Windows 10: Windows under attack: 0-day vulnerability used by ransomware group

Discus and support Windows under attack: 0-day vulnerability used by ransomware group in Windows 10 News to solve the problem; Microsoft released security updates for Windows yesterday and revealed today that the updates include a patch for a 0-day issue that is exploited in... Discussion in 'Windows 10 News' started by GHacks, Apr 9, 2025.

  1. GHacks
    GHacks New Member

    Windows under attack: 0-day vulnerability used by ransomware group


    Microsoft released security updates for Windows yesterday and revealed today that the updates include a patch for a 0-day issue that is exploited in the wild.

    The vulnerability -- Windows Common Log File System Driver Elevation of Privilege Vulnerability -- is tracked as CVE-2025-29824.

    Important information:

    • The issue affects most supported server and client versions of Windows, including Windows 10, Windows 11, and Windows Server 2025.
    • Microsoft notes that the exploit does not work in Windows 11, version 24H2.
    • It is a use-after-free security issue that may be exploited for local elevation attacks.
    • The attack does not require user interaction.
    • The attacker may gain system privileges upon successful exploitation.

    Microsoft notes that it is aware of limited attacks. It mentions targets in the IT and real estate sectors in the United States, the financial sector in Venezuela, a Spanish software company, and the retail sector in Saudi Arabia specifically in a special announcement on its security website.

    Installation of the update protects systems against exploits. Microsoft's guidance includes an ominous note revealing that the company is delaying the patch for Windows 10 systems. It does not provide an explanation for the delay. Affected users and administrators are asked to monitor the official CVE on Microsoft's MSRC website for updates regarding the rollout of the patch to Windows 10 systems.

    Home users may use Windows Update to install the patch immediately on Windows 11. This is done via Settings > Windows Update. Note that a restart of the system is necessary to finalize the installation of the security update.

    On the technical side, the vulnerability is found in the Common Log File System (CLFS) kernel driver according to Microsoft. The company says that has not determined the initial attack vector, but discovered "some notable pre-exploitation behaviors by Storm-2460".

    Good to known: Storm 2460, which is better known as RansomEXX, is a notorious ransomware group.

    Microsoft observed the following behavior in multiple cases:

    • The threat actor uses the certutil tool to download a malicious file from a legitimate but compromised third-party website.
    • The downloaded file was a malicious MSBuild file.
    • The malware in question goes by the name PipeMagic, which has been known since 2023.
    • After deployment of the malware, it is exploiting the vulnerability described in this guide for process injection into system processes.

    One of the activities of the malware on the user system is the dumping and parsing of LSASS memory to obtain user credentials. Ransomware activity followed on the target systems, notably file encryption and the adding of random extensions.

    Closing Words


    Microsoft recommends to install the Windows security patches immediately to protect systems from exploit attempts. The delay on Windows 10 is unfortunate, as it means that systems remain vulnerable to attacks until Microsoft releases the patch for the system.

    Now You: when do you install updates on your systems? Did you install the April 2025 security updates already?

    Thank you for being a Ghacks reader. The post Windows under attack: 0-day vulnerability used by ransomware group appeared first on gHacks Technology News.

    read more...
     
    GHacks, Apr 9, 2025
    #1
  2. DaveM121 Win User

    About Ransomware attack

    Here is Microsoft's Customer Guidance on the Ransomware Attack:

    • In March, we released a security update which addresses the vulnerability that these attacks are exploiting. Those who have Windows Update enabled are protected against attacks on this vulnerability. For those organizations who have not yet applied the
      security update, we suggest you immediately deploy Microsoft Security Bulletin MS17-010.

    • For customers using Windows Defender, we released an update earlier today which detects this threat as Ransom:Win32/WannaCrypt.
      As an additional “defense-in-depth” measure, keep up-to-date anti-malware software installed on your machines. Customers running anti-malware software from any number of security companies can confirm with their provider, that they are protected.

    • This attack type may evolve over time, so any additional defense-in-depth strategies will provide additional protections. (For example, to further protect against SMBv1 attacks, customers
      should consider blocking legacy protocols on their networks).

    For the full article,
    Click HERE
     
    DaveM121, Apr 9, 2025
    #2
  3. DaveM121 Win User
    Ransomware attack on Windows 10 PCs.... question

    Here is Microsoft's Customer Guidance on the Ransomware Attack:

    • In March, we released a security update which addresses the vulnerability that these attacks are exploiting. Those who have Windows Update enabled are protected against attacks on this vulnerability. For those organizations who have not yet applied the
      security update, we suggest you immediately deploy Microsoft Security Bulletin MS17-010.

