Get a Pentest and security assessment of your IT network.

News

Regsvr32 can be used to install Ransomware through Jscript Installers

A security researcher named Casey Smith published an article last week where he detailed how the Windows Regsvr32.exe command could be used to bypass AppLocker restrictions. In this article he described a not commonly known feature where Regsv.exe can execute specially crafted. scripts on a remote host using a URL. This means an attacker can do very bad things to your computer as long as they have access to it. As it is not known whether this will be patched or not, it is important to block Reg.virus software. If you do not have a firewall installed, you can use the Windows Firewall to do this.

Source: https://www.bleepingcomputer.com/news/security/regsvr32-can-be-used-to-install-ransomware-through-jscript-installers/

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

Webroot Impact of Web-borne threats on businesses

News

UK NCSC warns of cyber attacks powered by Russia against the political system