* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Friday, June 6, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    9 things to do this weekend in Lake County plus a look ahead – Leesburg Daily Commercial

    Discover 9 Exciting Weekend Adventures in Lake County and What’s Coming Up!

    Shows to Watch – The Advocate

    Must-See Shows You Can’t Miss!

    Fox News Entertainment Newsletter: Celebrities mentioned during Diddy’s high-profile sex trafficking trial – Fox News

    Fox News Entertainment Newsletter: Celebrities mentioned during Diddy’s high-profile sex trafficking trial – Fox News

    ‘Sinners,’ starring Michael B. Jordan, is now streaming on Prime Video – About Amazon

    Experience the Thrills of ‘Sinners’ Starring Michael B. Jordan – Now Streaming on Prime Video!

    California Mid-State Fair announces entertainment lineups for Frontier and Mission stages – KSBY News

    Exciting Entertainment Lineup Unveiled for California Mid-State Fair’s Frontier and Mission Stages!

    Spotify & OpenAI: Will Gen AI ‘Hollow Out’ Entertainment? – Technology Magazine

    Will Generative AI Transform the Future of Entertainment

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Property Technology Magazine Unveils “PropTech Top 50 Index” and the “2025 PropTech Trends Report – The Great Rebuild.” – Business Wire

    Property Technology Magazine Unveils “PropTech Top 50 Index” and the “2025 PropTech Trends Report – The Great Rebuild.” – Business Wire

    Micron Technology (NASDAQ:MU) Stock Price Expected to Rise, UBS Group Analyst Says – MarketBeat

    UBS Analyst Predicts Surge in Micron Technology Stock Price!

    Domo to Participate in the D.A. Davidson Technology Summit – Business Wire

    Domo Set to Shine at the D.A. Davidson Technology Summit!

    When fiction becomes fact: 3 pieces of modern technology inspired by Star Trek – Redshirts Always Die

    From Screen to Reality: 3 Modern Technologies Inspired by Star Trek

    The Isfahan Center for Nuclear Technology – UCF, ZPP, and IRR10 – Alma Research and Education Center

    Exploring the Isfahan Center for Nuclear Technology: Innovations and Insights from UCF, ZPP, and IRR10

    Inside the tedious effort to tally AI’s energy appetite – MIT Technology Review

    Inside the tedious effort to tally AI’s energy appetite – MIT Technology Review

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    9 things to do this weekend in Lake County plus a look ahead – Leesburg Daily Commercial

    Discover 9 Exciting Weekend Adventures in Lake County and What’s Coming Up!

    Shows to Watch – The Advocate

    Must-See Shows You Can’t Miss!

    Fox News Entertainment Newsletter: Celebrities mentioned during Diddy’s high-profile sex trafficking trial – Fox News

    Fox News Entertainment Newsletter: Celebrities mentioned during Diddy’s high-profile sex trafficking trial – Fox News

    ‘Sinners,’ starring Michael B. Jordan, is now streaming on Prime Video – About Amazon

    Experience the Thrills of ‘Sinners’ Starring Michael B. Jordan – Now Streaming on Prime Video!

    California Mid-State Fair announces entertainment lineups for Frontier and Mission stages – KSBY News

    Exciting Entertainment Lineup Unveiled for California Mid-State Fair’s Frontier and Mission Stages!

    Spotify & OpenAI: Will Gen AI ‘Hollow Out’ Entertainment? – Technology Magazine

    Will Generative AI Transform the Future of Entertainment

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Property Technology Magazine Unveils “PropTech Top 50 Index” and the “2025 PropTech Trends Report – The Great Rebuild.” – Business Wire

    Property Technology Magazine Unveils “PropTech Top 50 Index” and the “2025 PropTech Trends Report – The Great Rebuild.” – Business Wire

    Micron Technology (NASDAQ:MU) Stock Price Expected to Rise, UBS Group Analyst Says – MarketBeat

    UBS Analyst Predicts Surge in Micron Technology Stock Price!

    Domo to Participate in the D.A. Davidson Technology Summit – Business Wire

    Domo Set to Shine at the D.A. Davidson Technology Summit!

