Adobe Patch Tuesday: Critical Bugs in Acrobat, Reader, ColdFusion

Software maker Adobe on Tuesday rolled out a massive batch of security fixes to cover critical-severity flaws in its Acrobat and Reader, ColdFusion, inDesign, inCopy and Audition products.

As part of its scheduled Patch Tuesday updates, Adobe documented 72 distinct security bugs and called special attention to code-execution defects in the widely deployed Adobe Acrobat and Reader software.

In a critical-severity bulletin, Adobe documented at least 17 Acrobat and Reader bugs that expose unpatched Windows and macOS systems to arbitrary code execution and memory leak issues. 

Adobe also issued patches for at least six distinct ColdFusion flaws that could lead to arbitrary code execution and security feature bypass. The ColdFusion issues are flagged as critical and affects versions 2023 and 2021.  

The mega-patch bundle also includes cover for five vulnerabilities in RoboHelp Server (arbitrary code execution and memory leak in the context of the current user); six documented Photoshop bugs (arbitrary code execution and memory leak); seven denial-of-service and memory leak issues in InDesign; and three documented bugs exposing Adobe Bridge users to memory leakage.

The San Jose, Calif. vendor also covered code execution issues in the Adobe FrameMaker Publishing Server and the Adobe Media Encoder and Adobe Premiere Pro.

Adobe said it was not aware of in-the-wild exploits for any of the documented vulnerabilities.

Related: Two New Adobe ColdFusion Vulnerabilities Exploited in Attacks

Advertisement. Scroll to continue reading.

Related: Patch Tuesday: Code Execution Flaws in Adobe Commerce, Photoshop

Related: CISA Warns of Attacks Exploiting Adobe Acrobat Vulnerability

Related: Adobe Says Critical PDF Reader Zero-Day Being Exploited

https://www.securityweek.com/adobe-patch-tuesday-critical-bugs-in-acrobat-reader-coldfusion/




Protected Virtual Machines Exposed to New ‘CacheWarp’ AMD CPU Attack

A team of researchers has disclosed the details of a new attack method affecting a security feature present in AMD processors, demonstrating the risk it can pose to protected virtual machines (VMs).

The attack method, named CacheWarp, was discovered by researchers from the CISPA Helmholtz Center for Information Security in Germany, the Graz University of Technology in Austria, and independent researcher Youheng Lu. 

CacheWarp affects AMD Secure Encrypted Virtualization (SEV), a CPU extension designed for isolating VMs from the underlying hypervisor at the hardware level, enabling developers to securely deploy VMs even if the hypervisor is untrusted. AMD SEV provides protection by encrypting VM data, including memory and register state. 

The feature, particularly the new SEV-SNP (Secure Nested Paging), is highly useful for protecting sensitive data in cloud environments, securing VMs even against compromised or untrusted cloud providers.

According to the researchers who discovered the attack method, CacheWarp can allow malicious hackers to hijack control flow, break into an encrypted VM, and escalate privileges.

“For a simple example,” the researchers explained, “assume you have a variable determining whether a user is successfully authenticated. By exploiting CacheWarp, an attacker can revert the variable to a previous state and thus take over an old (already authenticated) session. Furthermore, an attacker can manipulate the return address stored on the stack and, by that, change the control flow of a victim program.”

In a CacheWarp attack scenario, the attacker (a malicious hypervisor) has elevated privileges, but has no control over the data or code inside the targeted VM.

CacheWarp has been described as a software-based fault injection attack that is possible due to a hardware issue in AMD CPUs. The researchers pointed out that the root cause is an architectural bug, and CacheWarp is not a transient-execution or side-channel attack, like many other CPU attack methods disclosed in recent years. 

CacheWarp can impact any system powered by an AMD CPU that supports SEV, but only users who deploy secure virtual machines using SEV are at risk of attacks.

Advertisement. Scroll to continue reading.

