Microsoft fixes Windows zero-day exploited in QakBot malware attacks

A zero-day vulnerability that was used in campaigns to install QakBot and other malware payloads on susceptible Windows systems has been patched by Microsoft.

This privilege escalation flaw, tracked as CVE-2024-30051, is brought on by a heap-based buffer overflow in the core library of the Desktop Window Manager (DWM). After an attack is successful, the attacker can obtain SYSTEM privileges.

When generating graphical user interface features like glass window frames and 3D transition animations, the OS can employ hardware acceleration thanks to the Desktop Window Manager Windows service, which was first released in Windows Vista.

While looking into another Windows DWM Core Library privilege escalation problem, tracked as CVE-2023-36033 and also used as a zero-day in attacks, Kaspersky security researchers came upon the vulnerability read more Microsoft fixes Windows zero-day exploited in QakBot malware attacks.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *