QakBot Malware Exploiting Windows zero-Day To Gain System Privileges

In April 2024, security researchers revisited CVE-2023-36033, a Windows DWM Core Library elevation of privilege vulnerability that was previously discovered and exploited in the wild.

As part of their investigation into exploit samples and potential attack vectors, they stumbled upon a curious document uploaded to VirusTotal on April 1st. 

The document’s presence on a malware repository dedicated to sharing suspicious files raised a red flag, prompting further analysis.

The researchers suspected that this document might be either a malicious payload designed to exploit CVE-2023-36033 or a component used in a larger malware campaign leveraging this vulnerability.

Free Webinar on Live API Attack Simulation: Book Your Seat | Start protecting your APIs from hackers

They examined a document with a filename indicative of a potential Windows vulnerability, which contained a poorly written description of a Desktop Window Manager (DWM) exploit that could be leveraged to escalate privileges on a system. 

While the exploit technique resembled the one used in CVE-2023-36033, the document appeared to describe a different vulnerability altogether, which suggests that the document might outline a novel DWM exploit with a distinct attack vector, separate from the previously discovered CVE.

Despite the suspicious nature of the vulnerability description, which lacked details for exploitation and potentially described a non-existent or inaccessible issue, researchers opted to investigate further. 

This due diligence paid off, as the investigation uncovered a legitimate zero-day privilege escalation vulnerability within the Windows DWM Core Library.

The researchers promptly reported the issue to Microsoft, which designated it CVE-2024-30051, and subsequently patched it on May 14, 2024, during Patch Tuesday.

Researchers discovered a zero-day elevation of privilege vulnerability (CVE-2024-30051) in the Windows DWM Core Library and reported it to Microsoft. 

They subsequently identified exploits leveraging this vulnerability used in conjunction with malware like QakBot, indicating widespread access among threat actors.

To allow for system patching, technical details regarding the exploit and vulnerability will be published after a grace period. 

According to SecureList, Kaspersky identified and reported a zero-day privilege escalation vulnerability (CVE-2024-30051) in the Windows DWM Core Library. 

They detected exploitation attempts using this vulnerability to deliver various malware strains, including generic exploits, trojans (Agent and Cobalt Strike variants), and potentially other malicious objects.

Kaspersky acknowledges Microsoft’s swift action in analyzing the report and issuing security patches.

On-Demand Webinar to Secure the Top 3 SME Attack Vectors: Watch for Free

Eswar

Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.

Recent Posts

Hackers Exploit NFC Technology to Steal Money from ATMs and POS Terminals

In a disturbing trend, cybercriminals, predominantly from Chinese underground networks, are exploiting Near Field Communication…

8 hours ago

Threat Actors Leverage TAG-124 Infrastructure to Deliver Malicious Payloads

In a concerning trend for cybersecurity, multiple threat actors, including ransomware groups and state-sponsored entities,…

8 hours ago

Ransomware Actors Ramp Up Attacks Organizations with Emerging Extortion Trends

Unit 42’s 2025 Global Incident Response Report, ransomware actors are intensifying their cyberattacks, with 86%…

8 hours ago

New SMS Phishing Attack Weaponizes Google AMP Links to Evade Detection

Group-IB’s High-Tech Crime Trends Report 2025 reveals a sharp 22% surge in phishing websites, with…

8 hours ago

Russian Hackers Exploit Microsoft OAuth 2.0 to Target Organizations

Cybersecurity firm Volexity has tracked a series of highly targeted attacks by suspected Russian threat…

8 hours ago

Hackers Weaponize Google Forms to Bypass Email Security and Steal Login Credentials

Threat actors are increasingly leveraging Google Forms, the tech giant’s widely-used form and quiz-building tool,…

10 hours ago