New Attack Technique Exploits Microsoft Management Console Files
ID: 4fbd0deb-d1c2-5f7f-b892-ba72f279da1f
STIX ID: report--4fbd0deb-d1c2-5f7f-b892-ba72f279da1f
Feed Name: The Hacker News
Elastic Security Labs identified an active attack technique dubbed "GrimResource" that uses specially crafted Microsoft Management Console (MSC) files to exploit an unpatched XSS vulnerability in apds.dll, enabling JavaScript execution in MMC. Attackers can combine this with DotNetToJScript to achieve arbitrary code execution, delivering a .NET loader (PASTALOADER) and ultimately Cobalt Strike; Microsoft notes MSC files are treated as potentially dangerous and Defender/Smart App Control provide protections, and users are advised not to open files from untrusted sources.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
