Source |
The Hacker News |
Identifiant |
3846869 |
Date de publication |
2021-12-21 23:45:57 (vue: 2021-12-22 08:06:08) |
Titre |
New Exploit Lets Malware Attackers Bypass Patch for Critical Microsoft MSHTML Flaw |
Texte |
A short-lived phishing campaign has been observed taking advantage of a novel exploit that bypassed a patch put in place by Microsoft to fix a remote code execution vulnerability affecting the MSHTML component with the goal of delivering Formbook malware.
"The attachments represent an escalation of the attacker's abuse of the CVE-2021-40444 bug and demonstrate that even a patch can't always |
Notes |
|
Envoyé |
Oui |
Condensat |
2021 40444 abuse advantage affecting always attachments attacker attackers been bug bypass bypassed campaign can code component critical cve delivering demonstrate escalation even execution exploit fix flaw formbook goal has lets lived malware microsoft mshtml new novel observed patch phishing place put remote represent short taking vulnerability |
Tags |
Malware
Vulnerability
|
Stories |
|
Move |
|