Bemstour
Description
(Symantec) Bemstour exploits two Windows vulnerabilities in order to achieve remote kernel code execution on targeted computers. One vulnerability is a Windows zero-day vulnerability (CVE-2019-0703) discovered by Symantec. The second Windows vulnerability (CVE-2017-0143) was patched in March 2017 after it was discovered to have been used by two exploit tools—EternalRomance and EternalSynergy—that were also released as part of the Shadow Brokers leak.
Names
| Name |
|---|
| Bemstour |
Category
Malware
Type
- Backdoor
Information
Alienvault Otx
Other Information
Uuid
5619e030-6454-4788-8770-243c6a754623
Last Card Change
2020-04-20