Exploitation of CLFS zero-day leads to ransomware activity
ID: 74e9dcc1-b5a3-5939-9a37-5da7dcb76594
STIX ID: report--74e9dcc1-b5a3-5939-9a37-5da7dcb76594
Feed Name: Microsoft Security
Threat Score
Microsoft discovered active exploitation of a zero-day Windows Common Log File System (CLFS) privilege-escalation vulnerability (CVE-2025-29824) that was used in limited targeted intrusions by the Storm-2460 actor. Attackers deployed the PipeMagic backdoor, launched an in-memory CLFS exploit to obtain SYSTEM privileges, dumped LSASS to harvest credentials, and then executed ransomware; Microsoft provides indicators, Sentinel hunting queries, and mitigation/patching guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
