Free unofficial patches are now available for a new zero-day vulnerability in Windows Themes that allows attackers to steal a target's NTLM credentials remotely.
See also: Lazarus exploits zero-day in Chrome for attacks

NTLM has been used extensively in NTLM relay attacks, where threat actors force vulnerable devices to authenticate against servers under their control, and pass-the-hash, where they exploit system vulnerabilities or deploy malware to obtain NTLM hashes from targeted systems.
Once they have the hash, attackers can authenticate the compromised user, gaining access to sensitive data and moving laterally through the now compromised network. A year ago, Microsoft announced that it plans to deprecate the NTLM authentication protocol in Windows 11 in the future.
ACROS Security researchers discovered the new Windows Themes zero-day (which has not yet been assigned a CVE identifier), while also deploying a micropatch for a security issue tracked as CVE-2024-38030 that could leak a user's credentials (as reported by Akamai's Tomer Peled).
See also: Hackers exploit Samsung's Zero-Day vulnerability
Peled found that “when a theme file specified a network file path for some of the theme properties (specifically BrandImage and Wallpaper), Windows would automatically send network authentication requests to remote hosts ,including the user’s NTLM credentials, when that theme file was viewed in Windows Explorer.”

Although Microsoft patched CVE-2024-38030 in July, ACROS Security found another issue that attackers could exploit to steal a target's NTLM credentials on all fully updated versions of Windows, from Windows 7 to Windows 11 24H2.
“This meant that simply having a malicious theme file listed in a folder or placed on the desktop would be enough to leak user credentials without any additional user action,” said ACROS Security CEO Mitja Kolsek.
Kolsek also shared a demonstration video, showing how copying a malicious Windows theme file to a fully patched Windows 11 24H2 system (on the left side) triggers a network connection to the attacker's computer, exposing the NTLM credentials of the logged-in user.
See alsoAI tool lets you discover Zero-Day vulnerabilities
A zero-day vulnerability refers to a software security flaw that is unknown to the software vendor and can be exploited by hackers before a fix is available. These vulnerabilities pose significant risks as they provide hackers with the opportunity to gain access to systems, data and networks without detection. Because vendors have “zero days” to address the problem once it is discovered, these vulnerabilities are highly sought after and can be used for malicious activities such as data theft, espionage and unauthorized access. Combating zero-day exploits requires proactive security measures, including regular system updates, network monitoring and the prompt application of security patches when they become available.
Source: bleepingcomputer
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
