Windows PCs under threat from zero-day flaw used in ransomware attacks — update your computer right now
- Microsoft addressed CVE-2025-29824, a zero-day vulnerability in Windows CLFS, during its April 2025 Patch Tuesday.
- Ransomware actors, specifically the Storm-2460 group , exploited the flaw to elevate privileges on compromised systems.
- This use-after-free vulnerability allowed low-privilege attackers to gain SYSTEM privileges without user interaction, enabling malware deployment.
- Microsoft urges applying security updates; however, Windows 10 x64/32-bit patches were delayed, and Windows 11 version 24H2 is unaffected.
- The vulnerability's exploitation led to the installation of PipeMagic backdoor and ransomware deployment, prompting CISA to add it to KEV.
26 Articles
26 Articles
Microsoft patches zero-day actively exploited in string of ransomware attacks
Microsoft addressed 126 vulnerabilities affecting its systems and core products, including a zero-day in the Windows Common Log File System (CLFS) that’s been actively exploited in a series of ransomware attacks, the company said in its latest security update Tuesday. A group Microsoft tracks as Storm-2460 has exploited CVE-2025-29824 to initiate ransomware attacks “against a small number of targets,” Microsoft Threat Intelligence said in a rese…
Ransomware-Attacken stoßen in Windows-Lücke
srcset="https://b2b-contenthub.com/wp-content/uploads/2025/04/shutterstock_2201386007.jpg?quality=50&strip=all 2800w, https://b2b-contenthub.com/wp-content/uploads/2025/04/shutterstock_2201386007.jpg?resize=300%2C168&quality=50&strip=all 300w, https://b2b-contenthub.com/wp-content/uploads/2025/04/shutterstock_2201386007.jpg?resize=768%2C432&quality=50&strip=all 768w, https://b2b-contenthub.com/wp-content/uploads/2025/04/shutterstock_2201386007.j…
Microsoft: Windows CLFS Vulnerability Could Lead to ‘Widespread Deployment and Detonation of Ransomware’
Microsoft warns CVE-2025-29824 lets attackers with user access escalate privileges to deploy ransomware via a flaw in Windows CLFS. This article has been indexed from Security | TechRepublic Read the original article: Microsoft: Windows CLFS Vulnerability Could Lead to ‘Widespread… Read more → The post Microsoft: Windows CLFS Vulnerability Could Lead to ‘Widespread Deployment and Detonation of Ransomware’ appeared first on IT Security News.
Coverage Details
Bias Distribution
- 100% of the sources are Center
To view factuality data please Upgrade to Premium
Ownership
To view ownership data please Upgrade to Vantage