• News/
  • bleepingcomputer-20250611154727

Hackers exploited Windows WebDav zero-day to drop malware

BleepingComputer
·
Published Jun 11, 2025
·
Updated

An APT hacking group known as 'Stealth Falcon' exploited a Windows WebDav RCE vulnerability in zero-day attacks since March 2025 against defense and government organizations in Turkey, Qatar, Egypt, and Yemen. Stealth Falcon (aka 'FruityArmor') is an advanced persistent threat (APT) group known for conducting cyberespionage attacks against Middle East organizations. The flaw, tracked under CVE-2025-33053, is a remote code execution (RCE) vulnerability that arises from the improper handling of the working directory by certain legitimate system executables. Specifically, when a .url file sets its WorkingDirectory to a remote WebDAV path, a built-in Windows tool can be tricked into executing a malicious executable from that remote location instead of the legitimate one. This allows attackers to force devices to execute arbitrary code remotely from WebDAV servers under their control without dropping malicious files locally, making their operations stealthy and evasive. The vulnerability was discovered by Check Point Research, with Microsoft fixing the flaw in the latest Patch Tuesday update, released yesterday. According to Check Point, the attempted attacks attacks may not have been successful, though the vulnerability is valid and confirmed to be exploited nonetheless. "In March 2025, Check Point Research identified an attempted cyberattack against a defense company in Turkey," mentions the Check Point report. "The threat actors used a previously undisclosed technique to execu...

Read full article

Affected Software

1 affected component
Microsoft Windows=CVE-2025-33053
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses how the hacking group Stealth Falcon exploited a Windows WebDav zero-day vulnerability to deploy malware.

2

What security implications are discussed in the article?

The article highlights the risk posed by the Windows WebDav vulnerability, particularly its exploitation in zero-day attacks against sensitive government and defense sectors.

3

What organizations were targeted by the hackers?

The hackers targeted defense and government organizations in Turkey, Qatar, Egypt, and Yemen.

4

What is the significance of the zero-day vulnerability mentioned?

The zero-day vulnerability is significant as it allows attackers to execute remote code and potentially gain unauthorized access to systems.

5

Which Microsoft products are affected by this vulnerability?

The affected Microsoft product mentioned in the article is the Windows operating system, specifically involving the iediagcmd.exe component.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203