Hackers utilizing zero-day joint logfile system vulnerability over to plant ransomware


  • Microsoft said it observed a threat actor known as storm-2460 abuse a use after free error in Windows Common Log File System Driver
  • The error is used to implement Pipemagic, which is then used to deliver ransomware
  • Users are advised to install the released patch right away

Cyber ​​criminals abuse a post-compromer zero-day vulnerability in Windows Common Log File System (CLFS) to implement ransomware.

Earlier this week, the Microsoft Threat Intelligence Center (MSTIC) and Microsoft Security Response Center (MSRC) published a new in-depth report describing how an error is traced as CVE-20125-29824 is used in cyberattacks.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top