The underlying vulnerability is tracked as CVE-2023-20592. AMD, which learned about the issue in April 2023, has published its own security advisory, providing information on impacted products and patches.  

The researchers have made available a paper detailing their findings and they have launched a dedicated website that provides a high-level summary of the CacheWarp attack.

They have also published a couple of videos showing how the vulnerability can be exploited to bypass OpenSSH authentication and escalate privileges to root via Sudo.

Related: New ‘Inception’ Side-Channel Attack Targets AMD Processors

Related: Retbleed: New Speculative Execution Attack Targets Intel, AMD Processors

Related: New ‘Hertzbleed’ Remote Side-Channel Attack Affects Intel, AMD Processors

Related: Chipmaker Patch Tuesday: Intel, AMD Address Over 100 Vulnerabilities

https://www.securityweek.com/protected-virtual-machines-exposed-to-new-cachewarp-amd-cpu-attack/




SysAid Zero-Day Vulnerability Exploited by Ransomware Group

Organizations using SysAid IT service management software have been warned about a zero-day vulnerability that has been exploited by affiliates of a notorious ransomware operation. 

Exploitation of the zero-day, tracked as CVE-2023-47246, was apparently first observed by Microsoft’s threat intelligence team, which rushed to notify SysAid about the vulnerability and the attacks.

The vendor has determined that its SysAid on-premises software is impacted by the flaw, which has been described as a path traversal issue leading to arbitrary code execution. 

SysAid learned about the zero-day on November 2, and it announced the release of version 23.3.36, which should patch the vulnerability, on November 8. 

In addition to patches, the vendor has shared technical information on the observed attacks, including indicators of compromise (IoCs), as well as recommendations on the steps that potentially impacted customers should take. 

According to Microsoft, CVE-2023-47246 has been exploited by a threat actor it tracks as Lace Tempest, which is also known as DEV-0950 and whose activities overlap with the groups named FIN11 and TA505. They are all known for deploying Cl0p ransomware.

Microsoft previously linked Lace Tempest to the massive MOVEit Transfer zero-day exploitation, which to date has impacted — both directly and indirectly — more than 2,500 organizations. In those attacks, the cybercriminals exploited a MOVEit managed file transfer software flaw to gain access to the information exchanged by organizations through the product. They then used the stolen files to extort money from victims.

In the SysAid zero-day attacks, the hackers leveraged the IT support software to deliver the MeshAgent remote administration tool and the GraceWire malware. 

Advertisement. Scroll to continue reading.

“This is typically followed by human-operated activity, including lateral movement, data theft, and ransomware deployment,” Microsoft said.

According to SysAid, the cybercriminals also deployed a PowerShell script to cover their tracks by erasing evidence from targeted servers. 

Related: Sony Confirms Data Stolen in Two Recent Hacker Attacks

Related: Cybersecurity Companies Report Surge in Ransomware Attacks

Related: Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw

https://www.securityweek.com/sysaid-zero-day-vulnerability-exploited-by-ransomware-group/




Critical Vulnerabilities Expose Veeam ONE Software to Code Execution

Veeam Software has rolled out patches for four severe security vulnerabilities that expose users of its Veeam ONE product to remote code execution attacks

The Ohio company issued an urgent advisory to document the flaws, which include a pair of critical issues with CVSS severity scores of 9.9 out of 10.

An IT monitoring and analytics solution, Veeam ONE provides organizations with real-time monitoring, management reporting, and business documentation for Veeam’s backup products.

Veeam is documenting the most serious issue as CVE-2023-38547 (CVSS 9.9), a security defect that could allow an attacker to execute code remotely.

“A vulnerability in Veeam ONE allows an unauthenticated user to gain information about the SQL server connection Veeam ONE uses to access its configuration database. This may lead to remote code execution on the SQL server hosting the Veeam ONE configuration database,” the company warned.

