A dangerous zero-day vulnerability has been discovered in Windows, which has been patched by a third-party developer.

The developers of the 0patch platform (owned by the Slovenian Acros Security) have released a free micropatch that fixes the problem with leaking NTLM credentials in Windows. Microsoft promised to get involved in solving the problem later.

Image Source: Windows/unsplash.com

The issue is related to the leak of New Technology LAN Manager (NTLM) credentials, a set of Microsoft-developed security protocols that are used to authenticate users and computers on a network. Back in January, Microsoft patched the NTLM-related vulnerability CVE-2024-21320, but then Akamai cybersecurity expert Tomer Peled discovered that attackers could bypass the patch by sending a potential victim a Windows theme file and forcing them to do some manipulations with it – You don’t even need to open the file. After these manipulations, Windows sends authenticated network requests to remote hosts with NTLN credentials belonging to the user.

As a result, the Windows theme spoofing vulnerability CVE-2024-38030 was registered and was fixed in July. Acros Security specialists analyzed the problem and identified an additional instance of the vulnerability, which is present in all fully updated versions of Windows up to Windows 11 24H2. The company reported its discovery to Microsoft and refused to release details until the software giant fixed the new vulnerability, but released its own micropatch that closes it. “We are aware of this report and will take appropriate action to help protect customers,” Microsoft said.

To exploit the vulnerability, “a user must either copy a theme file, for example, from an email or chat to a folder or desktop, or visit a malicious site from which the file is automatically downloaded to the Downloads folder,” Acros Security explained. That is, some actions on the part of the potential victim are still necessary.

admin

Share
Published by
admin

Recent Posts

Windows 11 will become smarter: Microsoft is testing AI file search

Microsoft is testing a new artificial intelligence (AI)-powered search feature in the latest build for…

59 minutes ago

Merger instead of sale: Perplexity AI wants to save TikTok in the US

Perplexity AI proposed on Saturday, a day before TikTok was blocked in the United States,…

59 minutes ago

Battle Shapers – fear of ambition. Review

Not defined Roguelikes with a first-person perspective are a fairly niche genre segment, but they…

6 hours ago

ASRock introduced industrial mini-PCs and motherboards based on Intel Arrow Lake-H and AMD Ryzen 300 AI

ASRock Industrial, according to the CNX-Software resource, presented industrial computers of a small form factor…

7 hours ago

The potential US Secretary of Transportation promised to deal with SpaceX fines and eliminate the space bureaucracy

This week, Congress held confirmation hearings for new ministers nominated by new US President Donald…

8 hours ago

Vast Space has built the world’s first private space station; it will go into orbit this year

California-based startup Vast Space has announced the completion of the world's first commercial space station,…

8 hours ago