    When fiction becomes fact: 3 pieces of modern technology inspired by Star Trek – Redshirts Always Die

    From Screen to Reality: 3 Modern Technologies Inspired by Star Trek

    The Isfahan Center for Nuclear Technology – UCF, ZPP, and IRR10 – Alma Research and Education Center

    Exploring the Isfahan Center for Nuclear Technology: Innovations and Insights from UCF, ZPP, and IRR10

    Inside the tedious effort to tally AI’s energy appetite – MIT Technology Review

    Inside the tedious effort to tally AI’s energy appetite – MIT Technology Review

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Microsoft patches two zero-days for Valentine’s Day

February 15, 2024
in Technology
Microsoft patches two zero-days for Valentine’s Day
Share on FacebookShare on Twitter

Two security feature bypasses impacting Microsoft SmartScreen are on the February Patch Tuesday docket, among more than 70 issues


Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 14 Feb 2024 14:00

Microsoft has patched two actively exploited zero-day vulnerabilities in its February Patch Tuesday – a pair of security feature bypasses affecting Internet Shortcut Files and Windows SmartScreen respectively – out of a total of just over 70 vulnerabilities disclosed in the second drop of 2024.

Among some of the more pressing issues this month are critical vulnerabilities in Microsoft Dynamics, Exchange Server, Office, and Windows Hyper-V and Pragmatic General Multicast, although none of these flaws are being used in the wild quite yet.

Water Hydra

The first of the two zero-days is tracked as CVE-2024-21412 and was found by Trend Micro researchers. It appears to be being used to target foreign exchange traders specifically by a group tracked as Water Hydra.

According to Trend Micro, the cyber criminal gang is leveraging CVE-2024-21412 as part of a wider attack chain in order to bypass SmartScreen and deliver a remote access trojan (RAT) called DarkMe, likely as a precursor to future attacks, possibly involving ransomware.

“CVE-2024-21412 represents a critical vulnerability characterised by sophisticated exploitation of the Microsoft Defender SmartScreen through a zero-day flaw,” explained Saeed Abbasi, product manager for vulnerability research at the Qualys Threat Research Unit.

“This vulnerability is exploited via a specially crafted file delivered through phishing tactics, which cleverly manipulates internet shortcuts and WebDAV components to bypass the displayed security checks.

“The exploitation requires user interaction, attackers must convince the targeted user to open a malicious file, highlighting the importance of user awareness alongside technical defences. The impact of this vulnerability is profound, compromising security and undermining trust in protective mechanisms like SmartScreen,” said Abbasi.

The second zero-day, tracked as CVE-2024-21351, is remarkably similar to the first in that ultimately, it impacts the SmartScreen service. In this case, however, it enables an attacker to get around the checks that it conducts for the so-called Mark-of-the-Web (MotW) that indicates whether a file can be trusted or not, and execute their own code.

“This bypass can occur with minimal user interaction, requiring only that a user opens a malicious file,” said Abbasi. “The impact of this exploit includes potential unauthorised access to data (some loss of confidentiality), severe manipulation or corruption of data (total loss of integrity), and partial disruption of system operations (some loss of availability).

“The significance of this vulnerability lies in its ability to undermine a crucial security defence against malware and phishing attacks, emphasising the urgency for users to update their systems to mitigate the risk.”

Critical vulns

The five critical vulnerabilities this month are, in CVE number order:

CVE-2024-20684, a denial of service (DoS) vulnerability in Windows Hyper-V;
CVE-2024-21357, a remote code execution (RCE) vulnerability in Windows Pragmatic General Multicast (PGM);
CVE-2024-21380, an information disclosure vulnerability in Microsoft Dynamics Business Central/NAV;
CVE-2024-21410, an elevation of privilege (EoP) vulnerability in Microsoft Exchange Server;
CVE-2024-21413, an RCE vulnerability in Microsoft Office.

Assessing this month’s critical vulnerabilities, security experts zoomed in on CVE-2024-21410 in Microsoft Exchange in particular. Kev Breen, senior director of threat research at Immersive Labs, said that it should be high on the list because while it is not marked as being actively exploited, it is much more likely to be exploited.

“This specific vulnerability is known as an NTLM relay or pass-the-hash attack and this style of attack is a favourite for threat actors as it allows them to impersonate users in the network,” he said.

“The way this vulnerability works is that if an attacker is able to collect your NTLM hash, they effectively have the encoded version of your password and can log in to the Exchange Server as you. Microsoft specifically calls out past vulnerabilities like the Outlook zero click exploit CVE-2023-35636 as one method attackers can gain access to this NTLM hash.”

“Financially motivated attackers will be quick to try and weaponise this as it allows for more convincing business email compromise attacks where they can intercept, read and send legitimate email on behalf of employees, for example, from the CEO or CFO,” he said.

Mike Walters, president and co-founder of Action1, drew attention to CVE-2024-21412 in Outlook, which carries a very high severity rating of 9.8 on the CVSS scale.

