CVE-2024-30051
published 2024-05-14CVE-2024-30051: Windows DWM Core Library Elevation of Privilege Vulnerability
PriorityP185high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2024-06-04
Exploited in the wild
EPSS
5.69%
92.1th percentile
Windows DWM Core Library Elevation of Privilege Vulnerability
Affected
35 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20651 | 10.0.10240.20651 |
| microsoft | windows_10_1607 | < 10.0.14393.6981 | 10.0.14393.6981 |
| microsoft | windows_10_1809 | < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_10_21h2 | < 10.0.19044.4412 | 10.0.19044.4412 |
| microsoft | windows_10_22h2 | < 10.0.19045.4412 | 10.0.19045.4412 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20651 | 10.0.10240.20651 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.6981 | 10.0.14393.6981 |
| microsoft | windows_10_version_1809 | >= 10.0.0 < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_10_version_21h2 | >= 10.0.19043.0 < 10.0.19044.4412 | 10.0.19044.4412 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.4412 | 10.0.19045.4412 |
| microsoft | windows_11_21h2 | < 10.0.22000.2960 | 10.0.22000.2960 |
| microsoft | windows_11_22h2 | < 10.0.22621.3593 | 10.0.22621.3593 |
| microsoft | windows_11_23h2 | < 10.0.22631.3593 | 10.0.22631.3593 |
| microsoft | windows_11_version_21h2 | >= 10.0.0 < 10.0.22000.2960 | 10.0.22000.2960 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.3593 | 10.0.22621.3593 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.3593 | 10.0.22631.3593 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.3593 | 10.0.22631.3593 |
| microsoft | windows_server_2016 | < 10.0.14393.6981 | 10.0.14393.6981 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.6981 | 10.0.14393.6981 |
| microsoft | windows_server_2019 | < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.5820 | 10.0.17763.5820 |
| microsoft | windows_server_2022 | < 10.0.20348.2458 | 10.0.20348.2458 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.2461 | 10.0.20348.2461 |
| msrc | windows_10 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2024-30051 is exploited as part of post-compromise activity for local privilege escalation, delivered via socially engineered document files sent over email, social media, or instant messaging. ↗
- →Once CVE-2024-30051 is exploited, the attacker can bypass OLE mitigations in Microsoft 365 and Microsoft Office; monitor for OLE mitigation bypass activity in Office processes. ↗
- →CVE-2024-30051 is used in conjunction with QakBot malware deployments; detections for QakBot loader activity should be correlated with DWM EoP exploit attempts. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Windows DWM Core Library Elevation of Privilege Vulnerability
vendor_msrc·2024-05-14·CVSS 7.8
CVE-2024-30051 [HIGH] CWE-122 Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Windows DWM Core Library: Windows DWM Core Library
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:Yes;Exploited:Yes;Latest Software Release:Exploitation Detected;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5037765
Reference: https://support.microsoft.com/help/5037765
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5037782
Reference: https://support.microsoft.com/help/5037782
Reference: https://catalog.updat
CISA
Microsoft DWM Core Library Privilege Escalation Vulnerability
cisa·2024-05-14·CVSS 7.8
CVE-2024-30051 [HIGH] CWE-122 Microsoft DWM Core Library Privilege Escalation Vulnerability
Vulnerability: Microsoft DWM Core Library Privilege Escalation Vulnerability
Affected: Microsoft DWM Core Library
Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2024-30051; https://nvd.nist.gov/vuln/detail/CVE-2024-30051
Remediation Due Date: 2024-06-04
GHSA
GHSA-rq9g-8pvx-hrqx: Windows DWM Core Library Elevation of Privilege Vulnerability
ghsa_unreviewed·2024-05-14
CVE-2024-30051 [HIGH] CWE-122 GHSA-rq9g-8pvx-hrqx: Windows DWM Core Library Elevation of Privilege Vulnerability
Windows DWM Core Library Elevation of Privilege Vulnerability
VulnCheck
Microsoft DWM Core Library Privilege Escalation Vulnerability
vulncheck·2024·CVSS 7.8
CVE-2024-30051 [HIGH] CWE-122 Microsoft DWM Core Library Privilege Escalation Vulnerability
Microsoft DWM Core Library Privilege Escalation Vulnerability
Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
Affected: Microsoft DWM Core Library
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2024-May; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2024-30051; https://securelist.com/cve-2024-30051/112618/; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.zerodayinitiative.com/bl
VulnCheck
Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
vulncheck·2023·CVSS 7.8
CVE-2023-36033 [HIGH] CWE-822 Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
Microsoft Windows Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability
Microsoft Windows Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2023-Nov; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://ti.qianxin.com/uploads/2024/02/02/dcc93e586f9028c68e7ab34c3326ff31.pdf; https://securelist.com/cve-2024-30051/112618/; https://securelist.com/it-thr
No detection rules found.
No public exploits indexed.
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
blogs_greynoiseio·2026-02-02
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Securelist
Mem3nt0 mori – The Hacking Team is back!
blogs_securelist·2025-10-27·CVSS 8.3
[HIGH] Mem3nt0 mori – The Hacking Team is back!
Table of Contents
- Attack chain
- Finding Dante
- Dante
- Conclusion
- Indicators of compromise
Authors
- Boris Larin
In March 2025, Kaspersky detected a wave of infections that occurred when users clicked on personalized phishing links sent via email. No further action was required to initiate the infection; simply visiting the malicious website using Google Chrome or another Chromium-based web browser was enough.
The malicious links were personalized and extremely short-lived to avoid detection. However, Kaspersky’s technologies successfully identified a sophisticated zero-day exploit that was used to escape Google Chrome’s sandbox. After conducting a quick analysis, we reported the vulnerability to the Google security team, who fixed it as CVE-2025-2783.
Acknowledgement for find
Krebs
Patch Tuesday, May 2025 Edition
blogs_krebs·2025-05-14·CVSS 7.8
[HIGH] Patch Tuesday, May 2025 Edition
Microsoft on Tuesday released software updates to fix at least 70 vulnerabilities in Windows and related products, including five zero-day flaws that are already seeing active exploitation . Adding to the sense of urgency with this month’s patch batch from Redmond are fixes for two other weaknesses that now have public proof-of-concept exploits available.
Microsoft and several security firms have disclosed that attackers are exploiting a pair of bugs in the Windows Common Log File System (CLFS) driver that allow attackers to elevate their privileges on a vulnerable device. The Windows CLFS is a critical Windows component responsible for logging services, and is widely used by Windows system services and third-party applications for logging. Tracked as CVE-2025-32701 & CVE-2025-32706 , the
Krebs
Patch Tuesday, May 2025 Edition
blogs_krebs·2025-05-14·CVSS 7.8
[HIGH] Patch Tuesday, May 2025 Edition
Microsoft on Tuesday released software updates to fix at least 70 vulnerabilities in Windows and related products, including five zero-day flaws that are already seeing active exploitation. Adding to the sense of urgency with this month’s patch batch from Redmond are fixes for two other weaknesses that now have public proof-of-concept exploits available.
