HomeSecurityRansomEXX ransomware group used Windows CLFS zero-day

RansomEXX ransomware group used Windows CLFS zero-day

Microsoft says the RansomEXX ransomware serious zero-day vulnerability in the Windows Common Log File System (CLFS) gang is exploiting a to gain SYSTEM privileges on victims' machines.

Windows CLFS zero-day RansomEXX

The vulnerability is tracked as CVE-2025-29824 and was fixed in this month's Patch Tuesday. It is a use-after-free, which allows local attackers with low privileges to gain SYSTEM privileges. Attacks can be simple and require no user interaction.

See also: State Bar of Texas: Data breach by INC ransomware gang?

While the company has issued security updates for the affected versions of Windows, it said that updates for Windows 10 x64 and 32-bit systems will be released as soon as possible.

Although the RansomEXX using the Windows vulnerability were limited, the targets were mainly:

  • organizations in the information technology (IT) and real estate sectors in the US
  • organizations in the financial sector in Venezuela
  • a Spanish software company
  • organizations in the retail sector in Saudi Arabia

“Customers running Windows 11, version 24H2 are not affected by the observed exploit, even if the vulnerability existed. Microsoft urges customers to apply these updates as soon as possible“.

See also: Hunters International: Focuses on data theft – The end of ransomware?

Microsoft has linked these attacks to the ransomware gang , which it tracks as Storm-2460. The attackers installed the PipeMagic backdoor on compromised systems, which was used to deploy the CVE-2025-29824 exploit, ransomware payloads, and !READ_ME_REXX2!.txt ransom notes after encrypting files.

PipeMagic was discovered by Kaspersky in 2022. The malware can collect sensitive data, provides full remote access to infected devices, and allows attackers to deploy additional malicious payloads to spread across networks.

See also: Highline Schools ransomware incident breached thousands of data

Microsoft ransomware
RansomEXX ransomware group used Windows CLFS zero-day

As we mentioned earlier, Microsoft fixed the zero-day vulnerability in Windows CLFS with Patch Tuesday April 2025.In addition to this vulnerability, however, it fixed 120+ other bugs. You can see them in brief below:

  • 49 vulnerabilities that allow privilege escalation
  • 31 vulnerabilities that allow remote code execution
  • 17 vulnerabilities that allow information disclosure
  • 14 vulnerabilities that allow Denial of Service attacks
  • 9 vulnerabilities that allow bypassing security features
  • 3 vulnerabilities that allow spoofing

Source: www.bleepingcomputer.com

Selecting the team

☁️ Keep safe copies with Proton Drive

Encrypted cloud storage from Proton — protect your files from ransomware, corruption, and data loss with end-to-end encryption.

  • ✔ End-to-end encrypted files & backups
  • ✔ Version history — recover files after ransomware
  • ✔ Free space — sync across all devices
Get started for free with Proton Drive →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS