Security News > 2024 > November > RomCom hackers chained Firefox and Windows zero-days to deliver backdoor

RomCom hackers chained Firefox and Windows zero-days to deliver backdoor
2024-11-26 10:00

Russia-aligned APT group RomCom was behind attacks that leveraged CVE-2024-9680, a remote code execution flaw in Firefox, and CVE-2024-49039, an elevation of privilege vulnerability in Windows Task Scheduler, as zero-days earlier this year. “Chaining together two zero-day vulnerabilities armed RomCom with an exploit that requires no user interaction,” ESET researchers said. The campaign leveraging the zero-click exploit CVE-2024-9680 allowed the attackers to execute code in the restricted context of the browser and CVE-2024-49039 allowed it … More → The post RomCom hackers chained Firefox and Windows zero-days to deliver backdoor appeared first on Help Net Security.


News URL

https://www.helpnetsecurity.com/2024/11/26/romcom-backdoor-cve-2024-9680-cve-2024-49039/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2024-11-12 CVE-2024-49039 Unspecified vulnerability in Microsoft products
Windows Task Scheduler Elevation of Privilege Vulnerability
local
low complexity
microsoft
8.8
2024-10-09 CVE-2024-9680 Use After Free vulnerability in Mozilla Thunderbird
An attacker was able to achieve code execution in the content process by exploiting a use-after-free in Animation timelines.
network
low complexity
mozilla CWE-416
critical
9.8