Critical Windows Zero-Day Alert: No Patch Available Yet for Users

Teilen:

Protect your systems with automated patching and server hardening strategies to defend against vulnerabilities like the NTLM zero-day. Stay proactive and secure your business.

Protect your systems with automated patching and server hardening strategies to defend against vulnerabilities like the NTLM zero-day. Stay proactive and secure your business.

A newly discovered Windows zero-day vulnerability exposes users across multiple Windows versions to credential theft. Discovered by 0patch researchers, this critical security flaw allows attackers to steal NTLM credentials through a deceptive yet simple method.

What Makes This Vulnerability Dangerous?

Widespread Impact

The vulnerability affects a wide range of Windows systems, including:

  • Windows Server 2022
  • Windows 11 (up to v24H2)
  • Windows 10 (multiple versions)
  • Windows 7 and Server 2008 R2

Exploitation Mechanism

Technical details of the vulnerability are withheld to minimize exploitation risk until Microsoft issues a fix to minimize any further risk of exploitation.

The vulnerability enables attackers to steal a user’s NTLM credentials by luring them into opening a malicious file in Windows Explorer.

Attackers can trigger the vulnerability through minimal user interaction:

  • Opening a shared folder
  • Accessing a USB disk
  • Simply viewing a malicious file in Windows Explorer
  • Accessing the Downloads folder with a strategically placed file

The Broader Context of Unpatched Vulnerabilities

This isn’t an isolated incident. The same research team has previously identified multiple unresolved Windows vulnerabilities, including:

  • Windows Theme file issue
  • “Mark of the Web” vulnerability
  • “EventLogCrasher” vulnerability
  • Three NTLM-related vulnerabilities (PetitPotam, PrinterBug/SpoolSample, and DFSCoerce)

0patch Micropatches

0patch is offering a free micropatch for the latest NTLM zero-day to all users registered on its platform until Microsoft releases an official fix. The security micropatch has already been automatically deployed to PRO and Enterprise accounts, except in cases where configurations explicitly block automatic updates.

“The impact on enterprises using outdated and legacy infrastructure is more significant than the simple impact on operating costs, said Jim Routh,” Chief Trust Officer at cybersecurity company Saviynt. “In this case, the obsolete authentication application (NTLM) from MS enables threat actors to steal Windows credentials potentially compromising customer experience.”

Focusing on the proactive approach

Automated patch management, like the protection provided to PRO and Enterprise accounts through 0patch, is a great start, but organizations need to do more. Implementing strong server-hardening strategies can add multiple layers of defence by setting consistent security configurations across all systems.

This proactive approach goes beyond simply reacting to vulnerabilities, helping businesses stay protected against threats like the recent NTLM zero-day vulnerability.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:46 am, Jan. 18, 2025
Wetter-Symbol 2°C
L: 1° | H: 3°
overcast clouds
Luftfeuchtigkeit: 89 %
Druck: 1031 mb
Wind: 5 mph E
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 7 km
Sonnenaufgang: 7:56 am
Sonnenuntergang: 4:24 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 9:00 pm
Wetter-Symbol
1° | 3°°C 0 mm 0% 4 mph 90 % 1031 mb 0 mm/h
Tomorrow 9:00 pm
Wetter-Symbol
1° | 5°°C 0 mm 0% 7 mph 93 % 1024 mb 0 mm/h
Mo. Jan. 20 9:00 pm
Wetter-Symbol
3° | 8°°C 0.26 mm 26% 6 mph 97 % 1019 mb 0 mm/h
Di. Jan. 21 9:00 pm
Wetter-Symbol
4° | 8°°C 0 mm 0% 8 mph 95 % 1019 mb 0 mm/h
Mi. Jan. 22 9:00 pm
Wetter-Symbol
4° | 7°°C 1 mm 100% 4 mph 99 % 1012 mb 0 mm/h
Today 9:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 2 mph 89 % 1031 mb 0 mm/h
Today 12:00 pm
Wetter-Symbol
3° | 5°°C 0 mm 0% 3 mph 83 % 1031 mb 0 mm/h
Today 3:00 pm
Wetter-Symbol
4° | 6°°C 0 mm 0% 3 mph 75 % 1028 mb 0 mm/h
Today 6:00 pm
Wetter-Symbol
3° | 3°°C 0 mm 0% 4 mph 88 % 1026 mb 0 mm/h
Today 9:00 pm
Wetter-Symbol
2° | 2°°C 0 mm 0% 3 mph 90 % 1025 mb 0 mm/h
Tomorrow 12:00 am
Wetter-Symbol
2° | 2°°C 0 mm 0% 3 mph 89 % 1024 mb 0 mm/h
Tomorrow 3:00 am
Wetter-Symbol
1° | 1°°C 0 mm 0% 3 mph 91 % 1022 mb 0 mm/h
Tomorrow 6:00 am
Wetter-Symbol
1° | 1°°C 0 mm 0% 3 mph 93 % 1021 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€100,326.42
0.93%
Ethereum(ETH)
€3,193.60
-3.42%
XRP(XRP)
€3.04
-4.48%
Fesseln(USDT)
€0.97
-0.02%
Solana(SOL)
€231.29
10.47%
Dogecoin(DOGE)
€0.387292
-3.87%
USDC(USDC)
€0.97
0.00%
Shiba Inu(SHIB)
€0.000022
-6.11%
Pepe(PEPE)
€0.000019
-4.00%
Peanut das Eichhörnchen(PNUT)
€0.52
-15.32%
Nach oben scrollen