Critical Windows Zero-Day Alert: No Patch Available Yet for Users

Share:

Protect your systems with automated patching and server hardening strategies to defend against vulnerabilities like the NTLM zero-day. Stay proactive and secure your business.

Protect your systems with automated patching and server hardening strategies to defend against vulnerabilities like the NTLM zero-day. Stay proactive and secure your business.

A newly discovered Windows zero-day vulnerability exposes users across multiple Windows versions to credential theft. Discovered by 0patch researchers, this critical security flaw allows attackers to steal NTLM credentials through a deceptive yet simple method.

What Makes This Vulnerability Dangerous?

Widespread Impact

The vulnerability affects a wide range of Windows systems, including:

  • Windows Server 2022
  • Windows 11 (up to v24H2)
  • Windows 10 (multiple versions)
  • Windows 7 and Server 2008 R2

Exploitation Mechanism

Technical details of the vulnerability are withheld to minimize exploitation risk until Microsoft issues a fix to minimize any further risk of exploitation.

The vulnerability enables attackers to steal a user’s NTLM credentials by luring them into opening a malicious file in Windows Explorer.

Attackers can trigger the vulnerability through minimal user interaction:

  • Opening a shared folder
  • Accessing a USB disk
  • Simply viewing a malicious file in Windows Explorer
  • Accessing the Downloads folder with a strategically placed file

The Broader Context of Unpatched Vulnerabilities

This isn’t an isolated incident. The same research team has previously identified multiple unresolved Windows vulnerabilities, including:

  • Windows Theme file issue
  • “Mark of the Web” vulnerability
  • “EventLogCrasher” vulnerability
  • Three NTLM-related vulnerabilities (PetitPotam, PrinterBug/SpoolSample, and DFSCoerce)

0patch Micropatches

0patch is offering a free micropatch for the latest NTLM zero-day to all users registered on its platform until Microsoft releases an official fix. The security micropatch has already been automatically deployed to PRO and Enterprise accounts, except in cases where configurations explicitly block automatic updates.

“The impact on enterprises using outdated and legacy infrastructure is more significant than the simple impact on operating costs, said Jim Routh,” Chief Trust Officer at cybersecurity company Saviynt. “In this case, the obsolete authentication application (NTLM) from MS enables threat actors to steal Windows credentials potentially compromising customer experience.”

Focusing on the proactive approach

Automated patch management, like the protection provided to PRO and Enterprise accounts through 0patch, is a great start, but organizations need to do more. Implementing strong server-hardening strategies can add multiple layers of defence by setting consistent security configurations across all systems.

This proactive approach goes beyond simply reacting to vulnerabilities, helping businesses stay protected against threats like the recent NTLM zero-day vulnerability.

Source

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
8:45 am, Jan 18, 2025
weather icon 2°C
L: 1° | H: 3°
overcast clouds
Humidity: 89 %
Pressure: 1031 mb
Wind: 5 mph E
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 100%
Rain Chance: 0%
Visibility: 7 km
Sunrise: 7:56 am
Sunset: 4:24 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
1° | 3°°C 0 mm 0% 4 mph 90 % 1031 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
1° | 5°°C 0 mm 0% 7 mph 93 % 1024 mb 0 mm/h
Mon Jan 20 9:00 pm
weather icon
3° | 8°°C 0.26 mm 26% 6 mph 97 % 1019 mb 0 mm/h
Tue Jan 21 9:00 pm
weather icon
4° | 8°°C 0 mm 0% 8 mph 95 % 1019 mb 0 mm/h
Wed Jan 22 9:00 pm
weather icon
4° | 7°°C 1 mm 100% 4 mph 99 % 1012 mb 0 mm/h
Today 9:00 am
weather icon
2° | 2°°C 0 mm 0% 2 mph 89 % 1031 mb 0 mm/h
Today 12:00 pm
weather icon
3° | 5°°C 0 mm 0% 3 mph 83 % 1031 mb 0 mm/h
Today 3:00 pm
weather icon
4° | 6°°C 0 mm 0% 3 mph 75 % 1028 mb 0 mm/h
Today 6:00 pm
weather icon
3° | 3°°C 0 mm 0% 4 mph 88 % 1026 mb 0 mm/h
Today 9:00 pm
weather icon
2° | 2°°C 0 mm 0% 3 mph 90 % 1025 mb 0 mm/h
Tomorrow 12:00 am
weather icon
2° | 2°°C 0 mm 0% 3 mph 89 % 1024 mb 0 mm/h
Tomorrow 3:00 am
weather icon
1° | 1°°C 0 mm 0% 3 mph 91 % 1022 mb 0 mm/h
Tomorrow 6:00 am
weather icon
1° | 1°°C 0 mm 0% 3 mph 93 % 1021 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,326.42
0.93%
Ethereum(ETH)
€3,193.60
-3.42%
XRP(XRP)
€3.04
-4.48%
Tether(USDT)
€0.97
-0.02%
Solana(SOL)
€231.29
10.47%
Dogecoin(DOGE)
€0.387292
-3.87%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000022
-6.11%
Pepe(PEPE)
€0.000019
-4.00%
Peanut the Squirrel(PNUT)
€0.52
-15.32%
Scroll to Top