Skip to content

Conversation

@MHaggis
Copy link
Contributor

@MHaggis MHaggis commented Mar 24, 2025

Adds new detections and story for ZDI-CAN-25373 Windows shortcut zero-day vulnerability:

  • Windows SSH ProxyCommand abuse detection
  • Windows Explorer LNK exploit with padding detection
  • Windows Explorer spawning PowerShell/CMD detection
  • Analytic story covering APT campaigns exploiting this vulnerability

Thank you to AJ and Jesse Hunter (Community) for the assist!

Adds new detections and story for ZDI-CAN-25373 Windows shortcut zero-day vulnerability:
- Windows SSH ProxyCommand abuse detection
- Windows Explorer LNK exploit with padding detection
- Windows Explorer spawning PowerShell/CMD detection
- Analytic story covering APT campaigns exploiting this vulnerability

Thank you to AJ and Hunter (Community) for the assist!
@MHaggis MHaggis changed the title Clear and Present Haag-er Clear and Present Haag-er: ZDI-CAN-25373 Mar 24, 2025
Added Jesse Hunter
@patel-bhavin patel-bhavin added this to the v5.3.0 milestone Mar 25, 2025
@patel-bhavin
Copy link
Contributor

Updates look good! 🚢

@patel-bhavin patel-bhavin merged commit 041054c into develop Apr 1, 2025
4 checks passed
@patel-bhavin patel-bhavin deleted the ZDI-CAN-25373 branch April 1, 2025 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants