April 2, 2024, 2:15 p.m. | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

 


January 2024 Windows Updates brought a patch for CVE-2024-21320, a privilege escalation vulnerability in Windows. The vulnerability allows a remote attacker to acquire user's NTLM credentials when the victim simply downloads a Theme file or views such file in a network folder.

Security researcher Tomer Peled of Akamai discovered this issue, reported it to Microsoft, and later published a detailed article along with a proof of concept.
These allowed us to reproduce the issue and create a micropatch …

akamai a network attacker credentials cve cve-2024 downloads escalation file folder issue january january 2024 network ntlm patch privilege privilege escalation researcher security security researcher theme tomer peled updates victim vulnerability windows windows themes windows updates

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Senior - Penetration Tester

@ Deloitte | Madrid, España

Associate Cyber Incident Responder

@ Highmark Health | PA, Working at Home - Pennsylvania

Senior Insider Threat Analyst

@ IT Concepts Inc. | Woodlawn, Maryland, United States