On March 11 - Patch Tuesday - Microsoft rolled out its usual buffet of bug fixes. Just eight days later, miscreants had weaponized one of the vulnerabilities, using it against government and private sector targets in Poland and Romania. The Windows flaw in question was CVE-2025-24054, an NTLM hash-leaking vulnerability that Microsoft rated as "less likely" to be exploited. Attackers begged to differ and built malware that abused the bug, according to researchers at Check Point. Last Wednesday, Apple pushed out iOS 18.4.1 and iPadOS 18.4.1 to patch two zero-day vulnerabilities that it says were exploited in "extremely sophisticated" attacks against targeted individuals. The first fix addresses a memory corruption issue in CoreAudio, which processes audio streams. Apple and Google's Threat Analysis Group jointly reported the bug, which could lead to arbitrary code execution when handling a maliciously crafted media file. The second patch addresses a flaw in the Return Pointer Authentication Code (RPAC), part of Apple's mechanism for blocking pointer manipulation attacks. According to Cupertino, an attacker with arbitrary read and write access "may be able to bypass Pointer Authentication." Apple mitigated the issue by removing the vulnerable code. Specifically, the vulnerability can be exploited to leak a victim's Net-NTLMv2 or NTLMv2-SSP hash over the network. According to Check Point, miscreants can "attempt to brute-force the hash offline or perform relay attacks," and imper...
Microsoft rated this bug as low exploitability. Miscreants weaponized it in just 8 days
The Register
·Iain Thomson
·Published Apr 21, 2025
·Updated
Affected Software
6 affected components
Microsoft Windows
Apple iOS=18.4.1
Apple iPadOS=18.4.1
Microsoft Windows
Apple iOS=18.4.1
Apple iPadOS=18.4.1
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a recent vulnerability in Microsoft and Apple software that was rapidly weaponized by attackers shortly after its disclosure.
2
What security implications are discussed in the article?
The article highlights the low exploitability rating by Microsoft that changed as attackers quickly adapted to exploit the vulnerability.
3
What products or software are affected by the vulnerability?
The vulnerability affects Microsoft Windows and Apple iOS and iPadOS version 18.4.1.
4
How quickly was the vulnerability weaponized by attackers?
The vulnerability was weaponized by attackers just eight days after Microsoft released the patch.
5
What type of targets were affected by the exploitation of the vulnerability?
The attacked targets include both government and private sector entities.