Hackers exploited the publicly available code of an unpatched Windows vulnerability to attack at least one organization. The code was recently announced released by a disgruntled security researcher known as Chaotic Eclipse after Microsoft failed to respond to his vulnerability report.

According to reports Bloomberg, specialists from Huntress have identified the exploitation of three Windows vulnerabilities named BlueHammer, UnDefend, and RedSun. These flaws affect the Windows Defender antivirus and allow attackers to gain administrative rights on the compromised computer. The code to exploit these vulnerabilities was published by Chaotic Eclipse on GitHub.
"I wasn't bluffing before Microsoft, and I'm doing it again," he wrote. "Huge thanks to the MSRC leadership for making this possible," added Chaotic Eclipse, referring to the Microsoft Cybersecurity Response Center, which investigates and handles reports of vulnerabilities.
So far, Microsoft has released a patch for only one of the three vulnerabilities — BlueHammer, the fix for which became available this week. The other two flaws, UnDefend and RedSun, remain unpatched, continuing to pose a threat to systems. The identities of the hackers and their targets have not yet been established.
John Hammond, a researcher at Huntress, noted that the availability of ready-made attack tools turns defense into an exhausting race against criminals. Microsoft representative Ben Hope responded by stating that the company supports coordinated disclosure of vulnerabilities and addressing issues before they are publicly disclosed.
Source:
Source: 3dnews.ru
