logo

Zero-day-cve-2024-4351-report.pdf

ID: 6326ebca-dfed-4a5b-b81a-bcf517fdae8f

STIX ID: report--6326ebca-dfed-4a5b-b81a-bcf517fdae8f

Threat Score

86/100

Uploaded: 2026-08-11

Published Date: 2024-11-13

Last Modified Date: 2024-11-13

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ClearSky describes a Windows zero-day (CVE-2024-43451) where specially crafted .url files trigger SMB connections on innocuous actions (right-click, delete, drag), allowing NTLM hash exfiltration and the download/execution of malware (SparkRAT and Redline); the campaign abused downloads from a Ukrainian government site, is attributed to UAC-0194 (suspected Russian), includes detailed IOCs (file hashes, IPs), and Microsoft released a patch on 2024-11-12.