ZeroHour
The Recordpublished ()ingested

Windows flaw may have been exploited with Black Basta ransomware before it was patched

criticalRansomwareimportance 60CVE-2024-26169

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-26169
Local Privilege Escalation in Microsoft Windows Error Reporting Service (CVE-2024-26169)

Microsoft Windows Error Reporting Service contains an improper privilege management flaw (CWE-269) that allows an elevation of privilege, rated CVSS 3.1 7.8 with a local attack vector, low attack complexity, and no user interaction required. An attacker who can already execute code with low privileges on a vulnerable machine — e.g., after phishing, malware, or another exploit — can trigger the flaw to gain elevated rights, with high impact on confidentiality, integrity, and availability, a step CISA notes has known ransomware use. Any unpatched deployment of Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server 2008/2012/2016/2019 is affected. CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-06-13, and related reporting links a Windows zero-day exploited before patching to Black Basta ransomware operations. EPSS estimates a 4.0% probability of exploitation within 30 days (90th percentile), and no public proof-of-concept code is known.

Do: Apply Microsoft's June 2024 security updates (the release that fixed this CVE) to all listed Windows 10, Windows 11, and Windows Server versions, per the KEV-required action to apply vendor updates or discontinue use. Because the flaw requires prior local code execution and CISA lists known ransomware use, treat unpatched Windows hosts as at risk and check them for post-exploitation signs such as unexpected SYSTEM-level process activity, new persistence, or ransomware staging.

7.84% KEV ransomware
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019
mass≈1 billion+ unpatched Windows 10/11 and Windows Server installations worldwide
Full article295 words · extracted from therecord.media · click to collapse

A group operating the notorious Black Basta ransomware may have exploited a recently patched Windows vulnerability as a zero-day, researchers have found.

In March, a high-severity flaw — tracked as CVE-2024-26169 — was discovered in the Windows Error Reporting Service, a feature in Windows that helps Microsoft identify and fix problems with the operating system and other software.

The successful exploitation of the vulnerability could allow attackers to gain control over the entire system.

The flaw was patched in March, and at the time Microsoft stated there was no evidence of its exploitation in the wild.

However, a new analysis by Symantec of an exploit tool deployed in recent attacks revealed evidence that it could have been made prior to patching, meaning at least one group may have been exploiting the vulnerability as a zero-day.

“This issue was addressed in March, and customers who apply the fix are protected. Our security software also includes detections to protect against the malware,” a Microsoft spokesperson said.

This exploit was used in a recently attempted ransomware attack similar to those described in a Microsoft report detailing Black Basta activity. The hacker group operating the ransomware, known as Cardinal or Storm-1811, did not succeed in deploying a ransomware payload in the attack, researchers said.

Cardinal introduced Black Basta in April 2022, and from its inception the ransomware was closely associated with the Qakbot botnet, which appeared to be its primary infection vector.

Qakbot was one of the world’s most prolific malware distribution botnets until it was taken down in August 2023, leading to a decline in Black Basta activity. Cardinal has since resumed attacks and now appears to have switched to working with the operators of the DarkGate loader to obtain access to potential victims, according to Symantec.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/black-basta-ransomware-zero-day-windows