A dangerous zero-day vulnerability has been discovered in Windows, which has been patched by a third-party developer.

The developers of the 0patch platform (owned by the Slovenian Acros Security) have released a free micropatch that fixes the problem with leaking NTLM credentials in Windows. Microsoft promised to get involved in solving the problem later.

Image Source: Windows/unsplash.com

The issue is related to the leak of New Technology LAN Manager (NTLM) credentials, a set of Microsoft-developed security protocols that are used to authenticate users and computers on a network. Back in January, Microsoft patched the NTLM-related vulnerability CVE-2024-21320, but then Akamai cybersecurity expert Tomer Peled discovered that attackers could bypass the patch by sending a potential victim a Windows theme file and forcing them to do some manipulations with it – You don’t even need to open the file. After these manipulations, Windows sends authenticated network requests to remote hosts with NTLN credentials belonging to the user.

As a result, the Windows theme spoofing vulnerability CVE-2024-38030 was registered and was fixed in July. Acros Security specialists analyzed the problem and identified an additional instance of the vulnerability, which is present in all fully updated versions of Windows up to Windows 11 24H2. The company reported its discovery to Microsoft and refused to release details until the software giant fixed the new vulnerability, but released its own micropatch that closes it. “We are aware of this report and will take appropriate action to help protect customers,” Microsoft said.

To exploit the vulnerability, “a user must either copy a theme file, for example, from an email or chat to a folder or desktop, or visit a malicious site from which the file is automatically downloaded to the Downloads folder,” Acros Security explained. That is, some actions on the part of the potential victim are still necessary.

admin

Share
Published by
admin

Recent Posts

Trump’s new executive order calls for the creation of a US national cryptocurrency reserve

Donald Trump, who during his first term criticized cryptocurrencies as a whole, by the time…

52 minutes ago

Dasung has released a compact 10.3-inch monitor with an electronic ink matrix and an update frequency of 60 Hz

The Chinese company Dasung has released a compact monochrome touchscreen monitor, Paperlike 103, equipped with…

52 minutes ago

Google launches accounts through the print scanner on Android

Google has launched a new security feature for Android 15 that will help protect users'…

1 hour ago

Nvidia has removed Hot Spot monitoring from GeForce RTX 50 series video cards

Nvidia has talked a lot about evolutionary design solutions for its graphics card cooling systems,…

2 hours ago

FitBit will pay a fine of $ 12 million for burns from Ionic smart watch in 78 people

Google-owned Fitbit will pay a $12.25 million fine over problems with its Ionic smartwatch. The…

2 hours ago

A large American retailer announced the date of the start of sales of the AMD series of the Radeon RX 9070 series

One of the most famous American retailers, B&H, announced that it will begin accepting pre-orders…

3 hours ago