logo

Microsoft fixes Windows zero-day exploited in QakBot malware attacks

ID: 469507ea-76e1-553a-93dc-150c1473252d

STIX ID: report--469507ea-76e1-553a-93dc-150c1473252d

Feed Name: Bleeping Computer

Threat Score
85/100

Date Published: 2024-05-14

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Microsoft patched a zero-day privilege escalation vulnerability in the Windows Desktop Window Manager (CVE-2024-30051) — a heap-based buffer overflow allowing escalation to SYSTEM — which Kaspersky and other security teams observed being exploited in the wild to deliver QakBot and other malware; multiple vendors reported active exploitation and Microsoft released a Patch Tuesday update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.