Navigation
Recherche
|
Microsoft Isn't Fixing 8-Year-Old Shortcut Exploit Abused For Spying
mercredi 19 mars 2025, 02:25 , par Slashdot
![]() Trend reported this to Microsoft in September last year and estimates that it has been used since 2017. It said it had found nearly 1,000 tampered.LNK files in circulation but estimates the actual number of attacks could have been higher. 'This is one of many bugs that the attackers are using, but this is one that is not patched and that's why we reported it as a zero day,' Dustin Childs, head of threat awareness at the Zero Day Initiative, told The Register. 'We told Microsoft but they consider it a UI issue, not a security issue. So it doesn't meet their bar for servicing as a security update, but it might be fixed in a later OS version, or something along those lines.' After poring over malicious.LNK samples, the security shop said it found the vast majority of these files were from state-sponsored attackers (around 70 percent), used for espionage or information theft, with another 20 percent going after financial gain. Among the state-sponsored crews, 46 percent of attacks came from North Korea, while Russia, Iran, and China each accounted for around 18 percent of the activity. Read more of this story at Slashdot.
https://it.slashdot.org/story/25/03/18/2226205/microsoft-isnt-fixing-8-year-old-shortcut-exploit-abu...
Voir aussi |
56 sources (32 en français)
Date Actuelle
mer. 19 mars - 08:14 CET
|