CVE-2024-26234
published 2024-04-09CVE-2024-26234: Proxy Driver Spoofing Vulnerability Proxy Driver Spoofing Vulnerability
medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
ITWVulnCheck KEV
Exploited in the wild
EPSS
4.85%
90.9th percentile
Proxy Driver Spoofing Vulnerability
Proxy Driver Spoofing Vulnerability
Affected
32 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20596 | 10.0.10240.20596 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.6897 | 10.0.14393.6897 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5696 | 10.0.17763.5696 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5696 | 10.0.17763.5696 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4291 | 10.0.19044.4291 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4291 | 10.0.19045.4291 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2899 | 10.0.22000.2899 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3447 | 10.0.22621.3447 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3447 | 10.0.22631.3447 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3447 | 10.0.22631.3447 |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27067 | 6.1.7601.27067 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.22618 | 6.0.6003.22618 |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.24821 | 6.2.9200.24821 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.21924 | 6.3.9600.21924 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.6897 | 10.0.14393.6897 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5696 | 10.0.17763.5696 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2402 | 10.0.20348.2402 |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1809 | — | — |
| msrc | windows_10_version_21h2 | — | — |
| msrc | windows_10_version_22h2 | — | — |
| msrc | windows_11_version_21h2 | — | — |
| msrc | windows_11_version_22h2 | — | — |
| msrc | windows_11_version_23h2 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Look for a malicious Windows driver signed with a valid Microsoft Hardware Publisher Certificate impersonating Thales Group, labeled 'Catalog Authentication Client Service' by 'Catalog Thales'. ↗
- →The malicious driver was previously bundled with a marketing software called 'LaiXi Android Screen Mirroring' — flag installations or drivers associated with this software. ↗
- →The file functions as a malicious backdoor; treat any driver signed by 'Catalog Thales' as highly suspicious and check against Microsoft's updated revocation list. ↗
- →CVE-2024-26234 is confirmed exploited in the wild and publicly disclosed; prioritize detection on all Windows endpoints listed as affected. ↗
- →Microsoft has added the malicious files to its driver revocation list as part of the April 2024 Patch Tuesday cycle; verify revocation list is applied on all endpoints. ↗
- ·Sophos could not independently verify the legitimacy of the LaiXi Android Screen Mirroring software itself, only that the bundled driver is malicious. ↗
- ·Microsoft initially failed to tag CVE-2024-26234 as a zero-day/exploited vulnerability; the advisory was updated post-release to reflect active exploitation. ↗
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
cvelistv56.7MEDIUM
vulncheck6.7MEDIUM
vendor_msrc6.7MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Proxy Driver Spoofing Vulnerability
vendor_msrc·2024-04-09·CVSS 6.7
CVE-2024-26234 [MEDIUM] CWE-284 Proxy Driver Spoofing Vulnerability
Proxy Driver Spoofing Vulnerability
Windows Proxy Driver: Windows Proxy Driver
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036896
Reference: https://support.microsoft.com/help/5036896
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036909
Reference: https://support.microsoft.com/help/5036909
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036894
Reference: https://support.microsoft.com/help/5036894
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5036892
Reference: https://support.microsoft.com/help/50368
CVEList
Proxy Driver Spoofing Vulnerability
cvelistv5·2024-04-09·CVSS 6.7
CVE-2024-26234 [MEDIUM] CWE-284 Proxy Driver Spoofing Vulnerability
Proxy Driver Spoofing Vulnerability
Proxy Driver Spoofing Vulnerability
VulnCheck
N-able N-Central Authentication Bypass Using an Alternate Path or Channel
vulncheck·2024·CVSS 6.7
CVE-2024-28200 [MEDIUM] N-able N-Central Authentication Bypass Using an Alternate Path or Channel
N-able N-Central Authentication Bypass Using an Alternate Path or Channel
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2.
This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.
Affected: N-able N-Central
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-26234
VulnCheck
Proxy Driver Spoofing Vulnerability
vulncheck·2024·CVSS 6.7
CVE-2024-26234 [MEDIUM] Proxy Driver Spoofing Vulnerability
Proxy Driver Spoofing Vulnerability
Proxy Driver Spoofing Vulnerability
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2024-Apr; https://news.sophos.com/en-us/2024/04/09/smoke-and-screen-mirrors-a-strange-signed-backdoor/; https://www.cert.europa.eu/publications/threat-intelligence/tlr2024/pdf
No detection rules found.
No public exploits indexed.
Checkpoint
15th April – Threat Intelligence Report
blogs_checkpoint·2024-04-15
CVE-2024-29990 15th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 15th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 15th April, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Japanese optics giant Hoya Corporation has been a victim of a ransomware attack that impacted its major IT infrastructure and various business divisions. Hunters International ransomware gang claimed responsibility for the attack and demanded a ransom of $10M for alleged 1.7M stolen files.
