Gallery

Contacts

405 W. Greenlawn Ave Lansing, Michigan 48910

contact@techjacksolutions.com

+1-616-320-4064

CrowdStrike has published the first documented in-depth technical analysis of Microsoft ClickOnce as a malware delivery mechanism, revealing that threat actors can exploit the framework’s native design, no admin privileges required, minimal user friction, auto-update functionality, to deploy malicious payloads on Windows endpoints while evading standard endpoint defenses. The research documents both previously known and newly disclosed abuse vectors, catalogued under CWE-494 and CWE-345, with an associated CVSS score of 7.5 (High). This disclosure signals a broader pattern of adversaries repurposing trusted, built-in Windows deployment infrastructure to bypass security controls, a strategy that compounds detection difficulty and increases dwell time.

Author

Tech Jacks Solutions