The second critical issue, tracked as CVE-2023-38548 (CVSS 9.8), could allow an attacker obtained the hashed password for the Veeam ONE Reporting Service.

“A vulnerability in Veeam ONE allows an unprivileged user who has access to the Veeam ONE Web Client the ability to acquire the NTLM hash of the account used by the Veeam ONE Reporting Service,” Veeam said.

Veeam also patched a medium-severity issue (CVE-2023-38549) that allows an attacker with ‘power user’ privileges to obtain the access token of a Veeam ONE administrator. Successful exploitation requires interaction from the administrator.

A fourth issue, tracked as CVE-2023-41723, was also fixed to block attackers with read-only access from viewing the application’s dashboard schedule.

Advertisement. Scroll to continue reading.

Veeam released hotfixes to address these flaws in Veeam ONE versions 11, 12, and 13. Administrators are advised to download the patches and install them as soon as possible.

Veeam makes no mention of any of these vulnerabilities being exploited in attacks, but attackers are known to have targeted flaws in its backup solutions.

Related: PoC Exploit Published for Veeam Data Backup Solution Flaw

Related: Serious Vulnerability in Veeam Data Backup Solution

Related: CISA Warns Veeam Backup & Replication Vulnerabilities Being Exploited

https://www.securityweek.com/critical-vulnerabilities-expose-veeam-one-software-to-code-execution/




Exploitation of Critical Confluence Vulnerability Begins

The first in-the-wild exploitation attempts targeting a recent vulnerability in Atlassian Confluence Data Center and Confluence Server were observed over the weekend, threat intelligence firm GreyNoise warns.

Patched a week ago, the critical security defect tracked as CVE-2023-22518 (CVSS score of 9.1) is an improper authorization flaw that could lead to “significant data loss”, Atlassian warned. The issue impacts all Confluence versions.

Less than five days after releasing the patch, Atlassian issued a second warning, informing customers that “critical information about the vulnerability” had been made public, and that the risk of exploitation had increased significantly.

The enterprise software maker issued the fresh alert on the same day that ProjectDiscovery published technical information on the flaw, along with details on potential exploitation methods.

On Friday, Atlassian updated its initial advisory again, to warn that the vulnerability is under active exploitation.

“We received a customer report of an active exploit. Customers must take immediate action to protect their instances. If you already applied the patch, no further action is required,” the company’s updated advisory reads.

Over the weekend, GreyNoise’s scanners caught in-the-wild exploitation of CVE-2023-22518 targeting organizations in the US, Taiwan, Ukraine, Georgia, Latvia, and Moldova.

Attacks were originating from three different IP addresses, GreyNoise CEO and founder Andrew Morris pointed out on Sunday.

Advertisement. Scroll to continue reading.

While the issue cannot be exploited to exfiltrate data from vulnerable Confluence servers, it could be used to replace the state of an instance to attacker-supplied data, without authentication.

Rapid7 too has observed multiple attempts to exploit web-accessible Confluence servers and says that at least some of the attacks targeted CVE-2023-22518, while others targeted CVE-2023-22515, a critical Confluence zero-day that came to light on October 4. 

“The process execution chain, for the most part, is consistent across multiple environments, indicating possible mass exploitation of vulnerable internet-facing Atlassian Confluence servers,” Rapid7 notes in a November 6 post.

Multiple attack chains, the cybersecurity firm notes, involved the post-exploitation execution of commands to download a malicious payload, leading to a Cerberus ransomware infection. 

Confluence Data Center and Server versions 7.19.16, 8.3.4, 8.4.4, 8.5.3, and 8.6.1 were released last week to address CVE-2023-22518. All users are advised to update their instances as soon as possible or at least create backups and block internet access to vulnerable instances until patches are applied.

