Urgent Windows Update: Russian Exploits and Zero-Day Threats Addressed

1 min read
Source: SecurityWeek
Urgent Windows Update: Russian Exploits and Zero-Day Threats Addressed
Photo: SecurityWeek
TL;DR Summary

A newly patched Windows zero-day vulnerability, CVE-2024-43451, allows minimal user interaction, such as file deletion or right-clicking, to trigger exploitation. This medium-severity flaw in the MSHTM engine can lead to NTLMv2 hash theft and pass-the-hash attacks. ClearSky reports that Russian threat actors have exploited this vulnerability in attacks on Ukrainian entities, using phishing emails to distribute malicious files. The vulnerability is more easily exploited on Windows 10 and 11, and CERT-UA attributes the attacks to a group suspected to be Russian.

Share this article

Reading Insights

Total Reads

0

Unique Readers

9

Time Saved

2 min

vs 3 min read

Condensed

82%

45881 words

Want the full story? Read the original article

Read on SecurityWeek