Microsoft and several security firms have disclosed that attackers are exploiting a pair of bugs in the Windows Common Log File System (CLFS) driver that allow attackers to elevate their privileges on a vulnerable device. The Windows CLFS is a critical Windows component responsible for logging services, and is widely used by Windows system services and third-party applications for logging. Tracked as CVE-2025-32701 & CVE-2025-32706, these
Tenable
Microsoft’s May 2025 Patch Tuesday Addresses 71 CVEs (CVE-2025-32701, CVE-2025-32706, CVE-2025-30400)
blogs_tenable·2025-05-13·CVSS 7.8
[HIGH] Microsoft’s May 2025 Patch Tuesday Addresses 71 CVEs (CVE-2025-32701, CVE-2025-32706, CVE-2025-30400)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Tenable
Microsoft Patch Tuesday 2024 Year in Review
blogs_tenable·2024-12-10
Microsoft Patch Tuesday 2024 Year in Review
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
Meet hrtng, Kaspersky GReAT’s plugin for IDA Pro
blogs_securelist·2024-12-05
Meet hrtng, Kaspersky GReAT’s plugin for IDA Pro
Table of Contents
Authors
- Georgy Kucherin
Update 18.02.2025: hrtng plugin won the 2024 Plugin Contest held by the IDA Pro developer, Hex-Rays.
Nowadays, a lot of cybersecurity professionals use IDA Pro as their primary tool for reverse engineering. While IDA is a complex tool that implements a multitude of features useful for dissecting binaries, many reverse engineers use various plugins to add further functionality to this software. We in the Global Research and Analysis Team do the same – and over the years we have developed our own IDA plugin named hrtng that is specifically designed to aid us with malware reverse engineering.
We started working on hrtng back in 2016, when we forked the hexrays_tools plugin developed by Milan Bohacek. Since then, our highly experienced reverse
Securelist
Kaspersky report on APT trends in Q3 2024
blogs_securelist·2024-11-28
Kaspersky report on APT trends in Q3 2024
Table of Contents
- The most remarkable findings
- Chinese-speaking activity
- Europe
- Middle East
- Southeast Asia and Korean Peninsula
- Hacktivism
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
Kaspersky’s Global Research and Analysis Team (GReAT) has been releasing quarterly summaries of advanced persistent threat (APT) activity for over seven years now. Based on our threat intelligence research, these summaries offer a representative overview of what we’ve published and discussed in more detail in our private APT reports. They are intended to highlight the significant events and findings that we think are important for people to know about. This is our latest roundup, covering activity we observed during Q3 2024.
If you’d like to learn more about our intellige
Securelist
APT trends report Q3 2024
blogs_securelist·2024-11-28
APT trends report Q3 2024
Table of Contents
The most remarkable findings
Chinese-speaking activity
Europe
Middle East
Southeast Asia and Korean Peninsula
Hacktivism
Other interesting discoveries
Final thoughts
Authors
GReAT
Kaspersky’s Global Research and Analysis Team (GReAT) has been releasing quarterly summaries of advanced persistent threat (APT) activity for over seven years now. Based on our threat intelligence research, these summaries offer a representative overview of what we’ve published and discussed in more detail in our private APT reports. They are intended to highlight the significant events and findings that we think are important for people to know about. This is our latest roundup, covering activity we observed during Q3 2024.
If you’d like to learn more about our intelligence reports
Securelist
Lazarus APT steals cryptocurrency and user data via a decoy MOBA game
blogs_securelist·2024-10-23
Lazarus APT steals cryptocurrency and user data via a decoy MOBA game
Table of Contents
- Introduction
- The exploit
- Shellcode
- Social activity
- The game
- Conclusions
- Indicators of Compromise
Authors
- Boris Larin
- Vasily Berdnikov
## Introduction
Lazarus APT and its BlueNoroff subgroup are a highly sophisticated and multifaceted Korean-speaking threat actor. We closely monitor their activities and quite often see them using their signature malware in their attacks — a full-feature backdoor called Manuscrypt. According to our research, Lazarus has been employing this malware since at least 2013 and we’ve documented its usage in 50+ unique campaigns targeting governments, diplomatic entities, financial institutions, military and defense contractors, cryptocurrency platforms, IT and telecommunication operators, gaming companies, media outlets, ca
Securelist
IT threat evolution Q2 2024
blogs_securelist·2024-09-03
IT threat evolution Q2 2024
Table of Contents
Targeted attacks
XZ backdoor: a supply chain attack in the making
Timeline of events
DuneQuixote campaign targeting the Middle East
ToddyCat: punching holes in your infrastructure
Other malware
QakBot attacks with Windows zero-day
Using the LockBit builder to generate targeted ransomware
Stealers, stealers and more stealers
ShrinkLocker: turning BitLocker into a ransomware utility
Authors
David Emm
## Targeted attacks
## XZ backdoor: a supply chain attack in the making
On March 29, a message on the Openwall oss-security mailing list announced the discovery of a backdoor in XZ, a compression utility included in many popular Linux distributions. The backdoored library is used by the OpenSSH server process sshd . On a number of systemd -based distributions, in
Securelist
Malware report for Q2 2024 — a quarterly review
blogs_securelist·2024-09-03
Malware report for Q2 2024 — a quarterly review
Table of Contents
- Targeted attacks
- Other malware
Authors
- David Emm
## Targeted attacks
### XZ backdoor: a supply chain attack in the making
On March 29, a message on the Openwall oss-security mailing list announced the discovery of a backdoor in XZ, a compression utility included in many popular Linux distributions. The backdoored library is used by the OpenSSH server process sshd. On a number of systemd-based distributions, including Ubuntu, Debian and RedHat/Fedora Linux, OpenSSH is patched to use systemd features and is therefore dependent on the library (Arch Linux and Gentoo are not affected). The code was inserted in February and March 2024, mostly by Jia Cheong Tan – probably a fictitious identity. We suspect that the goal of the attack was to introduce exclusive remote
Checkpoint
20th May – Threat Intelligence Report
blogs_checkpoint·2024-05-20
CVE-2024-30051 20th May – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 20th May – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 20th May, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Australian electronic prescriptions provider MediSecure suffered a significant ransomware attack, leading to widespread disruptions and data breaches. The impact of the attack has been profound, broadly affecting healthcare data broadly in the country.
WebTPA, an American healthcare management and administrative services provide
Talos
Rounding up some of the major headlines from RSA
blogs_talos·2024-05-16
Rounding up some of the major headlines from RSA
## Rounding up some of the major headlines from RSA
While I one day wish to make it to the RSA Conference in person, I’ve never had the pleasure of making the trek to San Francisco for one of the largest security conferences in the U.S.
Instead, I had to watch from afar and catch up on the internet every day like the common folk. This at least gives me the advantage of not having my day totally slip away from me on the conference floor, so at least I felt like I didn’t miss much in the way of talks, announcements and buzz. So, I wanted to use this space to recap what I felt like the top stories and trends were coming out of RSA last week.
Here’s a rundown of some things you may have missed if you weren’t able to stay on top of the things coming out of the conference.
AI is the talk of
Talos
Rounding up some of the major headlines from RSA
blogs_talos·2024-05-16
Rounding up some of the major headlines from RSA
While I one day wish to make it to the RSA Conference in person, I’ve never had the pleasure of making the trek to San Francisco for one of the largest security conferences in the U.S.
Instead, I had to watch from afar and catch up on the internet every day like the common folk. This at least gives me the advantage of not having my day totally slip away from me on the conference floor, so at least I felt like I didn’t miss much in the way of talks, announcements and buzz. So, I wanted to use this space to recap what I felt like the top stories and trends were coming out of RSA last week.
Here’s a rundown of some things you may have missed if you weren’t able to stay on top of the things coming out of the conference.
AI is the talk of the town
This is unsurprising given how every other
Qualys
Microsoft and Adobe Patch Tuesday, May 2024 Security Update Review
blogs_qualys·2024-05-14
Microsoft and Adobe Patch Tuesday, May 2024 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for May 2024
Adobe Patches for May 2024
Zero-day Vulnerabilities Patched in May Patch Tuesday Edition
Critical Severity Vulnerability Patched in May Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
Qualys Monthly Webinar Series
Microsoft has released its May edition of Patch Tuesday. Let’s take a deep dive into the crucial insights from Microsoft’s Patch Tuesday updates for May 2024.
## Microsoft Patch Tuesday for May 2024
Microsoft Patch Tuesday’s May 2024 edition addressed 67 vulnerabilities, including one critical and 59 important severity vulnerabilities.
Krebs
Patch Tuesday, May 2024 Edition
blogs_krebs·2024-05-14·CVSS 8.8
CVE-2024-30051 [HIGH] Patch Tuesday, May 2024 Edition
Microsoft today released updates to fix more than 60 security holes in Windows computers and supported software, including two “zero-day” vulnerabilities in Windows that are already being exploited in active attacks. There are also important security patches available for macOS and Adobe users, and for the Chrome Web browser, which just patched its own zero-day flaw.
First, the zero-days. CVE-2024-30051 is an “elevation of privilege” bug in a core Windows library. Satnam Narang at Tenable said this flaw is being used as part of post-compromise activity to elevate privileges as a local attacker.
“CVE-2024-30051 is used to gain initial access into a target environment and requires the use of social engineering tactics via email, social media or instant messaging to convince a target to ope
Trendmicro
The May 2024 Security Update Review
blogs_trendmicro·2024-05-14·CVSS 7.8
[HIGH] The May 2024 Security Update Review
# The May 2024 Security Update Review
Get the May 2024 security update and review.
By: Dustin Childs
2024/05/14
Read time: ( words)
Save to Folio
Welcome to the second Tuesday of May. As expected, Adobe and Microsoft have released their standard bunch of security patches. Take a break from your regular activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Apple Patches for May 2024
Apple kicked off the May release cycle with a group of updates for their macOS and iOS platforms. Most notable is a fix for CVE-2024-23296 for iOS 16.7.8 and iPadOS 16.7.8. This vulnerability is a memory corruption issue in RTKit that could allow attackers to bypass kernel memory protec
Krebs
Patch Tuesday, May 2024 Edition
blogs_krebs·2024-05-14·CVSS 8.8
CVE-2024-30051 [HIGH] Patch Tuesday, May 2024 Edition
Microsoft today released updates to fix more than 60 security holes in Windows computers and supported software, including two “zero-day” vulnerabilities in Windows that are already being exploited in active attacks. There are also important security patches available for macOS and Adobe users, and for the Chrome Web browser, which just patched its own zero-day flaw.
First, the zero-days. CVE-2024-30051 is an “elevation of privilege” bug in a core Windows library. Satnam Narang at Tenable said this flaw is being used as part of post-compromise activity to elevate privileges as a local attacker.
“CVE-2024-30051 is used to gain initial access into a target environment and requires the use of social engineering tactics via email, social media or instant messaging to convince a target to ope
Qualys
Microsoft Patch Tuesday May 2024: Critical Fixes | Qualys
blogs_qualys·2024-05-14
Microsoft Patch Tuesday May 2024: Critical Fixes | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for May 2024
- Adobe Patches for May 2024
- Zero-day Vulnerabilities Patched in May Patch Tuesday Edition
- Critical Severity Vulnerability Patched in May Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- Qualys Monthly Webinar Series
Microsoft has released its May edition of Patch Tuesday. Let’s take a deep dive into the crucial insights from Microsoft’s Patch Tuesday updates for May 2024.
## Microsoft Patch Tuesday for May 2024
Microsoft Patch Tuesday’s May 2024 edition addressed 67 vulnerabilities, including one critical and 59 important severity vulne
Bleepingcomputer
Microsoft fixes Windows zero-day exploited in QakBot malware attacks
blogs_bleepingcomputer·2024-05-14·CVSS 7.8
CVE-2023-36033 [HIGH] Microsoft fixes Windows zero-day exploited in QakBot malware attacks
## Microsoft fixes Windows zero-day exploited in QakBot malware attacks
## Sergiu Gatlan
Kaspersky security researchers discovered the vulnerability while investigating another Windows DWM Core Library privilege escalation bug tracked as CVE-2023-36033 and also exploited as a zero-day in attacks.
While combing through data related to recent exploits and associated attacks, they stumbled upon an intriguing file uploaded to VirusTotal on April 1, 2024. The file's names hinted that it contained details on a Windows vulnerability.
As they discovered, the file provided information (in broken English) regarding a Windows Desktop Window Manager (DWM) vulnerability that could be exploited to escalate privileges to SYSTEM, with the outlined exploitation processing perfectly mirroring the one us
Talos
Only one critical vulnerability included in May’s Microsoft Patch Tuesday; One other zero-day in DWN Core
blogs_talos·2024-05-14·CVSS 6.8
CVE-2024-30044 [MEDIUM] Only one critical vulnerability included in May’s Microsoft Patch Tuesday; One other zero-day in DWN Core
After a relatively hefty Microsoft Patch Tuesday in April, this month’s security update from the company only included one critical vulnerability across its massive suite of products and services.
In all, May’s slate of vulnerabilities disclosed by Microsoft included 59 total CVEs, most of which are considered to be of “important” severity. There is only one moderate-severity vulnerability.
