Monday, April 14, 2025
HomeCVE/vulnerabilityWindows 0-Day Exploited in Wild with Single Right Click

Windows 0-Day Exploited in Wild with Single Right Click

Published on

SIEM as a Service

Follow Us on Google News

A newly discovered zero-day vulnerability, CVE-2024-43451, has been actively exploited in the wild, targeting Windows systems across various versions.

This critical vulnerability, uncovered by the ClearSky Cyber Security team in June 2024, has been linked to attacks aimed specifically at Ukrainian organizations.

The exploit allows malicious actors to gain control of a system through seemingly innocuous actions such as a single right-click on a malicious file.

- Advertisement - Google News

Free Ultimate Continuous Security Monitoring Guide - Download Here (PDF)

Vulnerability Overview

The zero-day flaw affects nearly all versions of Windows, including Windows 10, and 11, and some configurations of older versions like Windows 7 and 8.1.

The vulnerability is triggered by interacting with specially crafted URL files disguised as legitimate documents.

  • A single right-click on a malicious file (affects all Windows versions).
  • Deleting the file (Windows 10/11).
  • Dragging the file to another folder (Windows 10/11 and some older versions).

The malicious files, often disguised as academic certificates, were first observed being distributed from a compromised official Ukrainian government website.

The attack typically begins with a phishing email containing a malicious URL file. The email from a compromised Ukrainian government server encourages the recipient to renew their academic certificate.

Once the user interacts with the URL file in any triggering ways, a connection to the attacker’s server is established, allowing for the download of additional malicious payloads, including the SparkRAT malware.

SparkRAT, an open-source remote access trojan (RAT), is used to gain control of the victim’s system. Additionally, the attackers employ persistence techniques to maintain access even after a system reboot.

The Ukrainian Computer Emergency Response Team (CERT-UA) has attributed these attacks to the Russian-linked threat actor UAC-0194.

ClearSky researchers have also identified overlaps with techniques used by other Russian-affiliated groups, suggesting using a common toolkit.

Microsoft addressed this vulnerability with a security patch released on November 12, 2024. Users are urged to update their systems immediately to prevent exploitation of CVE-2024-43451.

Maintaining up-to-date security patches remains critical for safeguarding against these ongoing attacks.

Analyze Unlimited Phishing & Malware with ANY.RUN For Free - 14 Days Free Trial.

Divya
Divya
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Latest articles

BPFDoor Malware Uses Reverse Shell to Expand Control Over Compromised Networks

A new wave of cyber espionage attacks has brought BPFDoor malware into the spotlight...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...

Morocco Investigation Major Data Breach Allegedly Claimed by Algerian Hackers

The National Social Security Fund (CNSS) of Morocco has confirmed that initial checks on...

Smishing Campaign Hits Toll Road Users with $5 Payment Scam

Cybersecurity researchers at Cisco Talos have uncovered a large-scale smishing campaign targeting toll road...

Resilience at Scale

Why Application Security is Non-Negotiable

The resilience of your digital infrastructure directly impacts your ability to scale. And yet, application security remains a critical weak link for most organizations.

Application Security is no longer just a defensive play—it’s the cornerstone of cyber resilience and sustainable growth. In this webinar, Karthik Krishnamoorthy (CTO of Indusface) and Phani Deepak Akella (VP of Marketing – Indusface), will share how AI-powered application security can help organizations build resilience by

Discussion points


Protecting at internet scale using AI and behavioral-based DDoS & bot mitigation.
Autonomously discovering external assets and remediating vulnerabilities within 72 hours, enabling secure, confident scaling.
Ensuring 100% application availability through platforms architected for failure resilience.
Eliminating silos with real-time correlation between attack surface and active threats for rapid, accurate mitigation

More like this

BPFDoor Malware Uses Reverse Shell to Expand Control Over Compromised Networks

A new wave of cyber espionage attacks has brought BPFDoor malware into the spotlight...

EU’s GDPR Article 7 Poses New Challenges for Businesses To Secure AI-Generated Image Data

As businesses worldwide embrace digital transformation, the European Union’s General Data Protection Regulation (GDPR),...

Morocco Investigation Major Data Breach Allegedly Claimed by Algerian Hackers

The National Social Security Fund (CNSS) of Morocco has confirmed that initial checks on...