Microsoft fixes Windows zero-day bug exploited in ransomware attacks: Report
The researchers said they saw at least five different exploits of this kind, which were used in attacks on retail and wholesale, energy, manufacturing, healthcare, software development and other industries.
Microsoft has fixed a zero-day vulnerability affecting all supported versions of Windows, which experts say hackers exploited to launch ransomware attacks, a new report said on Thursday.
In February, researchers discovered an attack using a zero-day vulnerability in the Microsoft Common Log File System (CLFS). A cybercriminal group used an exploit developed for different versions and builds of Windows OS, including Windows 11 and attempted to deploy a Nokoyawa ransomware attack, according to the cybersecurity firm Kaspersky.
Microsoft assigned `CVE-2023-28252` to the discovered zero-day bug.
Attackers used the CVE-2023-28252 vulnerability to elevate privileges and steal credentials from the Security Account Manager (SAM) database.
While most of the vulnerabilities are used by APTs (Advanced Persistent Threat), the researchers stated that this one turned out to be exploited for cybercrime purposes by a sophisticated group that carries out ransomware attacks.
"Cybercrime groups are becoming increasingly more sophisticated using zero-day exploits in their attacks. Previously it was primarily a tool of APTs, but now cybercriminals have the resources to acquire zero-days and routinely use them in attacks," said Boris Larin, Lead Security Researcher with the Global Research and Analysis Team (GReAT).
"It`s very important for businesses to download the latest patch from Microsoft as soon as possible, and use other methods of protection, such as EDR solutions," he added.
Moreover, the report said that the hackers also attempted to execute similar elevation of privilege exploits in attacks on different small and medium-sized businesses in the Middle East and North America, and previously in Asia regions.
The researchers said they saw at least five different exploits of this kind, which were used in attacks on retail and wholesale, energy, manufacturing, healthcare, software development and other industries.
Get Latest Business News, Stock Market Updates and Videos; Check your tax outgo through Income Tax Calculator and save money through our Personal Finance coverage. Check Business Breaking News Live on Zee Business Twitter and Facebook. Subscribe on YouTube.
RECOMMENDED STORIES
Senior Citizen Latest FD Rates: Know what major banks like SBI, PNB, Canara Bank, HDFC Bank, ICICI Bank are providing on fixed deposits
Gratuity Calculator: Rs 38,000 as last-drawn basic salary, 5 years and 5 months of service; what will be gratuity amount?
Retirement Planning: In how many years your Rs 25K monthly SIP investment will grow to Rs 8.8 cr | See calculations
Top 5 Small Cap Mutual Funds with best SIP returns in 1 year: See how Rs 25,000 monthly investment has grown in each scheme
Top 7 SBI Mutual Funds With Best SIP Returns in 1 Year: Rs 25,000 monthly SIP investment in No.1 fund has jumped to Rs 3,58,404
SBI 5-Year FD vs MIS: Which can offer higher returns on a Rs 2,00,000 investment over 5 years? See calculations
07:44 AM IST