logo

New Attack Technique Exploits Microsoft Management Console Files

ID: 4fbd0deb-d1c2-5f7f-b892-ba72f279da1f

STIX ID: report--4fbd0deb-d1c2-5f7f-b892-ba72f279da1f

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2024-06-25

Date Updated: 2026-05-08

Author: [email protected] (The Hacker News)

...
...

Elastic Security Labs identified an active attack technique dubbed "GrimResource" that uses specially crafted Microsoft Management Console (MSC) files to exploit an unpatched XSS vulnerability in apds.dll, enabling JavaScript execution in MMC. Attackers can combine this with DotNetToJScript to achieve arbitrary code execution, delivering a .NET loader (PASTALOADER) and ultimately Cobalt Strike; Microsoft notes MSC files are treated as potentially dangerous and Defender/Smart App Control provide protections, and users are advised not to open files from untrusted sources.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.