Tag: Windows Common Log File System (CLFS)

PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware
News

PipeMagic Trojan Exploits Windows Zero-Day Vulnerability to Deploy Ransomware

Microsoft has disclosed that ransomware attacks targeting a limited number of targets exploited a now-patched security hole affecting the Windows Common Log File System (CLFS) as a zero-day vulnerability. The computer giant claimed the targets include companies in the US IT and real estate industries, the Venezuelan banking sector, a Spanish software company, and the Saudi Arabian retail industry. It is possible to obtain SYSTEM rights by exploiting the privilege escalation bug in CLFS, CVE-2025-29824. Redmond corrected problem as part of its April 2025 Patch Tuesday update. Under the alias Storm-2460, Microsoft is monitoring the activity and post-compromise exploitation of CVE-2025-29824. The threat actors are also using a piece of malware called PipeMagic to distribute the expl...