SECURITY AFFAIRS MALWARE NEWSLETTER
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-43451 | NTLMv2 Hash Disclosure Spoofing Vulnerability in Microsoft Windows CVE-2024-43451 is a flaw in the NTLM authentication implementation of Microsoft Windows that lets an attacker obtain a user's NTLMv2 authentication hash. It requires user interaction: a victim who engages with attacker-supplied content, such as a crafted file or an attacker-controlled file path/URL reference (consistent with the CWE-73 external control of file name weakness), causes Windows to silently initiate an NTLM authentication to a hostile host, leaking the hash. An attacker who captures the hash can crack it offline to recover the user's password or relay it to authenticate (spoof) as that user to other services, enabling credential theft and lateral movement. Any unpatched installation of the listed Windows 10, Windows 11, and Windows Server 2008/2012/2016/2019 versions is exposed, which covers essentially every mainstream Windows estate current in late 2024. Exploitation is confirmed: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12, researchers have reported Russian-linked attackers using it in phishing campaigns delivering RAT malware, and EPSS assigns an 84.1% probability of exploitation within 30 days, though no public proof-of-concept code is known. Do: Apply Microsoft's November 2024 Patch Tuesday security updates (or later cumulative updates) to all listed Windows 10/11 client and Windows Server versions; the KEV listing makes patching mandatory for US federal agencies. As interim mitigation, block outbound SMB/HTTP NTLM authentication to untrusted destinations (e.g., firewall outbound TCP 445 from endpoints) and, where feasible, restrict NTLM in favor of Kerberos via Group Policy. Hunt for phishing emails containing crafted files and for unexpected outbound authentication attempts from workstations, and rotate credentials for accounts that may have authenticated to untrusted hosts before patching. | 6.5 | 84% | KEV |
| masshundreds of millions of Windows 10/11 endpoints and Windows Server 2008-2019 instances worldwide |
Full article221 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
November 17, 2024

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.
New Campaign Uses Remcos RAT to Exploit Victims
Bengal cat lovers in Australia get psspsspss’d in Google-driven Gootloader campaign
Ymir: new stealthy ransomware in the wild
ShrinkLocker (+Decryptor): From Friend to Foe, and Back Again
Stealthy Attributes of APT Lazarus: Evading Detection with Extended Attributes
Glove Stealer: Leveraging IElevator to Bypass App-Bound Encryption & Steal Sensitive Data
Botnet exploits GeoVision zero-day to install Mirai malware
Chaotic-Based Shellcode Encryption: A New Strategy for Bypassing Antivirus Mechanisms
Malware Spotlight: A Deep-Dive Analysis of WezRat
APT Actors Embed Malware within macOS Flutter Applications
CVE-2024-43451: A New Zero-Day Vulnerability Exploited in the wild
New PXA Stealer targets government and education sectors for sensitive information
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/171089/malware/security-affairs-malware-newsletter-round-20.html