*Updated with information from Rapid7

Related: US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability

Related: Microsoft Blames Nation-State Threat Actor for Confluence Zero-Day Attacks

Related: Atlassian Patches Remote Code Execution Vulnerabilities in Confluence, Bamboo

https://www.securityweek.com/exploitation-of-critical-confluence-vulnerability-begins/




Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent

Microsoft says four Exchange ‘zero-days’ disclosed by ZDI have either already been patched or they don’t require immediate attention.

The post Microsoft Says Exchange ‘Zero Days’ Disclosed by ZDI Already Patched or Not Urgent appeared first on SecurityWeek.

https://www.securityweek.com/microsoft-says-exchange-zero-days-disclosed-by-zdi-already-patched-or-not-urgent/




Atlassian Issues Second Warning on Potential Exploitation of Critical Confluence Flaw 

Atlassian warns that ‘critical information’ released on the Confluence bug CVE-2023-22518 increases the risk of exploitation.

The post Atlassian Issues Second Warning on Potential Exploitation of Critical Confluence Flaw  appeared first on SecurityWeek.

https://www.securityweek.com/atlassian-issues-second-warning-on-potential-exploitation-of-critical-confluence-flaw/




After Major Cloud Hacks, Microsoft Unveils ‘Secure Future Initiative’

In response to a spate of embarrassing hacks, Redmond pushes ‘Secure Future Initiative’ promising faster cloud patches, better management of identity signing keys and products with a higher default security bar.

The post After Major Cloud Hacks, Microsoft Unveils ‘Secure Future Initiative’ appeared first on SecurityWeek.

https://www.securityweek.com/after-major-cloud-hacks-microsoft-unveils-secure-future-initiative/




Mass Exploitation of ‘Citrix Bleed’ Vulnerability Underway

Thousands of Citrix NetScaler ADC and Gateway instances remain unpatched against a critical vulnerability that is being widely exploited, security researchers warn.

The flaw, which had been exploited as a zero-day since August, is tracked as CVE-2023-4966 (CVSS score of 9.4) and is now referred to as ‘Citrix Bleed’. It allows unauthenticated attackers to leak sensitive information from on-prem appliances that are configured as an AAA virtual server or a gateway.

Citrix released patches for the bug on October 10 and warned last week that threat actors are actively exploiting the vulnerability in the wild to perform session hijacking, which allows them to completely bypass authentication, including multi-factor authentication protections.

Over the past few days, security researchers have started raising the alarm on CVE-2023-4966 being widely exploited, with multiple threat actors, including ransomware groups, targeting internet-accessible NetScaler ADC and Gateway instances.

The ongoing mass exploitation started around the same time Assetnote published a technical writeup of the vulnerability and a proof-of-concept (PoC) exploit for it.

According to security researcher Kevin Beaumont, however, the mass exploitation has not necessarily been triggered by the PoC publication, as “it was clear multiple groups had already obtained technical details”.

By exploiting the vulnerability, attackers gain memory access to NetScaler ADC and Gateway appliances, which allows them to extract session cookies and attempt to bypass authentication. This means that even patched instances are at risk of exploitation, as the session tokens persist in memory.

Advertisement. Scroll to continue reading.

The compromised cookies allow the attackers to replay the sessions for authentication. All they need to do is type ‘aaaaaaaaaaaaaaaaaaaaaaaa’ until they are in, Beaumont says.

“This cookie is issued post-authentication, which can include multi-factor authentication checks. An attacker with access to a valid cookie can establish an authenticated session to the NetScaler appliance without knowledge of the username, password, or access to a multi-factor authentication token or device,” Google’s cybersecurity arm Mandiant explains.

Over the weekend, Beaumont warned that attackers had stolen the session tokens of over 20,000 exploited NetScaler servers. As of November 1, data from Greynoise shows 158 unique IP addresses being used to target vulnerable instances over the past 10 days.

Warning that roughly half of NetScaler customers have yet to apply the patches, including telecommunication, electric, food, and government organizations, Beaumont last week published a scanner to help identify vulnerable NetScaler servers. 

