Тёмный

Click with Caution: The Moniker Link Vulnerability (CVE-2024-21413) Exposed | Threat Snapshot 

SnapAttack
Подписаться 1,5 тыс.
Просмотров 1,9 тыс.
50% 1

Did you catch the Moniker Link vulnerability from Microsoft's recent "Patch Tuesday"? It's not often that a 9.8 CVSS remote code execution flaw is identified in one of Microsoft's products. But does it live up to the hype? Tracked as CVE-2024-21413, this security flaw could lead to NTLM credential theft and potentially allow remote code execution through manipulated hyperlinks in Microsoft Outlook. The flaw underscores the risks associated with the Component Object Model (COM) in Windows and prompts a broader conversation on the security of software that utilizes COM APIs insecurely. In the latest Threat SnapShot, we'll break down how the attack works and what artifacts it leaves behind, helping to create behavioral detections and hunting queries to protect your organization.
References:
- msrc.microsoft.com/update-gui...
- research.checkpoint.com/2024/...
- / 1758137072215523717
SnapAttack Resources:
- app.snapattack.com/threat/679... - Threat: CVE-2024-21413 Outlook MonikerLink Exploitation
- app.snapattack.com/detection/... - Detection: MonikerLink Exploitation
- app.snapattack.com/detection/... - Detection: Suspicious SMB Connection as System
- app.snapattack.com/detection/... - Detection: Suspicious Outlook Child Process
- app.snapattack.com/detection/... - Detection: Office Application Initiated Network Connection To Non-Local IP

Наука

Опубликовано:

 

15 фев 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 4   
@marcinbykos7066
@marcinbykos7066 4 месяца назад
great stuff, always a pleasure to watch :-)
@mukeshsingh7069
@mukeshsingh7069 5 месяцев назад
Great Walkthrough 👏👏👏
@mystery7957
@mystery7957 4 месяца назад
How to get Event ID 25 Outlook?
Далее
The Patch Report - CVE-2024-21412 Special Edition
6:03
A Vulnerability to Hack The World - CVE-2023-4863
18:00
How MonikerLink CVE-2024-21413 Works
0:22
Просмотров 256
Acer Predator Тараканьи Бега!
1:00
Просмотров 487 тыс.
APPLE дают это нам БЕСПЛАТНО!
1:01
Просмотров 616 тыс.
Собери ПК и Получи 10,000₽
1:00
Просмотров 2,7 млн