A newly discovered zero-day vulnerability, CVE-2024-43451, has been actively exploited in the wild, targeting Windows systems across various versions.
This critical vulnerability, uncovered by the ClearSky Cyber Security team in June 2024, has been linked to attacks aimed specifically at Ukrainian organizations.
The exploit allows malicious actors to gain control of a system through seemingly innocuous actions such as a single right-click on a malicious file.
Free Ultimate Continuous Security Monitoring Guide - Download Here (PDF)
The zero-day flaw affects nearly all versions of Windows, including Windows 10, and 11, and some configurations of older versions like Windows 7 and 8.1.
The vulnerability is triggered by interacting with specially crafted URL files disguised as legitimate documents.
The malicious files, often disguised as academic certificates, were first observed being distributed from a compromised official Ukrainian government website.
The attack typically begins with a phishing email containing a malicious URL file. The email from a compromised Ukrainian government server encourages the recipient to renew their academic certificate.
Once the user interacts with the URL file in any triggering ways, a connection to the attacker’s server is established, allowing for the download of additional malicious payloads, including the SparkRAT malware.
SparkRAT, an open-source remote access trojan (RAT), is used to gain control of the victim’s system. Additionally, the attackers employ persistence techniques to maintain access even after a system reboot.
The Ukrainian Computer Emergency Response Team (CERT-UA) has attributed these attacks to the Russian-linked threat actor UAC-0194.
ClearSky researchers have also identified overlaps with techniques used by other Russian-affiliated groups, suggesting using a common toolkit.
Microsoft addressed this vulnerability with a security patch released on November 12, 2024. Users are urged to update their systems immediately to prevent exploitation of CVE-2024-43451.
Maintaining up-to-date security patches remains critical for safeguarding against these ongoing attacks.
Analyze Unlimited Phishing & Malware with ANY.RUN For Free - 14 Days Free Trial.
Ivanti has issued an urgent security advisory for CVE-2025-22457, a critical vulnerability impacting Ivanti Connect…
A concerning malware campaign was disclosed by the AhnLab Security Intelligence Center (ASEC), revealing how…
EncryptHub, a rapidly evolving cybercriminal entity, has come under intense scrutiny following revelations of operational…
A sophisticated phishing campaign, dubbed "PoisonSeed," has been identified targeting customer relationship management (CRM) and…
A surge in phishing text messages claiming unpaid tolls has been linked to a massive…
The State Bar of Texas has confirmed a data breach following the detection of unauthorized…