The lone critical security issue is CVE-2024-30044, a remote code execution vulnerability in SharePoint Server. An authenticated attacker who obtains Site Owner permissions or higher could exploit this vulnerability by uploading a specially crafted file to the targeted SharePoint Server. Then, they must craft specialized API requests to trigger the deserialization of that file’s parameters, potentiall
Securelist
QakBot attacks with Windows zero-day (CVE-2024-30051)
blogs_securelist·2024-05-14·CVSS 7.8
CVE-2023-36033 [HIGH] QakBot attacks with Windows zero-day (CVE-2024-30051)
Authors
Boris Larin
Mert Degirmenci
In early April 2024, we decided to take a closer look at the Windows DWM Core Library Elevation of Privilege Vulnerability CVE-2023-36033 , which was previously discovered as a zero-day exploited in the wild. While searching for samples related to this exploit and attacks that used it, we found a curious document uploaded to VirusTotal on April 1, 2024. This document caught our attention because it had a rather descriptive file name, which indicated that it contained information about a vulnerability in Windows OS. Inside we found a brief description of a Windows Desktop Window Manager (DWM) vulnerability and how it could be exploited to gain system privileges, everything written in very broken English. The exploitation process described in this docum
Trendmicro
The May 2024 Security Update Review
blogs_trendmicro·2024-05-14·CVSS 7.8
[HIGH] The May 2024 Security Update Review
## The May 2024 Security Update Review
Get the May 2024 security update and review.
By: Dustin Childs 2024/05/14 Read time: ( words)
Save to Folio
Welcome to the second Tuesday of May. As expected, Adobe and Microsoft have released their standard bunch of security patches. Take a break from your regular activities and join us as we review the details of their latest advisories. If you’d rather watch the full video recap covering the entire release, you can check it out here:
Apple Patches for May 2024
Apple kicked off the May release cycle with a group of updates for their macOS and iOS platforms. Most notable is a fix for CVE-2024-23296 for iOS 16.7.8 and iPadOS 16.7.8 . This vulnerability is a memory corruption issue in RTKit that could allow attackers to bypass kernel memory prote
Tenable
Microsoft’s May 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-30051, CVE-2024-30040)
blogs_tenable·2024-05-14·CVSS 8.8
[HIGH] Microsoft’s May 2024 Patch Tuesday Addresses 59 CVEs (CVE-2024-30051, CVE-2024-30040)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Bleepingcomputer
Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
blogs_bleepingcomputer·2024-05-14·CVSS 8.8
[HIGH] Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
## Microsoft May 2024 Patch Tuesday fixes 3 zero-days, 61 flaws
## Lawrence Abrams
17 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
27 Remote Code Execution Vulnerabilities
7 Information Disclosure Vulnerabilities
3 Denial of Service Vulnerabilities
4 Spoofing Vulnerabilities
The total count of 61 flaws does not include 2 Microsoft Edge flaws fixed on May 2nd and four fixed on May 10th.
To learn more about the non-security updates released today, you can review our dedicated articles on the new Windows 11 KB5037771 cumulative update and the Windows 10 KB5037768 update .
## Three zero-days fixed
This month's Patch Tuesday fixes two actively exploited and one publicly disclosed zero-day vulnerabilities.
Microsoft classifies a zero-day as a flaw
Securelist
QakBot attacks with Windows zero-day (CVE-2024-30051)
blogs_securelist·2024-05-14·CVSS 7.8
CVE-2024-30051 [HIGH] QakBot attacks with Windows zero-day (CVE-2024-30051)
Authors
- Boris Larin
- Mert Degirmenci
In early April 2024, we decided to take a closer look at the Windows DWM Core Library Elevation of Privilege Vulnerability CVE-2023-36033, which was previously discovered as a zero-day exploited in the wild. While searching for samples related to this exploit and attacks that used it, we found a curious document uploaded to VirusTotal on April 1, 2024. This document caught our attention because it had a rather descriptive file name, which indicated that it contained information about a vulnerability in Windows OS. Inside we found a brief description of a Windows Desktop Window Manager (DWM) vulnerability and how it could be exploited to gain system privileges, everything written in very broken English. The exploitation process described in this doc
Talos
Only one critical vulnerability included in May’s Microsoft Patch Tuesday; One other zero-day in DWN Core
blogs_talos·2024-05-14·CVSS 6.8
[MEDIUM] Only one critical vulnerability included in May’s Microsoft Patch Tuesday; One other zero-day in DWN Core
## Only one critical vulnerability included in May’s Microsoft Patch Tuesday; One other zero-day in DWN Core
After a relatively hefty Microsoft Patch Tuesday in April, this month’s security update from the company only included one critical vulnerability across its massive suite of products and services.
In all, May’s slate of vulnerabilities disclosed by Microsoft included 59 total CVEs, most of which are considered to be of “important” severity. There is only one moderate-severity vulnerability.
The lone critical security issue is CVE-2024-30044 , a remote code execution vulnerability in SharePoint Server. An authenticated attacker who obtains Site Owner permissions or higher could exploit this vulnerability by uploading a specially crafted file to the targeted SharePoint Server. Then
Securelist
Operation Triangulation: The last (hardware) mystery
blogs_securelist·2023-12-27·CVSS 5.5
CVE-2023-38606 [MEDIUM] Operation Triangulation: The last (hardware) mystery
Table of Contents
- Operation Triangulation’ attack chain
- The mystery and the CVE-2023-38606 vulnerability
- Technical details
- Conclusion
- Update 2024-01-09
Authors
- Boris Larin
UPD 23.04.2025: MITRE created a page for Operation Triangulation as part of its ATT&CK framework.
Today, on December 27, 2023, we (Boris Larin, Leonid Bezvershenko, and Georgy Kucherin) delivered a presentation, titled, “Operation Triangulation: What You Get When Attack iPhones of Researchers”, at the 37th Chaos Communication Congress (37C3), held at Congress Center Hamburg. The presentation summarized the results of our long-term research into Operation Triangulation, conducted with our colleagues, Igor Kuznetsov, Valentin Pashkov, and Mikhail Vinogradov.
This presentation was also the first time we h
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #3 – October 2022)
blogs_securelist·2023-12-21·CVSS 7.8
[HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #3 – October 2022)
Authors
- Boris Larin
This is part four of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operators (Ex
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023-23376)
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2023-23376 [HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #4 – CVE-2023-23376)
Authors
- Boris Larin
This is part five of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operators (Ex
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #2 – September 2022)
blogs_securelist·2023-12-21·CVSS 7.8
[HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #2 – September 2022)
Authors
- Boris Larin
This is the third part of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operator
Securelist
Windows CLFS and five exploits used by ransomware operators
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2023-28252 [HIGH] Windows CLFS and five exploits used by ransomware operators
Authors
- Boris Larin
In April 2023, we published a blog post about a zero-day exploit we discovered in ransomware attacks that was patched as CVE-2023-28252 after we promptly reported it to Microsoft.
