ZeroHour
Security Affairspublished ()ingested @securityaffairs

SECURITY AFFAIRS MALWARE NEWSLETTER

criticalMalwareimportance 60CVE-2024-38178

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38178
Unauthenticated RCE via Memory Corruption in Microsoft Windows Scripting Engine

CVE-2024-38178 is a memory corruption flaw (CWE-843 type confusion) in the Microsoft Windows Scripting Engine that allows an unauthenticated attacker to execute arbitrary code. Exploitation is triggered when a user is lured into opening a specially crafted URL, so no prior authentication or network access to the target is required. A successful attack gains remote code execution, typically in the context of the fooled user's privileges. Any supported Microsoft Windows system with the scripting engine is affected, per CISA's listing of 'Microsoft Windows'. The vulnerability is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-08-13, coinciding with Microsoft's August 2024 Patch Tuesday, and EPSS assigns a high 41.4% probability of exploitation in the next 30 days.

Do: Apply Microsoft's August 2024 Windows cumulative security updates immediately, prioritizing internet-facing and high-value systems, and verify patch levels against the KBs released 2024-08-13. As interim mitigation, limit user exposure to untrusted links and consider restricting or disabling legacy scripting/IE-mode rendering where business needs allow. No public PoC is known, but KEV listing confirms active exploitation, so hunt for anomalous process spawns from browsing/link-opening activity and apply CISA's required action of vendor mitigations or discontinuing use.

7.541% KEV
  • Microsoft Windows (Scripting Engine) CISA lists 'Microsoft Windows' without enumerating ranges; affected Windows releases are those covered by Microsoft's August 2024 security updates
masshundreds of millions of Windows devices worldwide
Full article202 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini October 20, 2024

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape.

Expanding the Investigation: Deep Dive into Latest TrickMo Samples  

HijackLoader evolution: abusing genuine signing certificates

FASTCash for Linux     

Water Makara Uses Obfuscated JavaScript in Spear Phishing Campaign, Targets Brazil With Astaroth Malware  

Technical Analysis of DarkVision RAT  

Encrypted Symphony: Infiltrating the Cicada3301 Ransomware-as-a-Service Group  

Ransomware Claims Spike: Key Insights from Coalition’s 2024 Cyber Claims Report

ClickFix tactic: The Phantom Meet

A Novel Approach to Malicious Code Detection Using CNN-BiLSTM and Feature Fusion

Adaptive Ransomware Detection Using Similarity-Preserving Hashing

Advanced Persistent Threats (APT) Attribution Using Deep Reinforcement Learning

Android Malware Detection Using Support Vector Regression for Dynamic Feature Analysis

AhnLab and NCSC Release Joint Report on Microsoft Zero-Day Browser Vulnerability (CVE-2024-38178)   

UAT-5647 targets Ukrainian and Polish entities with RomCom malware variants  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170047/malware/security-affairs-malware-newsletter-round-16.html