Check Point Harmony Endpoint and Th
Qualys
Microsoft and Adobe Patch Tuesday, April 2024 Security Update Review
blogs_qualys·2024-04-09
Microsoft and Adobe Patch Tuesday, April 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for April 2024
Adobe Patches for April 2024
Other Critical Severity Vulnerabilities Patched in April Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Qualys Monthly Webinar Series
Welcome to another insightful dive into Microsoft’s Patch Tuesday! This month’s security updates address a vast number of vulnerabilities in multiple popular products, features, and roles. We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tuesday for Ap
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
# The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs
2024/04/09
Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager, however, all of the bugs being patched are simple Cross
Bleepingcomputer
Microsoft fixes two Windows zero-days exploited in malware attacks
blogs_bleepingcomputer·2024-04-09·CVSS 6.7
CVE-2024-26234 [MEDIUM] Microsoft fixes two Windows zero-days exploited in malware attacks
## Microsoft fixes two Windows zero-days exploited in malware attacks
## Sergiu Gatlan
Microsoft has fixed two actively exploited zero-day vulnerabilities during the April 2024 Patch Tuesday, although the company failed to initially tag them as such.
The first, tracked as CVE-2024-26234 and described as a proxy driver spoofing vulnerability, was issued to track a malicious driver signed using a valid Microsoft Hardware Publisher Certificate that was found by Sophos X-Ops in December 2023 and reported by team lead Christopher Budd.
This malicious file was labeled as "Catalog Authentication Client Service" by "Catalog Thales," likely an attempt to impersonate Thales Group. However, further investigation revealed that it was previously bundled with a marketing software called LaiXi Androi
Tenable
Microsoft’s April 2024 Patch Tuesday Addresses 147 CVEs (CVE-2024-29988)
blogs_tenable·2024-04-09·CVSS 8.8
[HIGH] Microsoft’s April 2024 Patch Tuesday Addresses 147 CVEs (CVE-2024-29988)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
blogs_bleepingcomputer·2024-04-09·CVSS 8.1
[HIGH] Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Microsoft April 2024 Patch Tuesday fixes 150 security flaws, 67 RCEs
## Lawrence Abrams
There were also fixes for twenty-six Secure Boot bypasses released this month, including two from Lenovo.
The number of bugs in each vulnerability category is listed below:
31 Elevation of Privilege Vulnerabilities
29 Security Feature Bypass Vulnerabilities
67 Remote Code Execution Vulnerabilities
13 Information Disclosure Vulnerabilities
7 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The total count of 150 flaws does not include 5 Microsoft Edge flaws fixed on April 4th and 2 Mariner flaws. Mariner is an open-source Linux distribution developed by Microsoft for its Microsoft Azure services.
To learn more about the non-security updates released today, you can review our ded
Trendmicro
The April 2024 Security Updates Review
blogs_trendmicro·2024-04-09
The April 2024 Security Updates Review
## The April 2024 Security Updates Review
Get the April 2024 security update and review.
By: Dustin Childs 2024/04/09 Read time: ( words)
Save to Folio
It’s the second Tuesday of the month, and Adobe and Microsoft have released a fresh crop of security updates. Take a break from your other activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Adobe Patches for April 2024
For April, Adobe released nine patches addressing 24 CVEs in Adobe After Effects, Photoshop, Commerce, InDesign, Experience Manager, Media Encoder, Bridge, Illustrator, and Adobe Animate. The largest of these updates is for Experience Manager , however, all of the bugs being patched are simple Cros
Krebs
April’s Patch Tuesday Brings Record Number of Fixes
blogs_krebs·2024-04-09·CVSS 8.1
[HIGH] April’s Patch Tuesday Brings Record Number of Fixes
If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.
Yes, you read that right. Microsoft today released updates to address 147 security holes in Windows, Office , Azure , .NET Framework , Visual Studio , SQL Server , DNS Server , Windows Defender , Bitlocker , and Windows Secure Boot .
“This is the largest release from Microsoft this year and the largest since at least 2017,” said Dustin Childs , from Trend Micro’s Zero Day Initiative (ZDI). “As far as I can tell, it’s the largest Patch Tuesday release from Mic
Qualys
Security Update Review: Microsoft & Adobe April 2024 Patch Tuesday | Qualys
blogs_qualys·2024-04-09
Security Update Review: Microsoft & Adobe April 2024 Patch Tuesday | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for April 2024
- Adobe Patches for April 2024
- Other Critical Severity Vulnerabilities Patched in April Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Qualys Monthly Webinar Series
Welcome to another insightful dive into Microsoft’s Patch Tuesday! This month’s security updates address a vast number of vulnerabilities in multiple popular products, features, and roles. We invite you to join us to review and discuss the details of these security updates and patches.
## Microsoft Patch Tu
Krebs
April’s Patch Tuesday Brings Record Number of Fixes
blogs_krebs·2024-04-09·CVSS 8.1
[HIGH] April’s Patch Tuesday Brings Record Number of Fixes
If only Patch Tuesdays came around infrequently — like total solar eclipse rare — instead of just creeping up on us each month like The Man in the Moon. Although to be fair, it would be tough for Microsoft to eclipse the number of vulnerabilities fixed in this month’s patch batch — a record 147 flaws in Windows and related software.
Yes, you read that right. Microsoft today released updates to address 147 security holes in Windows, Office, Azure, .NET Framework, Visual Studio, SQL Server, DNS Server, Windows Defender, Bitlocker, and Windows Secure Boot.
“This is the largest release from Microsoft this year and the largest since at least 2017,” said Dustin Childs, from Trend Micro’s Zero Day Initiative (ZDI). “As far as I can tell, it’s the largest Patch Tuesday release from Microsoft of
Zscaler
Zscaler found Windows Security Vulnerabilities | 04-09-2024
blogs_zscaler·CVSS 7.5
[HIGH] Zscaler found Windows Security Vulnerabilities | 04-09-2024
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2024-04-09
Published
Exploited in the wild