logo

Attackers Exploit Microsoft Security-Bypass Zero-Day Bugs

ID: 9872e16a-600d-596f-8d12-82e4e40003e9

STIX ID: report--9872e16a-600d-596f-8d12-82e4e40003e9

Feed Name: Dark Reading

Threat Score
85/100

Date Published: 2024-02-13

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Microsoft's February Patch Tuesday addresses 73 CVEs including two zero-days being actively exploited: CVE-2024-21412 (Internet Shortcut Files bypass) which Water Hydra is using to target financial traders and drop the DarkMe RAT, and CVE-2024-21351 (Defender SmartScreen bypass) that can allow code injection; the bulletin also highlights other critical flaws in Exchange (CVE-2024-21410) and Outlook (CVE-2024-21413) and provides remediation guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.