Bemstour

Description

(Symantec) Bemstour exploits two Windows vulnerabilities in order to achieve remote kernel code execution on targeted computers. One vulnerability is a Windows zero-day vulnerability (CVE-2019-0703) discovered by Symantec. The second Windows vulnerability (CVE-2017-0143) was patched in March 2017 after it was discovered to have been used by two exploit tools—EternalRomance and EternalSynergy—that were also released as part of the Shadow Brokers leak.

Names

Name
Bemstour

Category

Malware

Type

  • Backdoor

Information

Alienvault Otx

Other Information

Uuid

5619e030-6454-4788-8770-243c6a754623

Last Card Change

2020-04-20