Microsoft console files are misused to give hackers access to private systems

Hackers are now using custom MSC files to exploit a known but unpatched Windows cross-site scripting (XSS) vulnerability, allowing them to remotely execute malware or malicious code on target devices.

Cybersecurity researchers on the Elastic team recently noticed threat actors distributing Microsoft Saved Console (MSC) files, which are typically used by the Microsoft Management Console (MMC). This tool handles various parts of the operating system and can create custom views of commonly used tools.