In that blog post, we mentioned that the zero-day exploit we discovered was very similar to other Microsoft Windows elevation-of-privilege (EoP) exploits that we have seen in ransomware attacks throughout the year. We found that since June 2022, attackers have used exploits for at least five different Common Log File System (CLFS) driver vulnerabilities. Four of these vulnerabilities used by the attackers (CVE-2022-24521, CVE-2022-37969, CVE-2023-23376, CVE-2023-28252) have been captured in the wild as zero-days.
Seeing a Win32k driver zero-day being used in attacks isn’t really surprisi
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022-24521)
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2022-24521 [HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #1 – CVE-2022-24521)
Authors
- Boris Larin
This is the second part of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous part first if you haven’t already.
You can skip to the other parts using this table of contents or using the link at the end of this part.
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operator
Securelist
Windows CLFS and five exploits used by ransomware operators (Exploit #5 – CVE-2023-28252)
blogs_securelist·2023-12-21·CVSS 7.8
CVE-2023-28252 [HIGH] Windows CLFS and five exploits used by ransomware operators (Exploit #5 – CVE-2023-28252)
Authors
- Boris Larin
This is part six of our study about the Common Log File System (CLFS) and five vulnerabilities in this Windows OS component that have been used in ransomware attacks throughout the year. Please read the previous parts first if you haven’t already.
You can go to other parts using this table of contents:
- Part 1 – Windows CLFS and five exploits of ransomware operators
- Part 2 – Windows CLFS and five exploits of ransomware operators (Exploit #1 – CVE-2022-24521)
- Part 3 – Windows CLFS and five exploits of ransomware operators (Exploit #2 – September 2022)
- Part 4 – Windows CLFS and five exploits of ransomware operators (Exploit #3 – October 2022)
- Part 5 – Windows CLFS and five exploits of ransomware operators (Exploit #4 – CVE-2023-23376)
- Part 6 – Windows CLF
Securelist
Tool to find the Operation Triangulation traces
blogs_securelist·2023-06-02
Tool to find the Operation Triangulation traces
Table of Contents
- How to back up your device
- How to use our triangle_check utility
- Interpreting the results
Authors
- Igor Kuznetsov
- Valentin Pashkov
- Leonid Bezvershenko
- Georgy Kucherin
UPD 23.04.2025: MITRE created a page for Operation Triangulation as part of its ATT&CK framework.
In our initial blogpost about “Operation Triangulation”, we published a comprehensive guide on how to manually check iOS device backups for possible indicators of compromise using MVT. This process takes time and requires manual search for several types of indicators. To automate this process, we developed a dedicated utility to scan the backups and run all the checks. For Windows and Linux, this tool can be downloaded as a binary build, and for MacOS it can be simply installed as a Python pac
Securelist
Nokoyawa ransomware attacks with Windows zero-day
blogs_securelist·2023-04-11·CVSS 7.8
[HIGH] Nokoyawa ransomware attacks with Windows zero-day
Table of Contents
- Elevation-of-privilege exploit
- Post exploitation and malware
- Conclusions
- Indicators of compromise
Authors
- Boris Larin
Updated April 20, 2023
In February 2023, Kaspersky technologies detected a number of attempts to execute similar elevation-of-privilege exploits on Microsoft Windows servers belonging to small and medium-sized businesses in the Middle East, in North America, and previously in Asia regions. These exploits were very similar to already known Common Log File System (CLFS) driver exploits that we analyzed previously, but we decided to double check and it was worth it – one of the exploits turned out to be a zero-day, supporting different versions and builds of Windows, including Windows 11. The exploit was highly obfuscated with more than 80% of
Securelist
How to train your Ghidra
blogs_securelist·2022-12-09
How to train your Ghidra
Table of Contents
- Getting started with Ghidra
- Disclaimer
- Building Ghidra
- Setting up the UI
- Opening a file for analysis
- Going further
- A few more things
- This is just the beginning
Authors
- Igor Kuznetsov
## Getting started with Ghidra
For about two decades, being a reverse engineer meant that you had to master the ultimate disassembly tool, IDA Pro. Over the years, many other tools were created to complement or directly replace it, but only a few succeeded. Then came the era of decompilation, adding even more to the cost and raising the barrier to entry into the RE field.
Then, in 2019, Ghidra was published: a completely open-source and free tool, with a powerful disassembler and a built-in decompiler for each supported platform. However, the first release did not loo
Securelist
OpenTIP, command line edition
blogs_securelist·2022-08-11
OpenTIP, command line edition
Table of Contents
- A few words about privacy
- Setting things up
- The OpenTIP Scanner
- The IOC checker script
- The Python API class
- Any ideas are welcome
Authors
- Igor Kuznetsov
For more than a year, we have been providing free intelligence services via the OpenTIP portal. Using the web interface, anyone can upload and scan files with our antivirus engine, get a basic sandbox report, look up various network indicators (IP addresses, hosts, URLs). Later on, we presented an easy-to-use HTTPS-based programming interface, so that you could use the service in your own scripts and integrate it in existing workflow.
OpenTIP web interface – upload, look up, get results!
Of course, it is much easier to use the API when there is a set of working examples. It is also more convenient to
Securelist
Extracting type information from Go binaries
blogs_securelist·2021-10-27
Extracting type information from Go binaries
Authors
- Ivan Kwiatkowski
During the 2021 edition of the SAS conference, I had the pleasure of delivering a workshop focused on reverse-engineering Go binaries. The goal of the workshop was to share basic knowledge that would allow analysts to immediately start looking into malware written in Go. A YouTube version of the workshop was released around the same time. Of course, the drawback of providing entry-level or immediately actionable information is that a few subtleties must be omitted. One particular topic I brushed aside was related to the way that Go creates objects.
In this screenshot taken from IDA Pro, we can see a call to the runtime.newobject function, which receives a structure as an argument (here, in the RDX register, two lines above the call). The malware presented in t
Securelist
MysterySnail attacks with Windows zero-day
blogs_securelist·2021-10-12·CVSS 7.8
CVE-2016-3309 [HIGH] MysterySnail attacks with Windows zero-day
Table of Contents
- Executive Summary
- Elevation of privilege exploit
- MysterySnail RAT
- IoCs
Authors
- Boris Larin
- Costin Raiu
## Executive Summary
In late August and early September 2021, Kaspersky technologies detected attacks with the use of an elevation of privilege exploit on multiple Microsoft Windows servers. The exploit had numerous debug strings from an older, publicly known exploit for vulnerability CVE-2016-3309, but closer analysis revealed that it was a zero-day. We discovered that it was using a previously unknown vulnerability in the Win32k driver and exploitation relies heavily on a technique to leak the base addresses of kernel modules. We promptly reported these findings to Microsoft. The information disclosure portion of the exploit chain was identified as no
Securelist
PuzzleMaker attacks with Chrome zero-day exploit chain
blogs_securelist·2021-06-08·CVSS 5.5
[MEDIUM] PuzzleMaker attacks with Chrome zero-day exploit chain
Table of Contents
- Remote code execution exploit
- Elevation of privilege exploit
- Malware modules
- IoCs
Authors
- Costin Raiu
- Boris Larin
- Alexey Kulaev
On April 14-15, 2021, Kaspersky technologies detected a wave of highly targeted attacks against multiple companies. Closer analysis revealed that all these attacks exploited a chain of Google Chrome and Microsoft Windows zero-day exploits. While we were not able to retrieve the exploit used for remote code execution (RCE) in the Chrome web browser, we were able to find and analyze an elevation of privilege (EoP) exploit that was used to escape the sandbox and obtain system privileges.
