Back to Blog
CVE-2023-24932: Microsoft Windows — Kernel Backdoor Enables Stealth Espionage (June 2024)
vulnerabilities

CVE-2023-24932: Microsoft Windows — Kernel Backdoor Enables Stealth Espionage (June 2024)

breachwire TeamJun 18, 20262 min read

CVE-2023-24932 — Microsoft Windows

CVE-2023-24932 is a high-severity Windows vulnerability exploited by the China-linked FishMonger group to deploy SprySOCKS backdoors with kernel-level stealth. This CVE enables attackers to gain persistent, covert remote access and control over compromised systems. Active exploitation has been observed targeting government networks; immediate patching is required.

Attack Vector

FishMonger leverages malicious kernel drivers (DriverLoader, RawWNPF) and abuses the Windows Print Spooler (spoolsv.exe) to load SprySOCKS backdoors. The malware achieves stealth by operating at the kernel level and may use UEFI bootkit components for persistence. Attackers deploy IOCs such as KW1B5206BDC1743FP.dat and employ DLL side-loading to evade detection. The backdoor provides interactive shell access, file transfer, process/service enumeration, and SOCKS proxy capabilities, enabling long-term espionage.

Who Is at Risk

All Windows environments are potentially vulnerable, especially those running unpatched systems or exposed Print Spooler services. Confirmed targets include government organizations in Honduras, Taiwan, Thailand, and Pakistan. Any government or enterprise with high-value data and legacy Windows deployments should consider themselves at elevated risk.

Patch & Mitigate

  • Patch: Apply the latest Microsoft security updates addressing CVE-2023-24932 immediately. Prioritize systems with exposed Print Spooler services and those handling sensitive data.
  • Workaround: Disable the Print Spooler service on systems where printing is not required. Restrict driver installation to trusted administrators.
  • Detect: Monitor for unauthorized kernel driver loads (DriverLoader, RawWNPF), suspicious DLL side-loading activity, and files named KW1B5206BDC1743FP.dat. Review Print Spooler logs for anomalous behavior and scan for persistence in UEFI/bootloader regions.

MITRE ATT&CK

  • TA0005 — Defense Evasion: Kernel drivers and DLL side-loading are used to avoid detection and maintain stealth.
  • TA0007 — Persistence: UEFI bootkit components and kernel-level implants ensure long-term access.
  • TA0011 — Command and Control: SprySOCKS establishes covert channels for remote access and data exfiltration.

Source: https://securityaffairs.com/193728/apt/china-linked-fishmonger-ports-sprysocks-to-windows-with-kernel-level-stealth-and-uefi-bootkit-hints.html

Start Your 14-Day Free Trial

Get curated cyber intelligence delivered to your inbox every morning at 6 AM. No credit card required.

Get Started Free
Share this article: