • Cybercriminals
  • Data Leak
  • Google
    • Android
  • Information Security
  • Linux
  • Malware
  • Microsoft
    • Windows
  • Open Source Tool
  • Vulnerability
  • Technology
  • Vulnerability

The SNEK Initiative Drops “Eris”: New Post-Exploit Framework Abuses Windows Fax Service for SYSTEM Root

by Nam Phong · May 19, 2026

A novel exploitation framework designed to escalate execution privileges within the Windows environment, designated as Eris, has emerged in the public domain. The architect of the project asserts that the methodology facilitates the spawning of an interactive command terminal endowed with full systemic authority within an active user session, achieved by manipulating the native Windows Fax Service.

The Eris execution chain operates through a bifurcated sequence. In the introductory phase, the software orchestrates an evasion of the Windows User Account Control (UAC) interface by exploiting the legacy Silent Cleanup task scheduling mechanism. Having successfully secured elevated privileges, the payload modifies the system registry to register a counterfeit virtual fax device provider and reconfigures the Fax Service initialization parameters to mandate execution under the Local System security context. Upon the subsequent recycling of the service daemon, it processes the malicious payload, ultimately delivering a command shell maintaining absolute system privileges.

The creator of the framework characterizes the initial UAC bypass as a prerequisite “sacrifice,” an operational catalyst without which the core architecture of the second-tier attack vector cannot be initialized.

Validating the operational efficacy of Eris necessitates an environment equipped with the g++ compiler from the MinGW-w64 software suite or an active MSYS2 deployment. The project repository encapsulates the source code for two discrete components: the core payload library and the primary executable loader binary. Once compiled and executed by an operator, the toolkit yields an elevated terminal session.

Furthermore, the developer has distributed compiled, standalone binaries tailored for practitioners seeking to forgo manual compilation routines.

The integration architecture of Eris targets localized deployment scenarios, functioning on the presumption that an adversary has already established a primary foothold within the system architecture. Security analysts classify utilities of this typology as post-exploitation instruments, routinely weaponized by network interlopers to achieve persistent infrastructure dominance and facilitate lateral movement across enterprise Windows environments.

Related coverage

  • CISA Warns of Active Exploitation of Old Linux Flaws
  • Critical Vulnerability Found in D-Link DIR-822A Routers
  • Meta Muse Zero-Day Let Local Apps Hijack the AI Agent
  • Arista VeloCloud Orchestrator Flaw Under Active Attack
  • Four Ancient Linux Kernel Flaws Get Root Exploits

Support Our Threat Intelligence

If you find our technology report and cybersecurity news helpful, consider supporting our work.

Buy Me a Coffee Logo Buy Me a Coffee PayPal
Crypto QR Code
USDT (TRC20):
TN8BdV8cp4T1Cd28gK9qTAnZknzzuwyUtm
USDT (ERC20):
0x3725e1a7d3bc5765499fa6aaafe307fabcd75bce

Tags: Active Session TakeoverEris Exploitlocal privilege escalationMinGW-w64 CompilationPost-Exploitation ToolRegistry HijackSilent Cleanup TaskThe SNEK InitiativeUser Account Control BypassWindows Fax Service

Follow:

  • Next story Suspected Iranian Hackers Breach US Gas Station Fuel Monitoring Systems
  • Previous story VulnCheck Warns of Active Cisco Zero-Day and Massive Server Exploitation Wave

  • Recent Posts
  • Popular Posts
  • Tags
  • DJI drone Bluetooth vulnerability CVE-2026-78306 allowing unauthenticated DUML commands mid-flight

    Vulnerability

    DJI Bluetooth Flaw Lets Nearby Attackers Hijack Drones

    September 23, 2026

  • Linux kernel source code vulnerability analysis warning

    Vulnerability

    CISA Warns of Active Exploitation of Old Linux Flaws

    September 23, 2026

  • D-Link DIR-822A router vulnerability warning graphic

    Vulnerability

    Critical Vulnerability Found in D-Link DIR-822A Routers

    September 23, 2026

  • Meta Muse macOS zero-day not-a-mused hijacking dictation and authentication tokens

    Vulnerability

    Meta Muse Zero-Day Let Local Apps Hijack the AI Agent

    September 23, 2026

  • GPT-6 Sol and Luna models launching for Codex and ChatGPT Work with lower API pricing

    Technology

    GPT-6 Sol and Luna Arrive With Prices Cut in Half

    September 23, 2026

  • WeChat zero-click worm exploiting WeChat VoIP memory corruption

    Vulnerability

    WeChat Zero-Click Worm Exposed in New Security Advisory

    September 9, 2026

  • OpenSUSE Leap 15.4 Beta releases, Linux distributions

    Linux

    OpenSUSE Leap 15.4 Beta releases, Linux distributions

    May 30, 2020

  • Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    Linux

    Ubuntu 16.04.6 LTS released: fix security vulnerabilities

    March 1, 2019

  • GhostBSD 23.10.1 released, FreeBSD distribution

    Linux

    GhostBSD 23.10.1 released, FreeBSD distribution

    May 1, 2020

  • Solus 4.4 Fortitude releases, Linux distribution

    Linux

    Solus 4.4 Fortitude releases, Linux distribution

    January 26, 2020

  • AI AI security Android Apple APT BOTNET CISA cloud security Critical Infrastructure cryptocurrency cyberattack cybercrime Cyber Espionage cybersecurity Cybersecurity 2026 data breach DLL Sideloading Github google hacking Infosec InfoSec 2026 Infostealer Linux Linux Kernel malware Microsoft network security open source phishing privacy privilege escalation Prompt Injection ransomware RCE remote code execution security Social Engineering supply chain attack Tech News 2026 threat intelligence vulnerability windows Windows 11 zero-day
  • Home
  • About Us
  • Contact Us
  • DMCA NOTICE
  • Privacy Policy

Information Security News © 2026. All Rights Reserved.

Powered by  - Designed with Hueman Pro