logo

CISA warns of Windows bug exploited in ransomware attacks

ID: 6e7e1cba-40b6-577d-b8d3-48c6194d7668

STIX ID: report--6e7e1cba-40b6-577d-b8d3-48c6194d7668

Feed Name: Bleeping Computer

Threat Score
88/100

Date Published: 2024-06-14

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

CISA added a high-severity Windows zero-day (CVE-2024-26169) — an improper privilege management flaw in Windows Error Reporting allowing local escalation to SYSTEM — to its Known Exploited Vulnerabilities catalog after Symantec linked Black Basta operators to in-the-wild exploitation; Microsoft patched the bug on March 12, 2024, and CISA ordered federal agencies to remediate within three weeks while urging all organizations to prioritize fixes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.