June 21, 2025
Gadget

Microsoft fixed an old security vulnerability in Windows that had been bothering users for a long time

  • March 11, 2024
  • 0

According to Avast, it was actively used by North Korean hackers affiliated with the Lazarus group. The vulnerability was linked to the appid.sys driver in the AppLocker utility.

Microsoft fixed an old security vulnerability in Windows that had been bothering users for a long time

According to Avast, it was actively used by North Korean hackers affiliated with the Lazarus group. The vulnerability was linked to the appid.sys driver in the AppLocker utility.

Why was it dangerous?

Exploiting this flaw allowed attackers with system access to escalate their privileges to the SYSTEM level without any interaction with the victim. The vulnerability affected devices running various versions of Windows, including Windows 11, Windows 10, Windows Server 2022 and Windows Server 2019.

Avast explained that exploiting CVE-2024-21338 requires attackers to log into the system and then launch a specially crafted application designed to exploit the vulnerability and take control of the device.

According to Avast’s findings, the Lazarus group has been exploiting this vulnerability since at least August last year. Exploiting this flaw allowed attackers to gain kernel-level privileges and disable defense mechanisms on compromised systems. They then introduced the FudModule rootkit into the affected systems undetected, which allowed them to perform various manipulations with core objects.

Source: 24 Tv

Leave a Reply

Your email address will not be published. Required fields are marked *