Security News > 2023 > April > April Patch Tuesday: Ransomware gangs already exploiting this Windows bug
Microsoft patched 97 security flaws today for April's Patch Tuesday including one that has already been found and exploited by miscreants attempting to deploy Nokoyawa ransomware.
Microsoft, as usual, didn't disclose the extent of attacks against CVE-2023-28252, a privilege elevation bug in the Windows Common Log File System driver, infosec folk say they've spotted attempts to deploy the Nokoyawa ransomware via this security hole.
As Microsoft warned: "An attacker who successfully exploited this vulnerability could gain SYSTEM privileges." And according to Kaspersky, a cybercriminal crew is attempting to use this vulnerability to help itself spread ransomware among targets in the retail and wholesale, energy, manufacturing, healthcare, and software development industries, plus others.
The flaw is similar to another privilege elevation bug Microsoft patched in February.
A pair of critical layer two tunneling protocol RCEs, CVE-2023-28220 and CVE-2023-28219, that affect Windows Remote Access Servers are also marked as "Exploitation more likely."
One patch for Digital Edition plugs a critical code execution bug, and the bulletin for InCopy also fixes a single, critical code execution flaw.
News URL
https://go.theregister.com/feed/www.theregister.com/2023/04/11/april_patch_tuesday_ransomware/
Related news
- March 2024 Patch Tuesday: Microsoft fixes critical bugs in Windows Hyper-V (source)
- February 2024 Patch Tuesday forecast: Zero days are back and a new server too (source)
- Week in review: 10 must-read cybersecurity books, AnyDesk hack, Patch Tuesday forecast (source)
- Free Rhysida ransomware decryptor for Windows exploits RNG flaw (source)
- Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 74 flaws (source)
- Microsoft February 2024 Patch Tuesday fixes 2 zero-days, 73 flaws (source)
- March 2024 Patch Tuesday forecast: A popular framework updated (source)
- Week in review: Attackers use phishing emails to steal NTLM hashes, Patch Tuesday forecast (source)
- Microsoft March 2024 Patch Tuesday fixes 60 flaws, 18 RCE bugs (source)
- March Patch Tuesday sees Hyper-V join the guest-host escape club (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-11 | CVE-2023-28252 | Unspecified vulnerability in Microsoft products Windows Common Log File System Driver Elevation of Privilege Vulnerability | 7.8 |