Microsoft Confirms Active Exploitation of Windows Shell CVE-2026-32202
好的,我现在需要帮用户总结这篇文章的内容,控制在100字以内,而且不需要用“文章内容总结”这样的开头。首先,我得仔细阅读文章,抓住关键点。 文章主要讲的是微软修复了一个高危的安全漏洞CVE-2026-32202,这个漏洞已经被利用了。微软在Patch Tuesday更新中修复了它,属于 spoofing 漏洞,可能导致敏感信息泄露。攻击者需要发送恶意文件给受害者,受害者执行后才会被利用。微软还修正了之前的错误评分和信息。 另外,安全研究员Maor Dahan指出这个漏洞是由于之前修复的CVE-2026-21510的补丁不完整导致的。而CVE-2026-21510和CVE-2026-21513被俄罗斯的APT28组织利用,进行了针对乌克兰和欧盟国家的攻击活动。 攻击方式是通过恶意LNK文件,绕过微软的防护机制,自动连接到攻击者的服务器,导致敏感信息泄露。虽然微软修复了远程代码执行的问题,但认证绕过的问题仍然存在。 总结一下:微软修复了一个被利用的高危漏洞CVE-2026-32202,该漏洞源于之前补丁不完整。APT28利用此漏洞进行攻击,导致敏感信息泄露。 </think> 微软修复了高危漏洞CVE-2026-32202(CVSS评分4.3),该漏洞已被用于真实攻击。此spoofing漏洞允许攻击者通过恶意文件获取敏感信息。该漏洞源于之前补丁不完整。安全研究员指出该漏洞被俄罗斯APT28组织用于针对乌克兰和欧盟国家的攻击活动。 2026-4-28 05:50:0 Author: thehackernews.com(查看原文) 阅读量:13 收藏

Vulnerability / Threat Intelligence

Microsoft on Monday revised its advisory for a now-patched, high-severity security flaw impacting Windows Shell to acknowledge that it has been actively exploited in the wild.

The vulnerability in question is CVE-2026-32202 (CVSS score: 4.3), a spoofing vulnerability that could allow an attacker to access sensitive information. It was addressed as part of its Patch Tuesday update for this month.

"Protection mechanism failure in Windows Shell allows an unauthorized attacker to perform spoofing over a network," Microsoft noted in an alert. "An attacker would have to send the victim a malicious file that the victim would have to execute."

"An attacker who successfully exploited the vulnerability could view some sensitive information (Confidentiality) but not all resources within the impacted component may be divulged to the attacker. The attacker cannot make changes to disclosed information (Integrity) or limit access to the resource (Availability)."

On April 27, 2026, Microsoft said it rectified the "Exploitability Index, Exploited flag, and CVSS vector" as they were incorrect when they were published on April 14.

While the tech giant did not share any details about the exploitation activity, Akamai security researcher Maor Dahan, who is credited with discovering and reporting the bug, said the zero-click vulnerability stems from an incomplete patch for CVE-2026-21510.

The latter has been weaponized by a Russian nation-state group tracked as APT28 (aka Fancy Bear, Forest Blizzard, GruesomeLarch, and Pawn Storm) along with CVE-2026-21513 as part of an exploit chain -

  • CVE-2026-21510 (CVSS score: 8.8) - A protection mechanism failure in Windows Shell that allows an unauthorized attacker to bypass a security feature over a network. (Fixed by Microsoft in February 2026)
  • CVE-2026-21513 (CVSS score: 8.8) - A protection mechanism failure in MSHTML Framework that allows an unauthorized attacker to bypass a security feature over a network. (Fixed by Microsoft in February 2026)

It's worth noting that the abuse of CVE-2026-21513 was also flagged by the web infrastructure and security company early last month, linking it to APT28 after unearthing a malicious artifact in January 2026.

CVE-2026-21510 Exploitation

The campaign, targeting Ukraine and E.U. nations in December 2025, leverages a malicious Windows Shortcut (LNK) file to exploit the two vulnerabilities, effectively bypassing Microsoft Defender SmartScreen and enabling attacker-controlled code to be executed.

"APT28 leverages the Windows Shell namespace parsing mechanism to load a dynamic-link library (DLL) from a remote server using a UNC path," Dahan explained. "The DLL is loaded as part of the Control Panel (CPL) objects without proper network zone validation.

Akamai said the February 2026 patch, while mitigating the remote code execution risk by triggering a SmartScreen check of the CPL file's digital signature and origin zone, still allowed the victim machine to authenticate to the attacker's server and automatically fetch the CPL file by resolving the Universal Naming Convention (UNC) path and initiating an SMB connection without requiring user interaction.

"When that path is a UNC path (like '\\attacker.com\share\payload.cpl'), Windows initiates an SMB connection to the attacker's server," Dahan said. "This server message block (SMB) connection triggers an automatic NTLM authentication handshake, sending the victim's Net-NTLMv2 hash to the attacker, which can later be used for NTLM relay attacks and offline cracking."

"While Microsoft fixed the initial RCE (CVE-2026-21510), an authentication coercion flaw (CVE-2026-32202) remained. This gap between path resolution and trust verification left a zero-click credential theft vector via auto-parsed LNK files."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html
如有侵权请联系:admin#unsafe.sh