QakBot attacks with Windows zero-day (CVE-2024
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-36033 | Local Privilege Escalation in Microsoft Windows DWM Core Library A flaw in the Windows Desktop Window Manager (DWM) Core Library — classified as an untrusted pointer dereference/memory-bounds issue (CWE-822, CWE-119) — allows a local, low-privileged attacker to elevate privileges on affected Windows systems. Per the CVSS vector, exploitation requires only the ability to execute code on the target (local vector, low privileges) and no user interaction. A successful attacker runs code with elevated privileges, gaining high-impact control of confidentiality, integrity, and availability on the host, typically as a post-compromise escalation step after initial access. All systems running Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019, or Windows Server 2022 (including the 23H2 edition) are affected. The vulnerability is confirmed to be exploited in the wild: CISA added it to the KEV on 2023-11-14, Microsoft's November 2023 Patch Tuesday fixed it among three actively exploited zero-days, public coverage notes active exploitation including reported QakBot malware campaigns, and it carries an elevated EPSS of roughly 12% within 30 days (96th percentile). Do: Apply the November 2023 (November 14, 2023) cumulative Windows updates to all Windows 10 1809/21H2/22H2, Windows 11 21H2/22H2/23H2, Windows Server 2019, and Windows Server 2022 (including 23H2) systems, prioritizing servers, RDS hosts, and shared-use machines. Because the flaw is used as a post-compromise escalation step in the wild (KEV-listed, with public reporting tied to QakBot campaigns), assume possible compromise on unpatched endpoints and hunt for follow-on malware, credential theft, and persistence activity; verify patch levels across the fleet rather than relying on mitigations, as CISA lists patching per vendor instructions as the required action. | 7.8 | 12% | KEV |
| masshundreds of millions of Windows client and server endpoints (the Windows 10 1809+ through Windows 11 23H2 and Server 2019/2022 population; exact unpatched… | |
| CVE-2024-30051 | Elevation of Privilege in Microsoft Windows DWM Core Library (Actively Exploited) CVE-2024-30051 is a heap-based buffer overflow / out-of-bounds write (CWE-122, CWE-787) in the Windows Desktop Window Manager (DWM) Core Library that allows a local attacker to escalate privileges. It is triggered by locally executing crafted code that corrupts memory in the DWM component, requiring only low privileges and no user interaction (AV:L/AC:L/PR:L/UI:N). A successful exploit yields high-impact gains on the local system — typically elevation to elevated/SYSTEM rights, giving the attacker full control of confidentiality, integrity and availability on that host. Any organization running the affected Windows 10/11 client releases or Windows Server 2016/2019/2022 with the DWM component is exposed, which in practice means nearly every modern Windows endpoint. The flaw was a zero-day exploited in the wild before remediation: it was added to CISA KEV on 2024-05-14 with known ransomware use, and public reporting ties it to QakBot attack chains and Microsoft's May 2024 Patch Tuesday (which also fixed it alongside other exploited zero-days). Do: Apply Microsoft's May 2024 Patch Tuesday cumulative updates for every affected Windows 10/11 and Windows Server 2016/2019/2022 release immediately; per CISA KEV, apply vendor mitigations or discontinue use of affected systems if updates are unavailable. Prioritize endpoints and servers exposed to user-driven malware (email, web browsing) since the flaw is chained after initial access in QakBot and ransomware operations, and verify patched DWM/dwmcore binaries via the updated OS build. Monitor for local privilege-escalation activity and treat this as a high-priority patch alongside the other May 2024 exploited zero-days. | 7.8 | 6% | KEV ransomware |
| mass≈1 billion+ Windows 10/11 endpoints plus large Windows Server 2016/2019/2022 fleets (DWM is a core component present on effectively every affected Windows… |
Full article461 words · extracted from securelist.com · click to collapse
In early April 2024, we decided to take a closer look at the Windows DWM Core Library Elevation of Privilege Vulnerability CVE-2023-36033, which was previously discovered as a zero-day exploited in the wild. While searching for samples related to this exploit and attacks that used it, we found a curious document uploaded to VirusTotal on April 1, 2024. This document caught our attention because it had a rather descriptive file name, which indicated that it contained information about a vulnerability in Windows OS. Inside we found a brief description of a Windows Desktop Window Manager (DWM) vulnerability and how it could be exploited to gain system privileges, everything written in very broken English. The exploitation process described in this document was identical to that used in the previously mentioned zero-day exploit for CVE-2023-36033, but the vulnerability was different. Judging by the quality of the writing and the fact that the document was missing some important details about how to actually trigger the vulnerability, there was a high chance that the described vulnerability was completely made up or was present in code that could not be accessed or controlled by attackers. But we still decided to investigate it, and a quick check showed that this is a real zero-day vulnerability that can be used to escalate privileges. We promptly reported our findings to Microsoft, the vulnerability was designated CVE-2024-30051, and a patch was released on May 14, 2024, as part of Patch Tuesday.
After sending our findings to Microsoft, we began to closely monitor our statistics in search of exploits and attacks that exploit this zero-day vulnerability, and in mid-April we discovered an exploit for this zero-day vulnerability. We have seen it used together with QakBot and other malware, and believe that multiple threat actors have access to it.
We are going to publish technical details about CVE-2024-30051 once users have had time to update their Windows systems.
Kaspersky products detect the exploitation of CVE-2024-30051 and related malware with the verdicts:
- PDM:Exploit.Win32.Generic;
- PDM:Trojan.Win32.Generic;
- UDS:DangerousObject.Multi.Generic;
- Trojan.Win32.Agent.gen;
- Trojan.Win32.CobaltStrike.gen.
Kaspersky would like to thank Microsoft for their prompt analysis of the report and patches.
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/cve-2024-30051/112618/