Microsoft Fixes Two Zero-Day Vulnerabilities Exploited to Distribute Malware
Microsoft fixed 150 security vulnerabilities in its April Tuesday Patch, two of which were zero-day flaws used to distribute malware. The April Tuesday Patch was the largest update set released by Microsoft since at least 2017. Among the approximately 150 patched security vulnerabilities, the company addressed two zero-day vulnerabilities reported to be used by threat actors to distribute malware.

CVE-2024-26234 has been defined as a significant proxy driver impersonation vulnerability. Sophos, which reported the issue to Microsoft in December 2023, became aware of cyber attacks after receiving a report about alleged false positives in an executable file signed with a valid Windows Hardware Compatibility Program (WHCP) certificate.
Upon further analysis, it was found that the malicious backdoor file is associated with an Android screen mirroring application called LaiXi. This application can be used as a marketing software to "connect hundreds of smartphones together and automatically perform tasks such as following, liking, and commenting to increase the target audience."
According to Sophos' investigation, the malicious file integrates a small free proxy server that researchers believe is used to monitor and block network traffic on infected systems.
The certificate used to sign the file analyzed by Sophos was requested by Hainan YouHu Technology Co., a company identified as the developer of LaiXi.
Sophos states, "There is no evidence that the developers of LaiXi intentionally placed the malicious file in their products or that a threat actor conducted a supply chain attack to add the malicious backdoor to the creation/creation process of the LaiXi application. However, considering the connections between LaiXi and the malicious backdoor we investigated [...] users should be extremely cautious about downloading, installing, and using LaiXi."
Microsoft has patched CVE-2024-26234 with the latest Tuesday Patch updates and also added the files to the driver block list.
The second vulnerability is tracked under the identifier CVE-2024-29988 and does not reference a malicious exploit in Microsoft's advisory document. Trend Micro's Zero Day Initiative shows that this flaw indicates an abrupt deviation from the SmartScreen security feature, which is currently under active exploitation.
Exploiting this vulnerability may allow you to bypass the Mark of the Web (MotW) security feature. According to Peter Girnus from ZDI, who was credited by Microsoft for reporting the vulnerability, the flaw was discovered during the investigation of a campaign initiated by the threat group Water Hydra (DarkCasino).
Water Hydra attacks relied on exploiting a similar vulnerability, CVE-2024-21412. CVE-2024-21412 was used to bypass Microsoft Defender SmartScreen and deliver the malicious software named DarkMe to financial market traders.
Source: Microsoft Patches Two Zero-Day Vulnerabilities Exploited to Deliver Malware (itsecurity.pt)