Microsoft: Zero-day bug used in ransomware attacks on US real estate firms
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-24983 | Windows Win32k Use-After-Free Privilege Escalation Zero-Day (CVE-2025-24983) CVE-2025-24983 is a use-after-free memory-safety flaw (CWE-416) in the Windows Win32 kernel (Win32k) subsystem that allows an attacker who already has limited local access on a Windows machine to elevate privileges; it requires low privileges and no user interaction but carries high attack complexity (CVSS 3.1: 7.0). Because it is a local elevation-of-privilege bug rather than remote code execution, it is typically used to deepen control after an initial foothold, and the high attack complexity makes exploitation less turnkey than typical Win32k EoP bugs. Microsoft shipped fixes among 57 March 2025 Patch Tuesday updates on March 11, 2025, flagging this as one of six actively exploited zero-days, and CISA added it to the Known Exploited Vulnerabilities catalog the same day (ransomware use: unknown). Anyone running the affected legacy releases — Windows 10 1507 and 1607 and Windows Server 2008, 2012, and 2016 — without the March 2025 updates is exposed, especially environments where multiple or less-trusted users can log on locally. No public proof-of-concept is known and EPSS puts the 30-day exploitation probability at about 1.3%; note that same-cycle headlines about a Windows zero-day exploited in ransomware attacks on US real estate firms (PipeMagic trojan) cover the March Patch Tuesday zero-days without the provided data confirming that CVE-2025-24983 specifically was the one used in those ransomware attacks. Do: Apply the March 2025 Patch Tuesday security updates (released March 11, 2025) to every affected Windows 10 1507/1607 and Windows Server 2008/2012/2016 host, since in-the-wild exploitation is confirmed and no public PoC or workaround details are available. Prioritize systems where untrusted or semi-trusted users can log on locally, and confirm compliance with CISA BOD 22-01 requirements for federal systems. After patching, hunt for signs of prior compromise (unexpected local administrator activity, suspicious service or task creation) because an EoP bug of this type is usually exercised after an initial foothold. | 7.0 | 1% | KEV |
| mass≈tens of millions of Windows endpoints and servers on the affected legacy editions | |
| CVE-2025-29824 | Use-After-Free Privilege Escalation in Microsoft Windows CLFS Driver (Actively Exploited) CVE-2025-29824 is a use-after-free flaw (CWE-416) in the Windows Common Log File System (CLFS) kernel driver, scored 7.8 (High) with a local attack vector, low privileges required, and no user interaction. An authorized local attacker can trigger it by interacting with CLFS-managed log files in a way that references freed kernel memory. Successful exploitation elevates the attacker's local privileges, typically to SYSTEM, providing full control of the host that can be chained into ransomware deployment or lateral movement. Any unpatched system running the listed Windows 10, Windows 11, or Windows Server versions is affected. The flaw was exploited as a zero-day — reportedly by Play ransomware — before Microsoft shipped fixes in the April 2025 Patch Tuesday release; it was added to CISA's KEV catalog on 2025-04-08 with known ransomware use, and EPSS estimates a 13.9% probability of continued exploitation over 30 days (96th percentile). Do: Apply Microsoft's April 2025 Patch Tuesday security updates for your Windows version immediately — the vendor update is the only complete fix, and the flaw is on the KEV list with known ransomware use, so prioritize servers and endpoints used by privileged users. Until patched, limit untrusted local code execution and review hosts for post-exploitation privilege escalation; public detection and mitigation scripts (e.g., Vicarius) are available to help hunt for exploitation. Federal agencies must apply the vendor mitigations per BOD 22-01 deadlines or discontinue use of affected versions. | 7.8 | 14% | KEV ransomware PoC ×2 |
| massHundreds of millions of Windows devices worldwide |
Full article608 words · extracted from therecord.media · click to collapse
Hackers used a recently-patched zero-day vulnerability to attack real estate companies in the U.S. and several other organizations in Saudi Arabia, Spain and Venezuela Microsoft published a blog post on Tuesday about the bug alongside its larger Patch Tuesday release, detailing how hackers exploited the vulnerability and used a strain of malware called PipeMagic before deploying ransomware on victims. The zero-day vulnerability, tagged as CVE-2025-29824, impacts Windows Common Log File System Driver (CLFS) – a frequent target of ransomware gangs. CLFS is a logging framework that was first introduced by Microsoft in Windows Server 2003 R2 and included in later Windows operating systems. It effectively allows users to record a series of steps required for some actions so that they can be either reproduced accurately in the future or undone. The “small number of targets” of the campaign include IT and real estate companies in the U.S., financial firms in Venezuela, a software company in Spain and retail organizations in Saudi Arabia. Microsoft released a security update for CVE-2025-29824 on Tuesday. Microsoft did not provide more information on the hackers behind the campaign, only referring to the threat actors as “Storm-2460.” CVE-2025-29824 was the only Patch Tuesday bug from Microsoft added to the Cybersecurity and Infrastructure Security Agency’s catalog of exploited vulnerabilities on Tuesday. Microsoft researchers and several other cybersecurity experts said CVE-2025-29824 was concerning because it allows hackers to elevate their privileges and access in a system that has already been broken into. “This type of vulnerability is especially dangerous in post-compromise scenarios,” said Ben McCarthy, lead cybersecurity engineer at Immersive. “Once an attacker has a foothold on a machine — via phishing, malware, or other vectors — they can exploit the… bug to elevate privileges, maintain persistence and move laterally across an enterprise network. It is a favored class of vulnerability in targeted attacks and ransomware operations.” Microsoft added that ransomware gangs specifically value post-compromise bugs like CVE-2025-29824 because they “enable them to escalate initial access, including handoffs from commodity malware distributors, into privileged access.” The increased access allows them to detonate ransomware and create a wider blast radius, causing significantly more damage. In the attacks tracked by Microsoft, the incident responders were unable to figure out how the hackers gained their initial access. But once they had access, the threat actors deployed PipeMagic, which researchers at ESET and Kaspersky have been documenting for years. ESET previously spotlighted the malware’s use during exploitation of CVE-2025-24983, another recently-patched Microsoft bug. Microsoft was not able to obtain samples of the ransomware for analysis but found two clues in the ransom notes that were previously tied to the RansomEXX ransomware family. Immersive’s McCarthy noted that while Microsoft has confirmed the bug is being actively exploited, they have not released a specific patch for Windows 10 32-bit or 64-bit systems. “The lack of a patch leaves a critical gap in defense for a wide portion of the Windows ecosystem,” he said. “In the absence of a security update, organizations should take proactive steps to mitigate risk. Security teams are advised to monitor the CLFS driver closely using [Endpoint Detection and Response]/[Extended Detection and Response] tools.” Seth Hoyt, senior security engineer at Automox, added that with the privileges offered by the vulnerability, a hacker could install programs, disable protections and move laterally “with few barriers.”
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-zero-day-used-ransomware-attack-real-estate