The elevation of privilege exploit was fine-tuned to work against the latest and most prominent builds of Windows 10 (17763 – RS5, 18362 – 19H1,
Securelist
Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild
blogs_securelist·2021-04-13·CVSS 7.8
CVE-2021-28310 [HIGH] Zero-day vulnerability in Desktop Window Manager (CVE-2021-28310) used in the wild
Authors
- Boris Larin
- Costin Raiu
- Brian Bartholomew
While analyzing the CVE-2021-1732 exploit originally discovered by the DBAPPSecurity Threat Intelligence Center and used by the BITTER APT group, we discovered another zero-day exploit we believe is linked to the same actor. We reported this new exploit to Microsoft in February and after confirmation that it is indeed a zero-day, it received the designation CVE-2021-28310. Microsoft released a patch to this vulnerability as a part of its April security updates.
We believe this exploit is used in the wild, potentially by several threat actors. It is an escalation of privilege (EoP) exploit that is likely used together with other browser exploits to escape sandboxes or get system privileges for further access. Unfortunately, we weren
Securelist
Operation PowerFall: CVE-2020-0986 and variants
blogs_securelist·2020-09-02·CVSS 7.8
CVE-2020-0986 [HIGH] Operation PowerFall: CVE-2020-0986 and variants
Authors
- Boris Larin
In August 2020, we published a blog post about Operation PowerFall. This targeted attack consisted of two zero-day exploits: a remote code execution exploit for Internet Explorer 11 and an elevation of privilege exploit targeting the latest builds of Windows 10. While we already described the exploit for Internet Explorer in the original blog post, we also promised to share more details about the elevation of privilege exploit in a follow-up post. Let’s take a look at vulnerability CVE-2020-0986, how it was exploited by attackers, how it was fixed and what additional mitigations were implemented to complicate exploitation of many other similar vulnerabilities.
## CVE-2020-0986
CVE-2020-0986 is an arbitrary pointer dereference vulnerability in GDI Print/Print Spool
Securelist
Internet Explorer and Windows zero-day exploits used in Operation PowerFall
blogs_securelist·2020-08-12·CVSS 7.5
[HIGH] Internet Explorer and Windows zero-day exploits used in Operation PowerFall
Authors
- Boris Larin
## Executive summary
In May 2020, Kaspersky technologies prevented an attack on a South Korean company by a malicious script for Internet Explorer. Closer analysis revealed that the attack used a previously unknown full chain that consisted of two zero-day exploits: a remote code execution exploit for Internet Explorer and an elevation of privilege exploit for Windows. Unlike a previous full chain that we discovered, used in Operation WizardOpium, the new full chain targeted the latest builds of Windows 10, and our tests demonstrated reliable exploitation of Internet Explorer 11 and Windows 10 build 18363 x64.
On June 8, 2020, we reported our discoveries to Microsoft, and the company confirmed the vulnerabilities. At the time of our report, the security team at Mi
Securelist
GReAT thoughts: Awesome IDA Pro plugins
blogs_securelist·2020-07-21
GReAT thoughts: Awesome IDA Pro plugins
Authors
- Boris Larin
The Global Research & Analysis Team here at Kaspersky has a tradition of meeting up once a month and sharing cutting-edge research, interesting techniques and useful tools. We recently took the unprecedented decision to make our internal meetings public for a few months and present them as a series of talks called ‘GReAT Ideas. Powered by SAS’. In the second edition that takes place on July 22, 2020, I’ll be talking about awesome IDA Pro plugins that I regularly use. This article is a sneak peek into what I’ll be discussing.
## Highlighting control-flow transfer instructions
When you are reverse-engineering a binary it’s very important to follow control-flow transfer instructions and especially those instructions that are used to transfer the control flow to other
Securelist
Magnitude exploit kit – evolution
blogs_securelist·2020-06-24·CVSS 7.5
[HIGH] Magnitude exploit kit – evolution
Table of Contents
- Introduction
- Shellcode
- Elevation of privilege exploit
- Ransomware
- Conclusions
Authors
- Boris Larin
Exploit kits are not as widespread as they used to be. In the past, they relied on the use of already patched vulnerabilities. Newer and more secure web browsers with automatic updates simply do not allow known vulnerabilities to be exploited. It was very different back in the heyday of Adobe Flash because it’s just a plugin for a web browser, meaning that even if the user has an up-to-date browser, there’s a non-zero chance that Adobe Flash may still be vulnerable to 1-day exploits. Now that Adobe Flash is about to reach its end-of-life date at the end of this year, it is disabled by default in all web browser and has pretty much been replaced with open stand
Securelist
The zero-day exploits of Operation WizardOpium
blogs_securelist·2020-05-28·CVSS 8.8
[HIGH] The zero-day exploits of Operation WizardOpium
Table of Contents
- Google Chrome remote code execution exploit
- Microsoft Windows elevation of privilege exploit
- Conclusions
Authors
- Boris Larin
- Alexey Kulaev
Back in October 2019 we detected a classic watering-hole attack on a North Korea-related news site that exploited a chain of Google Chrome and Microsoft Windows zero-days. While we’ve already published blog posts briefly describing this operation (available here and here), in this blog post we’d like to take a deep technical dive into the exploits and vulnerabilities used in this attack.
## Google Chrome remote code execution exploit
In the original blog post we described the exploit loader responsible for initial validation of the target and execution of the next stage JavaScript code containing the full browser explo
Securelist
Cybersecurity Research During the Coronavirus Outbreak and After
blogs_securelist·2020-02-20
Cybersecurity Research During the Coronavirus Outbreak and After
Authors
- Vitaly Kamluk
Virus outbreaks are always gruesome: people, animals or computer systems get infected within a short time. Of course, viruses spreading across our physical world always take priority over the virtual world. Nevertheless, everyone should keep doing their job, which includes all kinds of malware researchers, digital forensics experts and incident responders. At times like this, we all realize how important it is to be able to work remotely. However, the duties of a security researcher or a digital forensics expert pushes them to travel, visit victims or collect digital evidence in an ongoing hunt for malware artefacts. What can we do to reduce the need for travel? Of course, keep looking for replacement of our physical routines with remote ones.