    • For customers using Windows Defender, we released an update earlier today which detects this threat as Ransom:Win32/WannaCrypt.
      As an additional “defense-in-depth” measure, keep up-to-date anti-malware software installed on your machines. Customers running anti-malware software from any number of security companies can confirm with their provider, that they are protected.

    • This attack type may evolve over time, so any additional defense-in-depth strategies will provide additional protections. (For example, to further protect against SMBv1 attacks, customers
      should consider blocking legacy protocols on their networks).

    For the full article, Click HERE
     
    DaveM121, Apr 9, 2025
    #3
  4. Windows under attack: 0-day vulnerability used by ransomware group

    Is Windows 10 still vulnerable to WannaCry Ransomware?

    The best defensive strategy to protect yourself from malware and ransomware (crypto malware) infections is a

    comprehensive approach
    to include prevention and your
    best defense is back up, back up, and more back up on a regular basis. When implementing a backup strategy include testing to ensure it works before an emergency arises; routinely check to verify backups are being made and
    stored properly; remove (disconnect) and isolate all backups from the network or home computer...if not, you risk ransomware infecting them when it strikes.


    For more suggestions to protect yourself from ransomware infections, see my comments (Post #2) in this topic...Ransomware
    Avoidance
    ...it includes a list of prevention tools.
     
    quietman7 - MVP, Apr 9, 2025
    #4
Thema:

Windows under attack: 0-day vulnerability used by ransomware group

Loading...
  1. Windows under attack: 0-day vulnerability used by ransomware group - Similar Threads - under attack vulnerability

  2. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Ransomware attack on my pc. All my files such as photos, videos, apps, xlxs, pdf and every thing are encrypted. every file extension shown as *YGKZ format and could not open anything. ID appears to be an online ID encryption. how do i resolve this....
  3. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: I downloaded one file which was containing viruses and now all my Data is encrypted with .omfl extension and i have very important files on my pc. how to recover all file https://answers.microsoft.com/en-us/windows/forum/all/ransomware-attack/305c4fbf-4a2e-4293-9c35-a3bf07f3602d
  4. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Ransomware has attacked my pc. I cant do anything.please help https://answers.microsoft.com/en-us/protect/forum/all/ransomware-attack/f0b64b4b-ea69-4af7-bb37-4f5e4a9ce363
  5. Install Latest Chrome Update to Patch 0-Day Bug Under Active Attacks

    in Windows 10 News
    Install Latest Chrome Update to Patch 0-Day Bug Under Active Attacks: Google yesterday released a new critical software update for its Chrome web browser for desktops that will be rolled out to Windows, Mac, and Linux users over the next few days. The latest Chrome 80.0.3987.122 includes security fixes for three new vulnerabilities, all of...
  6. Latest Microsoft Update Patches New Windows 0-Day Under Active Attack

    in Windows 10 News
    Latest Microsoft Update Patches New Windows 0-Day Under Active Attack: With its latest and last Patch Tuesday for 2019, Microsoft is warning billions of its users of a new Windows zero-day vulnerability that attackers are actively exploiting in the wild in combination with a Chrome exploit to take remote control over vulnerable computers....
  7. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: I have been attacked by ransomware. Is there any way to remove and decrypt the files? Or I have to completely format my hard drive? Seeking attention to Microsoft community. I have attached some screen shots. I am not sure about the ransom type yet. [IMG] [IMG]...
  8. Ransomware attack

    in AntiVirus, Firewalls and System Security
    Ransomware attack: Hello guys, i have a problem and i need help. to cut the long story short, my computer is infected with a ransomware (with ''nelasod'' extension on all docx, xlx, ppt and videos files). This has made it difficult to open any of my document in my external hard drive. It seems...
  9. Ransomware Attack

    in AntiVirus, Firewalls and System Security
    Ransomware Attack: Hello Dear all hope that you all doing well. Somone just hacked my pc.my all files stored on hard drive is converted to PPTX.how can i fix it. https://answers.microsoft.com/en-us/protect/forum/all/ransomware-attack/659f8e54-0800-4449-95f0-94604fae69f6
  10. New Ransomware attack

    in AntiVirus, Firewalls and System Security
    New Ransomware attack: Only 5 days out and Win10 being screwed with. This link was in an E-Mail today: New Windows 10 scam will encrypt your files for ransom | ZDNet 12608