HomeSecurityCritical vulnerability in iTunes: Update immediately!

Critical vulnerability in iTunes: Update immediately!

iTunesversion of iTunes Windows has been found to have a critical vulnerabilitythat hackers to attack vulnerable systems. Apple recommends that all iTunes (for Windows) users immediately update systems with the latest patch released the company

The problem started with a malicious code that was not detected by antivirus software, as it is considered part of Apple. However, the bug was discovered by the research team of the company Morphisec, which informed Apple. According to the researchers, this is a dangerous vulnerability. Morphisec became aware of the exploitation of the vulnerability in August, when there were some attacks on systems in the automotive industry.

This is an "unquoted path vulnerability"that affects iTunes for Windows, exploiting the Bonjour updater that comes with it.

These types of vulnerabilities have been known for 15 years. However, they are difficult to detect, especially when they are found in software from a known and trusted source, such as Apple.

Critical vulnerability in iTunes: Update immediately!

What happens is that Apple's own software enables the malware , so the defense mechanisms can't take action.

Bonjour is separate from iTunes. When someone uninstalls iTunes, Bonjour is still there. Many people don't know that they need to uninstall it separately. According to the researchers, many users had uninstalled iTunes from computers but not Bonjour, so it continued to exist and work in the background, without being updated. This makes systems vulnerable.

According to Morphisec, hackers exploited the vulnerability to install the ransomware BitPaymer by executing a malicious “program” file. “Bonjour attempted to run the ‘Program Files’ folder, but due to the vulnerability, it ran the BitPaymer ransomware with the name Program.” In this way, the vulnerability evades detection and bypasses defense mechanisms.

Morphisec researchers have identified several BitPaymer ransomware attacks on US companies. “At least 15 companies, in the financial, technology and agricultural sectors, have been targeted.” The attacks usually take place on weekends, when there is less chance of detection. This gives hackers enough time to spread the ransomware to many devices on the targeted network.

Therefore, all iTunes for Windows users should immediately update their systems to avoid falling victim to a ransomware attack.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS