공인 인증 솔루션(VestCert) 취약점 주의 및 업데이트 권고

2023-03-17 Ahnlab Be aware of public authentication solution (VestCert) vulnerabilities and recommend updates

https://asec.ahnlab.com/ko/49561/

Thumbnail for 공인 인증 솔루션(VestCert) 취약점 주의 및 업데이트 권고

AhnLab warned that vulnerable versions of YettieSoft VestCert, a Korean Non-ActiveX public certificate module, exposed users to remote code execution because the resident service can restart the process and keep it available for exploitation. AhnLab observed exploitation through its ASD infrastructure, where attackers used the vulnerability to download and execute malware named winsync.dll. The malware closely resembled the previously reported SCSKAppLink.dll, including abuse of Notepad++ plug-in open source code and the same string-decryption routine, and AhnLab urged operators and users to update or reinstall fixed VestCert versions.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 0a840090b5eac30db985f0c46f46a602 2023-03-17 2023-03-17
URL https://www.yettiesoft.com/html… 2023-03-17 2023-03-17

Related Reports

« Back