Aktiv ausgenutzter Windows MoTW Zero-Day erhält inoffiziellen Patch

Teilen:

A free unofficial patch has been released for an actively exploited zero-day that allows files signed with malformed signatures to bypass Mark-of-the-Web security warnings in Windows 10 and Windows 11.

Last weekend, BleepingComputer reported that threat actors were using stand-alone JavaScript files to install the Magniber ransomware on victims’ devices.

When a user downloads a file from the Internet, Microsoft adds a Mark-of-the-Web flag to the file, causing the operating system to display security warnings when the file is launched, as shown below.

windows warning1

Windows Mark-of-the-Web security warning
Quelle: BleepingComputer

What made these Magniber JavaScript files stand out was that even though they contained a Mark-of-a-Web, Windows did not display any security warnings when they were launched.

After being analyzed by Will Dormann, a senior vulnerability analyst at ANALYGENCE, he discovered that the JavaScript files were digitally signed using a malformed signature.

When a malicious file with one of these malformed signatures is opened, instead of being flagged by Microsoft SmartScreen and showing a security warning, Windows would automatically allow the program to run.

The image below demonstrates how the vulnerability allows a file (‘calc-othersig.js’) with a malformed signature to bypass the Mark-of-the-Web security warning.

windows warning2

Demonstration of the Windows zero-day bypassing security warnings
Quelle: BleepingComputer

Microsoft told BleepingComputer that they were aware of the issue and investigating it.

Free unofficial patch released

As this zero-day vulnerability is actively exploited in ransomware attacks, the 0patch micro-patching service decided to release an unofficial fix that can be used until Microsoft releases an official security update.

In einem 0patch blog post, co-founder Mitja Kolsek explains that this bug is caused by Windows SmartScreen’s inability to parse the malformed signature in a file.

When SmartScreen can’t parse the signature, Windows will incorrectly allow the program to run rather than displaying an error.

“The malformed signature discovered by Patrick and Will caused SmartScreen.exe to throw an exception when the signature could not be parsed, resulting in SmartScreen returning an error,” explains Kolsek.

“Which we now know means “Run”.”

Kolsek warned that though their patch fixes the majority of attack scenarios, there could also be situations that bypass his patch.

“While our patch fixes the most obvious flaw, its utility depends on the application opening the file using function DoSafeOpenPromptForShellExe in shdocvw.dll and not some other mechanism,” warns Kolsek.

“We’re not aware of another such mechanism in Windows, but it could technically exist.”

Until Microsoft releases official updates to address the flaw, 0patch has developed free patches for the following affected Windows versions:

  1. Windows 11 v21H2
  2. Windows 10 v21H2
  3. Windows 10 v21H1
  4. Windows 10 v20H2
  5. Windows 10 v2004
  6. Windows 10 v1909
  7. Windows 10 v1903
  8. Windows 10 v1809
  9. Windows 10 v1803
  10. Windows Server 2022
  11. Windows Server 2019

To install the micropatch on your Windows device, you will need to register a free 0patch account and install its agent.

Once the agent is installed, the patches will be applied automatically without requiring a system restart if there are no custom patching policies to block it.

You can see 0patch’s Windows micropatches in action in the video below.

Related Articles:

https://www.bleepingcomputer.com/news/microsoft/actively-exploited-windows-motw-zero-day-gets-unofficial-patch/

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
11:40 pm, Juli 7, 2025
Wetter-Symbol 16°C
L: 14° | H: 17°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 65 %
Druck: 1014 mb
Wind: 10 mph WNW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 45%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:52 am
Sonnenuntergang: 9:18 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Tomorrow 10:00 pm
Wetter-Symbol
14° | 17°°C 0.34 mm 34% 11 mph 70 % 1019 mb 0 mm/h
Mi. Juli 09 10:00 pm
Wetter-Symbol
15° | 26°°C 0.2 mm 20% 7 mph 65 % 1022 mb 0 mm/h
Do. Juli 10 10:00 pm
Wetter-Symbol
19° | 31°°C 0 mm 0% 6 mph 74 % 1023 mb 0 mm/h
Fr. Juli 11 10:00 pm
Wetter-Symbol
20° | 31°°C 0 mm 0% 10 mph 66 % 1022 mb 0 mm/h
Sa. Juli 12 10:00 pm
Wetter-Symbol
19° | 29°°C 0 mm 0% 10 mph 70 % 1020 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
14° | 16°°C 0.2 mm 20% 11 mph 65 % 1014 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
12° | 14°°C 0.34 mm 34% 11 mph 70 % 1014 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
13° | 14°°C 0 mm 0% 10 mph 68 % 1015 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 9 mph 47 % 1017 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
23° | 23°°C 0 mm 0% 8 mph 33 % 1018 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 7 mph 29 % 1017 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 7 mph 29 % 1017 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
20° | 20°°C 0 mm 0% 5 mph 41 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,139.23
-1.15%
Ethereum(ETH)
€2,160.94
-2.11%
Fesseln(USDT)
€0.85
0.00%
XRP(XRP)
€1.94
-0.20%
Solana(SOL)
€126.26
-3.15%
USDC(USDC)
€0.85
0.00%
Dogecoin(DOGE)
€0.142179
-3.44%
Shiba Inu(SHIB)
€0.000010
-2.71%
Pepe(PEPE)
€0.000009
-4.14%
Nach oben scrollen