SECURITY AFFAIRS MALWARE NEWSLETTER
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38178 | Unauthenticated RCE via Memory Corruption in Microsoft Windows Scripting Engine CVE-2024-38178 is a memory corruption flaw (CWE-843 type confusion) in the Microsoft Windows Scripting Engine that allows an unauthenticated attacker to execute arbitrary code. Exploitation is triggered when a user is lured into opening a specially crafted URL, so no prior authentication or network access to the target is required. A successful attack gains remote code execution, typically in the context of the fooled user's privileges. Any supported Microsoft Windows system with the scripting engine is affected, per CISA's listing of 'Microsoft Windows'. The vulnerability is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-08-13, coinciding with Microsoft's August 2024 Patch Tuesday, and EPSS assigns a high 41.4% probability of exploitation in the next 30 days. Do: Apply Microsoft's August 2024 Windows cumulative security updates immediately, prioritizing internet-facing and high-value systems, and verify patch levels against the KBs released 2024-08-13. As interim mitigation, limit user exposure to untrusted links and consider restricting or disabling legacy scripting/IE-mode rendering where business needs allow. No public PoC is known, but KEV listing confirms active exploitation, so hunt for anomalous process spawns from browsing/link-opening activity and apply CISA's required action of vendor mitigations or discontinuing use. | 7.5 | 41% | KEV |
| masshundreds of millions of Windows devices worldwide |
Full article202 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
October 20, 2024

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.
Expanding the Investigation: Deep Dive into Latest TrickMo Samples
HijackLoader evolution: abusing genuine signing certificates
Technical Analysis of DarkVision RAT
Encrypted Symphony: Infiltrating the Cicada3301 Ransomware-as-a-Service Group
Ransomware Claims Spike: Key Insights from Coalition’s 2024 Cyber Claims Report
ClickFix tactic: The Phantom Meet
A Novel Approach to Malicious Code Detection Using CNN-BiLSTM and Feature Fusion
Adaptive Ransomware Detection Using Similarity-Preserving Hashing
Advanced Persistent Threats (APT) Attribution Using Deep Reinforcement Learning
Android Malware Detection Using Support Vector Regression for Dynamic Feature Analysis
AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178)
UAT-5647 targets Ukrainian and Polish entities with RomCom malware variants
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170047/malware/security-affairs-malware-newsletter-round-16.html