{"id":330000,"date":"2024-04-11T19:00:53","date_gmt":"2024-04-11T17:00:53","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=330000"},"modified":"2024-08-08T18:44:39","modified_gmt":"2024-08-08T16:44:39","slug":"microsoft-corrige-dos-exploits-de-dia-cero-que-podian-utilizarse-para-colarte-malware","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/es\/microsoft-corrige-dos-exploits-de-dia-cero-que-podian-utilizarse-para-colarte-malware\/","title":{"rendered":"Microsoft corrige dos exploits de d\u00eda cero que pod\u00edan utilizarse para colarte malware"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>Microsoft<\/strong> ha lanzado esta semana un enorme lote de actualizaciones que corrige un gran n\u00famero de vulnerabilidades, incluyendo algunas utilizadas por ciberdelincuentes para distribuir malware. Entre las <strong>150 vulnerabilidades parcheadas<\/strong> se encuentran la <strong>CVE-2024-26234<\/strong> y la <strong>CVE-2024-29988<\/strong>, dos <a href=\"https:\/\/latam.kaspersky.com\/resource-center\/definitions\/zero-day-exploit\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">vulnerabilidades de d\u00eda cero<\/a> de extrema gravedad.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/9de631e4-96d2-11e6-be3c-00163ec9f5fa\/1794891465\/kaspersky-kaspersky.png\" alt=\"Kaspersky Anti-Virus\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Kaspersky Anti-Virus<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/kaspersky.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DESCARGAR<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/kaspersky.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">En un principio, Microsoft no marc\u00f3 estas dos <a href=\"https:\/\/www.softonic.com\/articulos\/google-logra-solucionar-uno-de-sus-mayores-quebraderos-de-cabeza-hasta-la-fecha\">vulnerabilidades<\/a> como activamente explotadas, pero tanto <strong>Sophos<\/strong> como <strong>Trend Micro<\/strong>, dos compa\u00f1\u00edas de ciberseguridad, compartieron informaci\u00f3n con la compa\u00f1\u00eda sobre c\u00f3mo <strong>fueron explotadas activamente en una serie de ataques<\/strong>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">En el caso de <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2024-26234\">CVE-2024-26234<\/a>, una vulnerabilidad de suplantaci\u00f3n de controladores proxy, Sophos comparti\u00f3 que este CVE est\u00e1 asignado a un <strong>controlador malicioso<\/strong> firmado con un certificado v\u00e1lido de Microsoft Hardware Publisher, y que se habr\u00eda utilizado para <strong>desplegar una puerta trasera previamente revelada por Stairwell<\/strong>.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"576\" src=\"https:\/\/articles-img.sftcdn.net\/sft\/articles\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-1024x576.jpg\" alt=\"\" class=\"wp-image-285040\" srcset=\"https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-1024x576.jpg 1024w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-300x169.jpg 300w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-768x433.jpg 768w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-800x450.jpg 800w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-664x374.jpg 664w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-238x134.jpg 238w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-436x246.jpg 436w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-370x208.jpg 370w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-304x170.jpg 304w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-18x10.jpg 18w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware-150x84.jpg 150w, https:\/\/articles-img.sftcdn.net\/auto-mapping-folder\/sites\/2\/2023\/04\/Troyano-Agent-Tesla-malware.jpg 1200w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2024-29988\" target=\"_blank\" rel=\"noopener nofollow\" title=\"\">CVE-2024-29988<\/a>, por otro lado, es un parche para eludir el fallo <strong>CVE-2024-21412<\/strong> (tambi\u00e9n un parche para el fallo CVE-2023-36025), que permite que los archivos adjuntos <strong>eludan los avisos de Microsoft Defender Smartscreen cuando se abre el archivo<\/strong>. Lo utiliz\u00f3 el grupo de piratas inform\u00e1ticos Water Hydra, con motivaciones financieras, para atacar foros de compraventa de divisas y canales de Telegram de compraventa de acciones en <strong>ataques de spearphishing que desplegaban el troyano de acceso remoto (RAT) DarkMe<\/strong>.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/9de631e4-96d2-11e6-be3c-00163ec9f5fa\/1794891465\/kaspersky-kaspersky.png\" alt=\"Kaspersky Anti-Virus\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">Kaspersky Anti-Virus<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/kaspersky.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\">DESCARGAR<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/kaspersky.softonic.com\/\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Microsoft ha lanzado esta semana un enorme lote de actualizaciones que corrige un gran n\u00famero de vulnerabilidades, incluyendo algunas utilizadas por ciberdelincuentes para distribuir malware. Entre las 150 vulnerabilidades parcheadas se encuentran la CVE-2024-26234 y la CVE-2024-29988, dos vulnerabilidades de d\u00eda cero de extrema gravedad. En un principio, Microsoft no marc\u00f3 estas dos vulnerabilidades como &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/es\/microsoft-corrige-dos-exploits-de-dia-cero-que-podian-utilizarse-para-colarte-malware\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Microsoft corrige dos exploits de d\u00eda cero que pod\u00edan utilizarse para colarte malware&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9256,"featured_media":291529,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":1},"categories":[9317],"tags":[],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-330000","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts\/330000","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/users\/9256"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/comments?post=330000"}],"version-history":[{"count":0,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts\/330000\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/media\/291529"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/media?parent=330000"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/categories?post=330000"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/tags?post=330000"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/usertag?post=330000"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/vertical?post=330000"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/content-category?post=330000"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}