U1 News
  • Home
  • World
  • U.S.
  • Business
  • Technology
  • Science
  • Entertainment
  • Sport
  • Health
Global News

Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

July 30, 2024

Taylor Swift speaks out after Southport mass stabbing at dance class

July 30, 2024

3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

July 30, 2024
Facebook Twitter Instagram
Trending
  • FDA approves first at-home HPV test to screen for cervical cancer
  • Brain stimulation technology improves Parkinson’s treatment for music conductor
  • Left-handedness linked to autism, schizophrenia in major neurological study
  • Heart health unexpectedly affected by shingles vaccine
  • Doctors remove spinal cancer through eye socket in revolutionary surgery
  • Laundry done at home by healthcare workers may spread superbugs, says new study
  • Longevity and organ function predicted in new ‘body clock’ tool
  • ‘Magic mushrooms’ may offer major relief for Parkinson’s patients, study shows
Sunday, May 11
U1 News
  • Home
  • World

    Israel targets Hezbollah commander in Beirut strike after deadly Golan Heights attack

    July 30, 2024

    Taylor Swift speaks out after Southport mass stabbing at dance class

    July 30, 2024

    3 girls killed in stabbing at Taylor Swift-themed UK dance class. 7 people still critically wounded

    July 30, 2024

    Kerala, India, hit by landslides, killing at least 99

    July 30, 2024

    Taylor Swift ‘in shock’ after horrific UK stabbing, as police say 3rd child dies

    July 30, 2024
  • U.S.

    Biden criticises ‘extreme’ Supreme Court in push for reform

    July 30, 2024

    FBI details shooter’s search history before Trump assassination attempt

    July 30, 2024

    Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

    July 29, 2024

    Biden to call for major Supreme Court reforms, including term limits, at Civil Rights Act event Monday

    July 29, 2024

    Sonya Massey’s death revives pain for Breonna Taylor, Floyd activists

    July 29, 2024
  • Business

    AMD stock jumps on earnings beat driven by AI chip sales

    July 30, 2024

    Amazon is responsible for dangerous products sold on its site, federal agency rules

    July 30, 2024

    Microsoft investigating new outages of services after global CrowdStrike chaos

    July 30, 2024

    S&P 500, Nasdaq Tumble as Chip Stocks Slide Ahead of Big Tech Earnings

    July 30, 2024

    American consumers feeling more confident in July as expectations of future improve

    July 30, 2024
  • Technology

    Apple says Safari protects your privacy. We fact checked those claims.

    July 30, 2024

    GameStop Dunks On Xbox 360 Store Closing And Gets Savaged

    July 30, 2024

    Logitech has an idea for a “forever mouse” that requires a subscription

    July 30, 2024

    Friend: a new digital companion for the AI age

    July 30, 2024

    London Sports Mod Community Devolves Into War

    July 30, 2024
  • Science

    NASA’s Lunar Gateway has a big visiting vehicles problem

    August 1, 2024

    Boeing’s Cursed ISS Mission May Finally Make It Back to Earth

    July 30, 2024

    Should you floss before or after you brush your teeth?

    July 30, 2024

    Ancient swimming sea bug ‘taco’ had mandibles, new fossils show

    July 30, 2024

    NASA’s DART asteroid impact mission revealed ages of twin space rock targets (images)

    July 30, 2024
  • Entertainment

    Richard Gadd Backs Netflix to Get ‘Baby Reindeer’ Lawsuit Dismissed

    July 30, 2024

    Batman: Caped Crusader review: a pulpy throwback to DC’s Golden Age

    July 30, 2024

    Channing Tatum Praises Ryan Reynolds For Taking Gamble On Gambit

    July 30, 2024

    ‘Star Wars Outlaws’ somehow made me fall in love with Star Wars again

    July 30, 2024

    Great Scott and O’Brien’s Pub find new life in Allston

    July 30, 2024
  • Sport

    How Snoop Dogg became a fixture of the Paris Olympics

    July 30, 2024

    Team USA’s Coco Gauff exits Olympics singles tournament with a third-round loss : NPR

    July 30, 2024

    French police investigating abuse targeting Olympic opening ceremony DJ over ‘Last Supper’ scene

    July 30, 2024

    French DJ Takes Legal Action

    July 30, 2024

    Why BYU’s Jimmer Fredette is at the 2024 Paris Olympics

    July 30, 2024
  • Health

    FDA approves first at-home HPV test to screen for cervical cancer

    May 10, 2025

    Brain stimulation technology improves Parkinson’s treatment for music conductor

    May 10, 2025

    Left-handedness linked to autism, schizophrenia in major neurological study

    May 10, 2025

    Heart health unexpectedly affected by shingles vaccine

    May 9, 2025

    Doctors remove spinal cancer through eye socket in revolutionary surgery

    May 9, 2025
U1 News
Home»Technology»Threat actors exploited Windows 0-day for more than a year before Microsoft fixed it
Technology

Threat actors exploited Windows 0-day for more than a year before Microsoft fixed it

u1news-staffBy u1news-staffJuly 11, 2024No Comments4 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Malware 760x380.jpg
Share
Facebook Twitter LinkedIn Pinterest Email

Getty Images

Researchers said Tuesday that threat actors had been using the malware to launch zero-day attacks against Windows users for more than a year before Microsoft patched the vulnerability.

