216.73.216.6

Exploitation of CLFS zero-day leads to ransomware activity

· Published 09/04/2025 17:43 · Modified 09/04/2025 20:40

Export JSON

Essential information

Published
09/04/2025 17:43
Modified
09/04/2025 20:40
Tags
2025-04-09 CVE-2025-24983 CVE-2025-29824 clfs pipemagic privilege-escalation ransomexx ransomware windows zero-day
Related entities
1 intrusion sets (apt), 9 techniques (mitre), 2 malware, 8 others

Description

A elevation of privilege vulnerability in Common Log File System () has been exploited against targets in IT, real estate, finance, software, and retail sectors across multiple countries. The exploit, deployed by malware and attributed to Storm-2460, enables privilege escalation and deployment. The vulnerability, , was patched on April 8, 2025. The attack involves downloading malicious MSBuild files, using , and exploiting to inject payloads into system processes. Post-exploitation activities include credential theft and deployment, with similarities to . Microsoft recommends immediate patching and provides mitigation strategies, detection methods, and hunting queries to counter this threat.

External references