Home Security Zero-click exploit abusing Firefox and Windows zero days

Zero-click exploit abusing Firefox and Windows zero days

by
0 comment
Zero-click exploit abusing Firefox and Windows zero days

Video

The backdoor can execute instructions and lets attackers obtain extra modules onto the sufferer’s machine, ESET analysis finds

ESET researchers have uncovered two beforehand unknown vulnerabilities in a number of Mozilla merchandise and in Home windows, with each flaws below energetic exploitation by RomCom, a Russia-aligned group identified for opportunistic campaigns towards chosen enterprise verticals and focused espionage operations alike.

  • CVE-2024-9680 is a use-after-free bug that enables susceptible variations of Firefox, Thunderbird, and the Tor Browser to execute code within the restricted context of the browser. Mozilla patched the vulnerability on October 9th, 2024.
  • CVE‑2024‑49039 is a privilege escalation bug in Home windows that enables code to run exterior of Firefox’s sandbox. Microsoft launched a patch for this second vulnerability on November 12th, 2024.

Chaining the 2 flaws permits dangerous actors to run arbitrary code within the context of the logged-in person – and with none person interplay – in a so-called zero-click exploit. In campaigns noticed by ESET, this led to the set up of RomCom’s eponymous backdoor on the sufferer’s laptop. The backdoor can execute instructions and obtain extra modules to the sufferer’s machine.

What precisely does the compromise chain contain and what else is there to know in regards to the vulnerabilities and the exploits abusing them? Discover out within the video by ESET Chief Safety Evangelist Tony Anscombe and be sure you additionally learn the complete blogpost.

See also  How Arid Viper spies on Android users in the Middle East – Week in security with Tony Anscombe

Source link

You may also like

Leave a Comment

cbn (2)

Discover the latest in tech and cyber news. Stay informed on cybersecurity threats, innovations, and industry trends with our comprehensive coverage. Dive into the ever-evolving world of technology with us.

© 2024 cyberbeatnews.com – All Rights Reserved.