EXECUTIVE SUMMARY
It is a critical security bypass vulnerability in Microsoft Windows SmartScreen. This flaw allows attackers to circumvent the SmartScreen security warning, potentially leading to the execution of malicious files on an affected system. The vulnerability can be exploited through a series of sophisticated techniques involving multiple malware frameworks, including ACR, Lumma, and Meduza Stealers, which enhance the attacker's ability to execute and conceal their malicious activities.[/subscribe_to_unlock_form]
EXECUTIVE SUMMARY
It is a critical security bypass vulnerability in Microsoft Windows SmartScreen. This flaw allows attackers to circumvent the SmartScreen security warning, potentially leading to the execution of malicious files on an affected system. The vulnerability can be exploited through a series of sophisticated techniques involving multiple malware frameworks, including ACR, Lumma, and Meduza Stealers, which enhance the attacker's ability to execute and conceal their malicious activities.[emaillocker id="1283"]
The exploitation of CVE-2024-21412 involves a multi-stage attack process. Initially, attackers craft a URL that directs the victim to a malicious link file (LNK). This LNK file then triggers the download of an executable containing a hidden HTA script. The script is designed to decode and execute PowerShell commands, which subsequently retrieve additional payloads. These payloads often include various types of stealers such as ACR, Lumma, and Meduza. Each of these stealers is used to gather sensitive information from the victim's system and exfiltrate it to a command and control server. The use of these advanced malware tools not only facilitates the initial infection but also helps in maintaining persistence and evading detection by employing various obfuscation techniques.
In conclusion, this CVE-2024-21412 poses a severe security risk due to its ability to bypass Windows SmartScreen's protective mechanisms. The advanced attack techniques, particularly the use of ACR, Lumma, and Meduza stealers, highlight the evolving strategies of threat actors. It is imperative for organizations and individuals to promptly apply security patches and adopt robust security practices to defend against potential exploitation of this vulnerability.
THREAT PROFILE:
| Tactic | Technique Id | Technique |
| Execution | T1203 | Exploitation for Client Execution |
| T1059 | Command and Scripting Interpreter | |
| T1053 | Scheduled Task/Job | |
| Privilege Escalation | T1068 | Exploitation for Privilege Escalation |
| Credential Access | T1003 | OS Credential Dumping |
| Command and Control | T1071 | Application Layer Protocol |
| Exfiltration | T1041 | Exfiltration Over C2 Channel |
| Impact | T1485 | Data Destruction |
RECOMMENDATION:
We strongly recommend applying an update for Internet Shortcut Files Security Feature Bypass Vulnerability
REFERENCES:
The following reports contain further technical details:
https://thehackernews.com/2024/07/microsoft-defender-flaw-exploited-to.html