It is about two and
Securelist
How we developed our simple Harbour decompiler
blogs_securelist·2019-12-20
How we developed our simple Harbour decompiler
Authors
- Konstantin Zykov
https://github.com/KasperskyLab/hb_dec
Every once in a while we get a request that leaves us scratching our heads. With these types of requests, existing tools are usually not enough and we have to create our own custom tooling to solve the “problem”. One such request dropped onto our desk at the beginning of 2018, when one of our customers – a financial institution – asked us to analyze a sample. This in itself is nothing unusual – we receive requests like that all the time. But what was unusual about this particular request was that the sample was written in ‘Harbour’. For those of you who don’t know what Harbour is (just like us), you can take a look here, or carry on reading.
Harbour is a programming language originally designed by Antonio Linares that sa
Securelist
Ransomware: two pieces of good news
blogs_securelist·2019-09-25
Ransomware: two pieces of good news
Authors
- AMR
## Decryptors released for Yatron and FortuneCrypt ransomware
“All your files have been encrypted.” How many times has this suddenly popped up on your screen? We hope never, because it’s one of the most common indicators that you’ve lost access to your files. And if there are no publicly available decryptors or you don’t have any backup copies, you’re in trouble.
Nowadays, cybercriminals have a thousand and one ways of creating and spreading ransomware. There are two common scenarios behind the creation of this kind of malware: in one, the criminals prefer to just reconfigure existing malicious source code; in the other, they choose to write their own ransomware, sometimes even using very specific languages.
However, don’t despair, because those fighting ransomware are n
Securelist
New win32k zero day: CVE-2019-0859
blogs_securelist·2019-04-15·CVSS 7.8
CVE-2019-0859 [HIGH] New win32k zero day: CVE-2019-0859
Authors
- Vasily Berdnikov
- Boris Larin
- Anton Ivanov
In March 2019, our automatic Exploit Prevention (EP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. It was the fifth consecutive exploited Local Privilege Escalation vulnerability in Windows that we have discovered in recent months using our technologies. The previous ones were:
- Zero-day exploit (CVE-2018-8453) used in targeted attacks
- A new exploit for zero-day vulnerability CVE-2018-8589
- Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
- The fourth horseman: CVE-2019-0797 vulnerability
On March 17, 2019 we reported our discovery to Microsoft; the company confirmed the
Securelist
The fourth horseman: CVE-2019-0797 vulnerability | Securelist
blogs_securelist·2019-03-13·CVSS 7.8
CVE-2019-0797 [HIGH] The fourth horseman: CVE-2019-0797 vulnerability | Securelist
Authors
- Vasily Berdnikov
- Boris Larin
## The new zero-day in the Windows OS exploited in targeted attacks
In February 2019, our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis of this event led to us discovering a zero-day vulnerability in win32k.sys. We reported it to Microsoft on February 22, 2019. The company confirmed the vulnerability and assigned it CVE-2019-0797. Microsoft have just released a patch, crediting Kaspersky Lab researchers Vasiliy Berdnikov and Boris Larin with the discovery:
This is the fourth consecutive exploited Local Privilege Escalation vulnerability in Windows we have discovered recently using our technologies. Just like with CVE-2018-8589, we believe this
Securelist
Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
blogs_securelist·2018-12-12·CVSS 7.8
CVE-2018-8611 [HIGH] Zero-day in Windows Kernel Transaction Manager (CVE-2018-8611)
Authors
- Boris Larin
- Vladislav Stolyarov
- Anton Ivanov
## Executive summary
In October 2018, our AEP (Automatic Exploit Prevention) systems detected an attempt to exploit a vulnerability in the Microsoft Windows operating system. Further analysis led us to uncover a zero-day vulnerability in ntoskrnl.exe. We reported it to Microsoft on October 29, 2018. The company confirmed the vulnerability and assigned it CVE-2018-8611. Microsoft just released a patch, part of its December update, crediting Kaspersky Lab researchers Boris Larin (Oct0xor) and Igor Soumenkov (2igosha) with the discovery.
This is the third consecutive exploited Local Privilege Escalation vulnerability in Windows we discovered this autumn using our technologies. Unlike the previously reported vulnerabilities in win3
Securelist
A new exploit for zero-day vulnerability CVE-2018-8589
blogs_securelist·2018-11-14·CVSS 7.8
CVE-2018-8589 [HIGH] A new exploit for zero-day vulnerability CVE-2018-8589
Authors
- Boris Larin
- Anton Ivanov
- Vladislav Stolyarov
Yesterday, Microsoft published its security bulletin, which patches a vulnerability discovered by our technologies. We reported it to Microsoft on October 17, 2018. The company confirmed the vulnerability and assigned it CVE-2018-8589.
In October 2018, our Automatic Exploit Prevention (AEP) systems detected an attempt to exploit a vulnerability in Microsoft’s Windows operating system. Further analysis revealed a zero-day vulnerability in win32k.sys. The exploit was executed by the first stage of a malware installer in order to gain the necessary privileges for persistence on the victim’s system. So far, we have detected a very limited number of attacks using this vulnerability. The victims are located in the Middle East.
Kasper
Securelist
Delving deep into VBScript
blogs_securelist·2018-07-03·CVSS 8.8
CVE-2018-8174 [HIGH] Delving deep into VBScript
Authors
- Boris Larin
## Analysis of CVE-2018-8174 exploitation
In late April we found and wrote a description of CVE-2018-8174, a new zero-day vulnerability for Internet Explorer that was picked up by our sandbox. The vulnerability uses a well-known technique from the proof-of-concept exploit CVE-2014-6332 that essentially “corrupts” two memory objects and changes the type of one object to Array (for read/write access to the address space) and the other object to Integer to fetch the address of an arbitrary object.
But whereas CVE-2014-6332 was aimed at integer overflow exploitation for writing to arbitrary memory locations, my interest lay in how this technique was adapted to exploit the use-after-free vulnerability. To answer this question, let’s consider the internal structure of t
Securelist
Modern OSs for embedded systems
blogs_securelist·2018-06-20
Modern OSs for embedded systems
Table of Contents
- Monolithic systems
- Monolithic kernel systems
- Microkernel operating systems
- Hybrid operating systems
- The ‘secure by design’ requirement
- KasperskyOS
- Conclusion
Authors
- Alexander Shadrin
- Andrey Nikishin
## A review from KasperskyOS developers
At Kaspersky Lab we analyze the technologies available on cybersecurity market and this time we decided to look at what OS developers are offering for embedded systems (or, in other words, the internet of things). Our primary interest is how and to what degree these OSs can solve cybersecurity-related issues.
