Kaspersky's automated detection technologies have identified a zero-day vulnerability in Windows. The exploit based on this vulnerability allowed attackers to gain elevated privileges on the attacked device and bypass protection mechanisms in the Google Chrome browser. The recently discovered exploit was used in the WizardOpium malware operation.
Zero-day vulnerabilities are previously unknown errors in software that, if discovered first by criminals, allow them to act unnoticed for a long time, causing serious and unexpected damage.
Classic security solutions do not recognize the "infection" of the system, nor can they protect users from a threat that has not yet been identified.
The new Windows vulnerability was discovered by Kaspersky researchers thanks to yet another zero-day exploit. In November 2019, Kaspersky’s exploit prevention technology, which is built into most of the company’s products, was able to detect a zero-day exploit in Google Chrome. This exploit allowed attackers to execute arbitrary code on a victim’s device. After further investigation by this company, which experts dubbed “WizardOpium,” another vulnerability was discovered, this time in the Windows operating system.
Criminals could exploit this vulnerability in the most recently updated versions of Windows 7 and even some versions of Windows 10 (new versions of Windows 10 are not affected).
“This type of attack requires huge resources. However, it gives significant advantages to attackers, and as we can see, they are happy to exploit them. The number of zero-days freely available on the Internet continues to grow, and this trend is unlikely to disappear. Organizations must rely on the latest threat intelligence available and have protective technologies in place that can proactively detect unknown threats such as zero-day exploits,” comments Anton Ivanov, security expert at Kaspersky.
The vulnerability was reported to Microsoft and a patch on December 10, 2019.
To prevent backdoors from being installed via the Windows zero-day vulnerability, Kaspersky recommends taking the following security measures:
- Install the Microsoft patch for the new vulnerability as soon as possible. Once the patch, threat actors can no longer exploit the vulnerability.
- Make sure all software is updated as soon as a new security patch is released if you are concerned about the security of your entire organization. Use security products with vulnerability assessment and patch management capabilities to ensure these processes are performed automatically.
- Use a proven security solution with behavior-based detection capabilities to protect against unknown threats.
- Make sure your security team has access to the latest digital threat intelligence.
- Use sandbox technology to analyze suspicious objects.
More information can be found on the dedicated Securelist.
