ZeroHour
Security Affairspublished ()ingested @securityaffairs

SECURITY AFFAIRS MALWARE NEWSLETTER

criticalMalware exploited in the wildimportance 60CVE-2024-43451

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43451
NTLMv2 Hash Disclosure Spoofing Vulnerability in Microsoft Windows

CVE-2024-43451 is a flaw in the NTLM authentication implementation of Microsoft Windows that lets an attacker obtain a user's NTLMv2 authentication hash. It requires user interaction: a victim who engages with attacker-supplied content, such as a crafted file or an attacker-controlled file path/URL reference (consistent with the CWE-73 external control of file name weakness), causes Windows to silently initiate an NTLM authentication to a hostile host, leaking the hash. An attacker who captures the hash can crack it offline to recover the user's password or relay it to authenticate (spoof) as that user to other services, enabling credential theft and lateral movement. Any unpatched installation of the listed Windows 10, Windows 11, and Windows Server 2008/2012/2016/2019 versions is exposed, which covers essentially every mainstream Windows estate current in late 2024. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12, researchers have reported Russian-linked attackers using it in phishing campaigns delivering RAT malware, and EPSS assigns an 84.1% probability of exploitation within 30 days, though no public proof-of-concept code is known.

Do: Apply Microsoft's November 2024 Patch Tuesday security updates (or later cumulative updates) to all listed Windows 10/11 client and Windows Server versions; the KEV listing makes patching mandatory for US federal agencies. As interim mitigation, block outbound SMB/HTTP NTLM authentication to untrusted destinations (e.g., firewall outbound TCP 445 from endpoints) and, where feasible, restrict NTLM in favor of Kerberos via Group Policy. Hunt for phishing emails containing crafted files and for unexpected outbound authentication attempts from workstations, and rotate credentials for accounts that may have authenticated to untrusted hosts before patching.

6.584% KEV
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 22H2, 23H2, 24H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019
masshundreds of millions of Windows 10/11 endpoints and Windows Server 2008-2019 instances worldwide
Full article221 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 17, 2024

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.

New Campaign Uses Remcos RAT to Exploit Victims

Bengal cat lovers in Australia get psspsspss’d in Google-driven Gootloader campaign      

Ymir: new stealthy ransomware in the wild  

ShrinkLocker (+Decryptor): From Friend to Foe, and Back Again   

Stealthy Attributes of APT Lazarus: Evading Detection with Extended Attributes  

Glove Stealer: Leveraging IElevator to Bypass App-Bound Encryption & Steal Sensitive Data  

Botnet exploits GeoVision zero-day to install Mirai malware

Unmasking the Shadows: Pinpoint the Implementations of Anti-Dynamic Analysis Techniques in Malware Using LLM

Chaotic-Based Shellcode Encryption: A New Strategy for Bypassing Antivirus Mechanisms  

Malware Spotlight:  A Deep-Dive Analysis of WezRat  

APT Actors Embed Malware within macOS Flutter Applications

Hamas-affiliated Threat Actor WIRTE Continues its Middle East Operations and Moves to Disruptive Activity  

CVE-2024-43451: A New Zero-Day Vulnerability Exploited in the wild

New PXA Stealer targets government and education sectors for sensitive information

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/171089/malware/security-affairs-malware-newsletter-round-20.html