We’d like to point out that this review reflects the author’s subjective opinion, and for the purposes of this analysis we developed our own classification of OSs.
Moreover, throughout this research we hav
Securelist
The King is dead. Long live the King!
blogs_securelist·2018-05-09·CVSS 7.5
CVE-2018-8174 [HIGH] The King is dead. Long live the King!
Authors
- Vladislav Stolyarov
- Boris Larin
- Anton Ivanov
## Root cause analysis of the latest Internet Explorer zero day – CVE-2018-8174
In late April 2018, a new zero-day vulnerability for Internet Explorer (IE) was found using our sandbox; more than two years since the last in the wild example (CVE-2016-0189). This particular vulnerability and subsequent exploit are interesting for many reasons. The following article will examine the core reasons behind the latest vulnerability, CVE-2018-8174.
### Searching for the zero day
Our story begins on VirusTotal (VT), where someone uploaded an interesting exploit on April 18, 2018. This exploit was detected by several AV vendors including Kaspersky, specifically by our generic heuristic logic for some older Microsoft Word exploits.
After
Securelist
Your new friend, KLara
blogs_securelist·2018-03-28
Your new friend, KLara
Authors
- GReAT
## GReAT’s distributed YARA scanner
While doing threat research, teams need a lot of tools and systems to aid their hunting efforts – from systems storing Passive DNS data and automated malware classification to systems allowing researchers to pattern-match a large volume of data in a relatively short period of time. These tools are extremely useful when working on APT campaigns where research is very agile and spans multiple months. One of the most frequently used tools for hunting new variants of malware is called YARA and was developed by Victor Manuel Alvarez while working for VirusTotal, now part of Alphabet.
In R&D we use a lot of open-source projects and we believe giving back to the community is our way of saying ‘Thank you’. More and more security companies are
Securelist
Disappearing bytes: Reverse engineering the MS Office RTF parser
blogs_securelist·2018-02-21
Disappearing bytes: Reverse engineering the MS Office RTF parser
Table of Contents
- State reset
- Final destination
- Fixed-size buffer
- Unnecessary data
- Kind of magic
- Conclusion
Authors
- Boris Larin
Microsoft Office was a prime target for attacks in 2017. As well as the large number of vulnerabilities discovered and proof-of-concept exploits published, malware authors felt it necessary to prevent detection of ‘one-day’ and ‘old-day’ exploits by antivirus software. It also became clear that using RTF parsing features and peculiarities are no longer enough to effectively evade detection. Along with the rise of MS Office exploitation, when RTF is used as a container for an exploit, we encountered lots of samples that were ‘exploiting’ the implementation of Microsoft Word’s RTF parser to confuse all other third-party RTF parsers, including thos
Securelist
A vulnerable driver: lesson almost learned
blogs_securelist·2018-02-08
A vulnerable driver: lesson almost learned
Authors
- Vladislav Stolyarov
- Boris Larin
## How not to use a driver to execute code with kernel privileges
Recently, we started receiving suspicious events from our internal sandbox Exploit Checker plugin. Our heuristics for supervisor mode code execution in the user address space were constantly being triggered, and an executable file was being flagged for further analysis. At first, it looked like we’d found a zero-day local privilege escalation vulnerability for Windows, but the sample that was triggering Exploit Checker events turned out to be the clean signed executable GundamOnline.exe, part of the multiplayer online game Mobile Suit Gundam Online from BANDAI NAMCO Online Inc.
The initial sample is packed using a custom packer and contains anti-analysis techniques that complic
Securelist
Happy IR in the New Year!
blogs_securelist·2017-12-28
Happy IR in the New Year!
Authors
- Sergey Golovanov
- Igor Kuznetsov
At the end of last year Mr. Jake Williams from aka @MalwareJake asked a very important question about Lack of visibility during detecting APT intrusions in twitter. Results show us that endpoint analysis is the most important part of any research connected with APTs. Also, for sure endpoint forensics is critical during any Incident Response (IR) because in many cases the initial intrusion happened too far away in time so there are no relevant logs and no backups to identify the first victim and the way how attackers were moving from one computer to another. At least once a year we have such issues during IR activities with our customers. In these cases we use a very simple script that is uploaded to every Windows computer in the corporate netwo
Securelist
Analyzing an exploit for СVE-2017-11826
blogs_securelist·2017-10-26
Analyzing an exploit for СVE-2017-11826
Authors
- Boris Larin
The latest Patch Tuesday (17 October) brought patches for 62 vulnerabilities, including one that fixed СVE-2017-11826 – a critical zero-day vulnerability used to launch targeted attacks – in all versions of Microsoft Office.
The exploit for this vulnerability is an RTF document containing a DOCX document that exploits СVE-2017-11826 in the Office Open XML parser.
The exploit itself is in word/document.xml as follows:
Under the ECMA-376 standard for Office Open XML File Formats, the valid ‘font’ element describing the fonts used in the document must look like this:
In the body of the exploit the closing tag is absent. The opening tag is followed by the object element which cause ‘type confusion’ in the OOXML parser. Any object element can be used to successfully
Securelist
Bitscout – The Free Remote Digital Forensics Tool Builder
blogs_securelist·2017-07-06
Bitscout – The Free Remote Digital Forensics Tool Builder
Authors
- Vitaly Kamluk
Being a malware researcher means you are always busy with the struggle against mountains of malware and cyberattacks around the world. Over the past decade, the number of daily new malware findings raised up to unimaginable heights: with hundreds of thousands of malware samples per day! However, while there are some rare and dangerous malware, not every sample is as malicious as these. Moreover, some of the biggest threats exist only when several ingredients are put together, including multiple malware tools, malicious infrastructure, and interactive commands coming from their operators.
This is why, instead of only looking at malware, we have started tracking groups of attackers and have focused on campaigns and isolated incidents. This has been an increasingly
Securelist
Malicious code and the Windows integrity mechanism
blogs_securelist·2016-11-28
Malicious code and the Windows integrity mechanism
Authors
- Vyacheslav Rusakov
## Introduction
Ask any expert who analyzes malicious code for Windows which system privileges malware works with and wants to acquire and, without a second thought, they’ll tell you: “Administrator rights”. Are there any studies to back this up? Unfortunately, I was unable to find any coherent analysis on the subject; however, it is never too late to play Captain Obvious and present the facts for public evaluation.
My goal wasn’t to review the techniques of elevating system privileges; the Internet already has plenty of articles on the subject. New mechanisms are discovered every year, and each technique deserves its own review. Here, I wanted to look at the overall picture and talk about the whole range of Windows operating systems in all their diversity
Crowdstrike
May 2024 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] May 2024 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
2024-05-14
Published
2024-05-14
Added to CISA KEV
Exploited in the wild