The vulnerability exists in both Windows 10 and 11 and causes the device to open Internet Explorer, the legacy browser provided by Microsoft. Obsolete In 2022, Windows ended support for the browser because its aging codebase had made it more vulnerable to exploits. The change made it difficult, and in some cases impossible, for Windows to open the browser, which was first introduced in the mid-1990s, in normal operation.

Old tricks and new tricks

According to the researchers who discovered and reported the vulnerability to Microsoft, malicious code exploiting the vulnerability dates back to at least January 2023 and was in the wild as early as May of this year. Repaired The vulnerability, tracked as CVE-2024-CVE-38112, was disclosed on Tuesday as part of the company’s Patch Tuesday program. The vulnerability, which is in the Windows MSHTML engine, has a severity rating of 7.0 out of 10.

Researchers at security firm Check Point said the exploit employed “a new (or previously unknown) trick to lure Windows users into remote code execution.” The links that supposedly open PDF files added a .url extension to the end of the file. For example, one file had the extension Books_A0UJKO.pdf.url. Malicious Code Samples.

When viewed in Windows, the file displayed an icon indicating it was a PDF file rather than a .url file, which are files designed to open with the application specified in the link.

A screenshot showing a file named Books_A0UJKO.pdf, with the file icon indicating it's a PDF.
Expanding / A screenshot showing a file named Books_A0UJKO.pdf, with the file icon indicating it’s a PDF.

Checkpoint

The link within the file calls msedge.exe, the file that runs Edge. However, the link incorporates two attributes (mhtml: and !x-usc:), an “old trick” that threat actors have used for years to open applications like MS Word on Windows. It also contained a link to a malicious website. When clicked, the .url file, disguised as a PDF, opens the site in Internet Explorer instead of Edge.

“From there (where the website opens in IE), an attacker can do a lot of bad things since IE is insecure and outdated,” wrote Haifei Li, the Check Point researcher who discovered the vulnerability. “For example, if an attacker has a zero-day exploit for IE (which is much easier to find compared to Chrome/Edge), they can hit the victim and perform remote code execution right away. However, in the samples we analyzed, the threat actors did not use an IE remote code execution exploit. Instead, they used a different trick for IE, which to our knowledge was probably not publicly known before, to trick the victim into performing remote code execution.”

IE will then display a dialog box to the user, asking if they want to open the file disguised as a PDF.[開く]If you click, Windows will display a second dialog box with a vague notification that continuing will open the content on your Windows device.[許可]When clicked, IE loads any file ending in .hta, which causes Windows to open the file in Internet Explorer and execute the embedded code.

Screenshot showing an open IE window and the IE-generated dialog box prompting you to open the Books_A0UJKO.pdf file.
Expanding / Screenshot showing an open IE window and the IE-generated dialog box prompting you to open the Books_A0UJKO.pdf file.

Checkpoint

Screenshot of IE security box asking user for confirmation
Expanding / Screenshot of the IE security box asking the user if they want to “open web content” using IE.

Checkpoint

“To summarize the attacks from an exploitation standpoint, the first technique used in these campaigns is the ‘mhtml’ trick, which allows the attackers to invoke IE instead of the more secure Chrome/Edge,” Li wrote. “The second technique is an IE trick that tricks the victim into believing they’re opening a PDF file, but they’re actually downloading and running a dangerous .hta application. The overall goal of these attacks is to trick the victim into believing they’re opening a PDF file, and using these two tricks allows them to do just that.”

Check Point’s post includes cryptographic hashes of the six malicious .url files used in the campaign: Windows users can use the hashes to check if they’ve been targeted.

0day actors exploited fixed Microsoft Threat Windows Year
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
u1news-staff
u1news-staff
  • Website

Related Posts

Colorado baby infected with measles in state’s second case of the year

April 8, 2025

‘I vaped for one year and almost died’

March 1, 2025

5 years after COVID, Americans are split on whether it’s still a threat

February 24, 2025

Heavy cannabis use could pose this threat to the brain

February 12, 2025
Add A Comment

Leave A Reply Cancel Reply

Latest Posts

FDA approves first at-home HPV test to screen for cervical cancer

May 10, 2025

Brain stimulation technology improves Parkinson’s treatment for music conductor

May 10, 2025

Left-handedness linked to autism, schizophrenia in major neurological study

May 10, 2025

Heart health unexpectedly affected by shingles vaccine

May 9, 2025
Unites States

Biden criticises ‘extreme’ Supreme Court in push for reform

July 30, 2024

FBI details shooter’s search history before Trump assassination attempt

July 30, 2024

Reps. Mike Kelly, Jason Crow to lead task force on Trump rally shooting

July 29, 2024

Subscribe to Updates

Get the latest sports news from SportsSite about soccer, football and tennis.

Copyright ©️ All rights reserved. | U1 News
  • Home
  • About Us
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • Disclaimer

Type above and press Enter to search. Press Esc to cancel.