HomeSecurityMicrosoft fixes zero-day used by Lazarus hackers

Microsoft fixes zero-day used by Lazarus hackers

As part of its monthly Patch Tuesday, Microsoft fixed a vulnerability in Windows that had been used as a zero-day by North Korean hackers Lazarus.

Microsoft zero-day hackers Lazarus

The vulnerability, which is tracked as CVE-2024-38193 (CVSS score: 7.8), has been described as a privilege escalation bug in the Windows Ancillary Function Driver (AFD.sys) for WinSock.

"An attacker who successfully exploits this vulnerability could gain SYSTEM privileges," said last week.

See also: Vulnerabilities expose solar systems to hacking

Gen Digital researchers Luigino Camastra and Milánek discovered and reported the vulnerability. Gen Digital owns a number of security software brands and utilities, including Norton, Avast, Avira, AVG, ReputationDefender, and CCleaner.

Microsoft warned that the vulnerability allows attackers to gain unauthorized access to sensitive areas of the system.

The bug began to be exploited by Lazarus hackers in early June 2024. “The vulnerability allowed attackers to bypass normal security and gain access to sensitive areas of the system that most users and administrators do not have access to.”

Researchers observed that the attacks were characterized by the use of a rootkit called FudModule, in an attempt to evade detection.

See also: SLUBStick Linux vulnerability allows hackers to gain complete control of the system

While the exact technical details are currently unknown, the vulnerability is reminiscent of another similar bug, which Microsoft patched in February and was also used by the Lazarus Group to install FudModule.

Previous attacks detailed by cybersecurity Avast revealed that the rootkit is delivered via a remote access trojan, known as the Kaolin RAT.

The ongoing threat from exploits of such vulnerabilities underscores the need for organizations to remain vigilant. Implementing updates, training employees on phishing and social engineering tactics, and implementing robust monitoring systems are crucial to mitigating the risks associated with such sophisticated attacks. Additionally, deploying endpoint detection and response (EDR) solutions can help identify unusual behaviors that may indicate the presence of rootkits or other hidden malware.

See also: Siri vulnerability allows data theft even on locked Apple devices

Microsoft fixes zero-day used by Lazarus hackers
Microsoft fixes zero-day used by Lazarus hackers

As cyber threats continue to evolve, staying informed about the latest vulnerabilities and threat groups is essential to protecting sensitive data and maintaining system integrity. Organizations must also consider the potential impact of state-backed actors and take appropriate measures to secure systems against these adversaries.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Source: thehackernews.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS