Chinese cyber attack sparks alert over six year old MS vuln | Computer Weekly

other

Summary

It is a remote code execution (RCE) flaw in Microsoft COM for Windows resulting from a failure to properly handle serialised objects. However, on 1 August 2024 Cisco’s Talos threat research unit disclosed evidence of a malicious campaign by APT41 that leveraged CVE-2018-0824 in the attack chain. This campaign appears to have started in mid-2023 and was aimed at a government-affiliated research institute located in Taiwan, in which APT41 delivered the ShadowPad malware, Cobalt Strike and other custom tools for post-compromise activity. As part of the attack, researchers also discovered that APT41 created a tailored loader to inject a proof-of-concept (PoC) malware, dubbed UnmarshalPwn, that exploits CVE-2018-0824 directly into memory. “Although we don’t have further visibility into more details about these campaigns at the moment, we hope that by revealing this information, it would empower the community to connect the dots and leverage these insights for additional investigations.” CISA’s KEV catalogue is a resource primarily designed to enforce prompt and effective patching across agencies of the US federal government, which are legally bound to implement its guidance within a specific timeframe – in this instance by 26 August 2024, three weeks from now.

Classifications

industries
No industries detected
applications
No applications detected

AskAI Classifications

Labels
No AI classifications detected

Linked Companies