To fully address the issue, organizations should apply the available patches and then kill all active and persistent sessions, Citrix pointed out last week, underlining that there are no known workarounds or mitigations beyond these recommended actions.

“If you are using an affected build, we urge you to install the recommended updates immediately, as this vulnerability has been identified as critical. We are aware of targeted attacks in the wild using this vulnerability,” the tech giant said.

On Tuesday, Mandiant said it is currently tracking four threat actors actively targeting CVE-2023-4966, compromising NetScaler servers, and performing various post-exploitation activities.

Threat actors have deployed various tools for reconnaissance and credential theft, remote monitoring and management (RMM) tools for persistent access, a backdoor called FreeFire, living-off-the-land binaries, and utilities for lateral movement, Mandiant said.

According to Mandiant, because NetScaler does not log requests associated with the bug, organizations can hunt for exploitation attempts using “web application firewalls (WAF) or other network appliances that record HTTP/S requests directed toward the NetScaler ADC or Gateway appliances”.

The cybersecurity firm has published comprehensive instructions on how organizations can identify evidence of session hijacking, along with indicators-of-compromise (IoCs) to aid hunters.

Mandiant has seen attacks targeting government, legal and professional services, and technology organizations in the Americas, EMEA, and the APAC regions.

“Given the widespread adoption of Citrix in enterprises globally, we suspect the number of impacted organizations is far greater and in several sectors,” it noted.

Related: US Gov Expects Widespread Exploitation of Atlassian Confluence Vulnerability

Related: In-the-Wild Exploitation Expected for Critical TeamCity Flaw Allowing Server Takeover

Related: Live Exploitation Underscores Urgency to Patch Critical WS-FTP Server Flaw

https://www.securityweek.com/mass-exploitation-of-citrix-bleed-vulnerability-underway/




Chrome 119 Patches 15 Vulnerabilities

Google on Tuesday announced the release of Chrome 119 to the stable channel with patches for 15 vulnerabilities, including 13 reported by external researchers.

Three of the externally reported bugs have a severity rating of ‘high’, and are described as inappropriate implementation in Payments (CVE-2023-5480), insufficient data validation in USB (CVE-2023-5482), and integer overflow in USB (CVE-2023-5849).

Google says in its advisory that it has paid out $16,000 for the first flaw and $11,000 for the second, and that it has yet to determine the amount to be awarded for the third issue.

Of the remaining 10 security defects reported by external researchers, eight are rated ‘medium severity’, and two have a severity rating of ‘low’.

Half of the medium-severity bugs are use-after-free issues impacting Chrome’s Printing, Profiles, Reading Mode, and Side Panel components. The other half includes two incorrect security UI issues and two inappropriate implementation flaws in Downloads.

The low-severity defects addressed this week include an inappropriate implementation in WebApp Provider and an incorrect security UI in ‘Picture In Picture’, Google notes.

The internet giant says it has paid out over $40,000 in bug bounty rewards to the reporting researchers. However, with the bounties for three of the bugs yet to be determined, the final amount might be much higher.

Advertisement. Scroll to continue reading.

As usual, Google is keeping access to the bugs restricted “until a majority of users are updated with a fix”.

The latest Chrome iteration is now rolling out to users as version 119.0.6045.105 for Linux and macOS, and as versions 119.0.6045.105/.106 for Windows.

Chrome for Android too was updated on Tuesday, bringing the same security fixes as the desktop version of the browser, Google says. Chrome 119 was pushed to iOS as well.

Google makes no mention of any of these vulnerabilities being exploited in the wild.

Related: Firefox, Chrome Updates Patch High-Severity Vulnerabilities

Related: Chrome 118 Patches 20 Vulnerabilities

Related: Google Patches Chrome Zero-Day Reported by Apple, Spyware Hunters

https://www.securityweek.com/chrome-119-patches-15-vulnerabilities/