Security News > 2024 > May > Microsoft fixes Windows zero-day exploited in QakBot malware attacks

Microsoft fixes Windows zero-day exploited in QakBot malware attacks
2024-05-14 18:18

Microsoft has fixed a zero-day vulnerability exploited in attacks to deliver QakBot and other malware payloads on vulnerable Windows systems.

Kaspersky security researchers discovered the vulnerability while investigating another Windows DWM Core Library privilege escalation bug tracked as CVE-2023-36033 and also exploited as a zero-day in attacks.

Microsoft fixes two Windows zero-days exploited in malware attacks.

Apple backports fix for zero-day exploited in attacks to older iPhones.

Google Chrome emergency update fixes 6th zero-day exploited in 2024.

Google fixes fifth Chrome zero-day exploited in attacks this year.


News URL

https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-zero-day-exploited-in-qakbot-malware-attacks/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2023-11-14 CVE-2023-36033 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Microsoft products
Windows DWM Core Library Elevation of Privilege Vulnerability
local
low complexity
microsoft CWE-119
7.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 365 50 1369 2821 160 4400