Forget Patch Tuesday: it’s Take Action Thursday as Microsoft confirms Windows zero-day double-header

Microsoft has confirmed two zero-day vulnerabilities impacting Windows users. The zero-days were both fixed in the monthly round-up of security updates, 73 in all, known as Patch Tuesday. For good reason, yesterday is also known as Exploit Wednesday because threat actors look to take the opportunity between disclosure of a vulnerability and application of the fix to attack as many targets as possible.

Today should rightly be called Take Action Thursday, especially as far as the zero-day fixes are concerned. Hereโ€™s what security experts told TechFinitive about the actively exploited zero-day vulnerabilities.


Related reading: what are zero-day exploits?


CVE-2024-21351 Windows zero-day vulnerability

The first of the two zero-days is CVE-2024-21351, a security feature bypass for the Windows SmartScreen function that can warn users of a potentially malicious file or block the execution of the same.

โ€œAs is common for Microsoft patch notes, very little details are available to network defenders,โ€ says Kev Breen, Senior Director Threat Research at Immersive Labs. However, Breen says that itโ€™s important to note that โ€œthis vulnerability alone is not enough for an attacker to compromise a userโ€™s workstation and would be used in conjunction with something like a spear phishing attack that delivers a malicious file.โ€

Meanwhile, Adam Barnett, Lead Software Engineer at Rapid7, picked up on the language used in describing the vulnerability, telling us that โ€œother critical SmartScreen bypass vulnerabilities from the past couple of years have not included language describing code injection into SmartScreen itself, focusing instead on the security feature bypass only.โ€

This is important as it suggests that exploitation could allow โ€œcode injection into SmartScreen to achieve remote code execution.โ€

CVE-2024-21412 Windows zero-day vulnerability

The second Windows zero-day vulnerability is also of the feature bypass variety, concerning internet shortcut files security.

Kevin Simzer, COO at Trend Micro, the organisation which disclosed this one, says that CVE-2024-21412 โ€œis being actively exploited by a financially motivated APT group to compromise foreign exchange traders participating in the high-stakes currency trading market.โ€

More specifically, itโ€™s part of a sophisticated zero-day attack chain โ€œdesigned to infect victims with the DarkMe remote access trojan (RAT) for potential data theft and ransomware,โ€ Simzer says.

Rapid7โ€™s Barnett points out that โ€œif further evidence were ever needed that clicking Internet Shortcut files from unknown sources is typically a bad idea, CVE-2024-21412 provides it.โ€

Finally, Saeed Abbasi, Product Manager, Vulnerability Research, Qualys Threat Research Unit, says that the vulnerability is exploited โ€œvia a specially crafted file delivered through phishing tactics, which cleverly manipulates internet shortcuts and WebDAV components to bypass the displayed security checks.โ€

Although exploitation requires user interaction, the impact, Abbasi concludes, โ€œis profound, compromising security and undermining trust in protective mechanisms like SmartScreenโ€.

More cybersecurity news

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.