logo

QakBot attacks with Windows zero-day (CVE-2024-30051)

ID: 6ff31af2-9978-58ab-bec5-e34a9e89a43c

STIX ID: report--6ff31af2-9978-58ab-bec5-e34a9e89a43c

Feed Name: Securelist by Kaspersky

Threat Score
80/100

Date Published: 2024-05-14

Date Updated: 2026-04-29

Author: Boris Larin, Mert Degirmenci

...
...

Kaspersky discovered a previously undocumented Windows DWM elevation-of-privilege zero-day (CVE-2024-30051) after finding a suspicious VirusTotal document; they confirmed the bug, reported it to Microsoft, and a patch was released on May 14, 2024. Kaspersky observed the exploit in the wild in mid-April 2024 being used with QakBot and other malware, believes multiple threat actors had access, and provides detection names for the exploit and associated malware.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.