United States, October 31, 2024- Windows themes Zero-Day bug uncovers major security risk, exposing users to NTLM credential theft.
A newly discovered zero-day in Windows Themes allows attackers to steal NTLM (New Technology LAN Manager) credentials. Mitja Kolsek, CEO of Acros Security said,
This exploit highlights the urgent need for users to safeguard their systems.
Millions of Windows users are now at risk of credential theft. The vulnerability, CVE-2024-38030, tricks Windows into sending NTLM credentials to remote hosts. Attackers can exploit this by prompting users to save or copy a malicious theme file. This action alone can unknowingly trigger the theft of credentials.
Microsoft attempted to patch this issue earlier, but Akamai researcher Tomer Peled found a workaround. His discovery led to the issue’s reemergence, demanding further action. Affected users remain vulnerable until an official fix is released.
Fortunately, Acros Security has developed a free 0patch micropatch to secure systems until Microsoft provides a fix. A Microsoft spokesperson said,
We’re aware of this report and will take action as needed.
No official timeline for the patch has been confirmed. Kolsek explained that while analyzing the bug, researchers found the issue still present in fully updated Windows versions, including the latest Windows 11 24H2 update. The discovery makes it urgent to get a patch from Microsoft.
The 0patch micro patch covers legacy and current Windows Workstation versions, providing a timely solution. Users are advised to install the micro patch immediately. This action will help mitigate the risk until Microsoft issues a permanent update.
Other News At VPNRanks
- Texas Life Data Breach Exposes 800K Nationwide Customers
- Osseo Schools Heighten Cybersecurity Amid Rising Threats
- Colorado Election Security Breach Raises Voter Integrity Alarm
- Strava Fitness App Exposes Secret Locations of Biden, Trump, and World Leaders
Hey, wait!
Stay informed on the latest privacy updates, cybersecurity insights, and internet freedom news by following VPNRanks news daily! As your primary resource for critical updates in online security, we ensure you’re always in the know. Make VPNRanks your go-to guide for safeguarding your digital life!