Home Malware Programs Trojans Exploit:Win32/Anogre.A

Exploit:Win32/Anogre.A

Posted: February 15, 2013

Threat Metric

Threat Level: 9/10
Infected PCs: 30
First Seen: February 15, 2013
Last Seen: August 18, 2020
OS(es) Affected: Windows

Exploit:Win32/Anogre.A is a Trojan that spreads as a malicious file exploiting a vulnerability in Windows (CVE-2011-3402), which allows attackers to install programs, view, change, or delete data or create new accounts with full administrative privileges. If a PC user visits a website, which contains the malicious code while using a vulnerable version of Windows, Exploit:Win32/Anogre.A will attempt to load itself on the machine. Once installed, Exploit:Win32/Anogre.A makes system changes by dropping infected files. Exploit:Win32/Anogre.A is a specially-crafted TrueType font file which exploits a vulnerability in the Win32k.sys. The Win32k.sys file is the Windows kernel mode driver, which, among other functions, is responsible for TrueType Fonts rendering in ring 0.

Loading...