“Characterised by its network-based attack vector, the vulnerability requires no special privileges or user interaction for exploitation and could significantly impact confidentiality, integrity, and availability,” he said.

An attacker can exploit this vulnerability via the preview pane in Outlook, allowing them to circumvent Office Protected View and force files to open in edit mode, rather than in the safer protected mode,” said Walters.

Walters said that the threat posed by this vulnerability was substantial, possibly enabling an attacker to elevate their privileges and gain the ability to read, write and delete data. Added to this concern, it could also allow them to craft malicious links to bypass Protected View Protocol, leading to the exposure of local NTLM credentials and possibly facilitating remote code execution. As such, it should be treated as a priority.

Read more on Application security and coding requirements


February Patch Tuesday corrects two Windows zero-days

TomWalat

By: Tom Walat


CISA warns Fortinet zero-day vulnerability under attack

ArielleWaldman

By: Arielle Waldman


Ivanti discloses new zero-day flaw, releases delayed patches

ArielleWaldman

By: Arielle Waldman


Critical vulnerability exposes Fortra GoAnywhere users

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366569879/Microsoft-patches-two-zero-days-for-Valentines-Day

Tags: Microsoftpatchestechnology
Previous Post

Met Police to scrap and replace ‘racist’ Gangs Violence Matrix

Next Post

Southern Water customer data was taken in ransomware attack

Ecological Restoration Service Market to Reach USD 87.9 Bn by 2031, Growing at 9.4% CAGR – openPR.com

Ecological Restoration Service Market Set to Soar to $87.9 Billion by 2031 with a Robust 9.4% Growth Rate!

June 6, 2025
Boise State moves forward with plans for new science building, signaling an investment in STEM majors – The Arbiter | Boise State

Boise State Unveils Ambitious Plans for Cutting-Edge Science Building, Boosting STEM Education!

June 6, 2025
The Science Of De-Extinction Is Providing Hope For Nature’s Future – Forbes

Reviving the Past: How De-Extinction Science Offers New Hope for Our Planet’s Future

June 6, 2025
Cardi B Slams Offset For Allegedly Not Helping With Kids’ Six-Figure Lifestyle – HOT 97

Cardi B Calls Out Offset for Failing to Support Their Kids’ Luxurious Lifestyle!

June 6, 2025
Hollywood legend Tom Cruise becomes record holder for his fiery Mission Impossible stunt – Guinness World Records

Tom Cruise Sets the Bar High with Record-Breaking Fiery Stunt in Mission Impossible!

June 6, 2025
India could become third largest economy in the world this year: Borge Brende – MSN

India Poised to Become the World’s Third Largest Economy This Year!

June 6, 2025
9 things to do this weekend in Lake County plus a look ahead – Leesburg Daily Commercial

Discover 9 Exciting Weekend Adventures in Lake County and What’s Coming Up!

June 6, 2025
Property Technology Magazine Unveils “PropTech Top 50 Index” and the “2025 PropTech Trends Report – The Great Rebuild.” – Business Wire

Property Technology Magazine Unveils “PropTech Top 50 Index” and the “2025 PropTech Trends Report – The Great Rebuild.” – Business Wire

June 6, 2025
Graphics: China’s ecological, environmental quality keeps improving steadily – news.cgtn.com

Graphics: China’s ecological, environmental quality keeps improving steadily – news.cgtn.com

June 5, 2025
The Forgotten History (and Slippery Science) of Canola Oil – Eater

The Forgotten History (and Slippery Science) of Canola Oil – Eater

June 5, 2025

Categories

Archives

June 2025
MTWTFSS
 1
2345678
9101112131415
16171819202122
23242526272829
30 
« May    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (670)
  • Economy (684)
  • Entertainment (21,590)
  • General (15,267)
  • Health (9,725)
  • Lifestyle (687)
  • News (22,149)
  • People (685)
  • Politics (691)
  • Science (15,902)
  • Sports (21,187)
  • Technology (15,669)
  • World (669)

Recent News

Ecological Restoration Service Market to Reach USD 87.9 Bn by 2031, Growing at 9.4% CAGR – openPR.com

Ecological Restoration Service Market Set to Soar to $87.9 Billion by 2031 with a Robust 9.4% Growth Rate!

June 6, 2025
Boise State moves forward with plans for new science building, signaling an investment in STEM majors – The Arbiter | Boise State

Boise State Unveils Ambitious Plans for Cutting-Edge Science Building, Boosting STEM Education!

June 6, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version