Microsoft Patches Critical Windows Vulnerability Linked to Lazarus Group

20 Aug 2024

In its recent Patch Tuesday cumulative update, Microsoft addressed a significant privilege escalation vulnerability within the Windows Ancillary Function Driver (AFD.sys) for WinSock. This flaw, designated as CVE-2024-38193, has been assigned a severity score of 7.8, indicating its potential for serious exploitation. If successfully leveraged, this vulnerability could allow attackers to gain administrative privileges on affected systems. Microsoft has cautioned that “an attacker who successfully exploited this vulnerability could gain SYSTEM privileges.”

Lazarus Strikes Again

Security firms such as Norton, Avira, and Avast have linked this vulnerability to the notorious Lazarus Group, a state-sponsored hacking organization from North Korea. According to Gen Digital, the exploitation of this flaw enabled the group to infiltrate sensitive areas of systems, stating, “This flaw allowed them to gain unauthorized access to sensitive system areas.” The breach effectively bypassed standard security measures, granting access to regions typically restricted to users and administrators alike.

The implications of such an attack are profound, with estimates suggesting that the techniques employed could be valued at several hundred thousand dollars on the black market. This is particularly alarming as the group appears to be targeting individuals in high-stakes fields, including cryptocurrency engineering and aerospace. The goal is to infiltrate their employers’ networks and pilfer cryptocurrencies, which may be used to finance further malicious operations.

Lazarus Group has established a reputation for orchestrating some of the most impactful cyberattacks in recent memory. Among their tactics is the creation of deceptive job offers, often utilizing fake LinkedIn profiles or impersonating well-known figures to lure software developers with enticing job propositions. One notable incident involved a blockchain developer, leading to a staggering theft of approximately $100 million from a cryptocurrency initiative. Analysts suggest that the funds may be funneled into supporting North Korea’s state activities and military programs.

As businesses and individuals continue to navigate the complexities of cybersecurity, the recent developments underscore the importance of staying vigilant and proactive in safeguarding digital assets. The collaboration between tech giants and security firms remains crucial in mitigating risks and fortifying defenses against increasingly sophisticated threats.

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
7298218
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1679575
downloads
WinRAR

WinRAR

Streamline file management with fast compression, secure your documents, and save space.

5
735 reviews
719527
downloads
Minecraft

Minecraft

Shape environments, explore vast worlds, and survive against monsters with endless creativity.

5
750 reviews
489363
downloads

News and reviews for Desktop Windows

Ubisoft Labels Assassin's Creed Games 'Quadruple-A'

Ubisoft calls Assassin's Creed Mirage and Shadows 'quadruple-A'; raises debate on meaning and impact.

Read more

Amistech Releases My Winter Car in Early Access with Increased Challenge

My Winter Car, a successor to My Summer Car, launched by Amistech on 2023-12-29, promises heightened difficulty and unique survival mechanics.

Read more

Secure Microsoft Bundle for PCs at $39.97

Get the Microsoft bundle with Office 2021 and Windows 11 Pro for $39.97. Enhance old PCs with new tools and OS for 2026 productivity.

Read more

Blue Prince Available on Steam with 34% Discount

Blue Prince is now on sale on Steam during Detective Fest until 2024-01-19, offering players a 34% discount.

Read more

Critical Patch Addressed in Apex Central by Trend Micro

Trend Micro fixed a severe vulnerability in Apex Central, preventing remote code execution. Patch is critical for system security.

Read more

Reignbreaker Available for Under $1 in Limited Bundle Offer

Reignbreaker, a punk roguelike, offers dynamic combat similar to Hades. Available now under $1 via the Killer Bundle.

Read more

Ninite Simplifies Windows App Installations for Users

Ninite offers streamlined Windows app installations, reducing bloatware and easing bulk updates for users.

Read more

Microsoft Plans to Clarify Windows 11 Driver Names

Microsoft seeks to provide clearer driver names in Windows 11, enhancing user understanding of device functions.

Read more

Dreadmyst Launches on Steam with Free Dungeon-Crawler RPG

Dreadmyst, a solo-developed 2D RPG, is now on Steam. Offers classic MMO elements and free content. Early feedback is positive.

Read more

Steam's Top PC VR Games of 2025 Dominated by Classics

Steam unveils top PC VR games in 2025. Older titles dominate, with one 2025 debut making the list.

Read more