Car Cybersecurity Study Shows Drop in Critical Vulnerabilities Over Past Decade

Research-focused security services provider IOActive has conducted an analysis of car vulnerability trends over the past decade and determined that the automotive industry has been placing increasing importance on cybersecurity. 

The new IOActive automotive cybersecurity study (PDF) looks at vulnerabilities discovered over the last 10 years, with a focus on trends between 2016, 2018 and 2022.  

The company has ranked and grouped vulnerabilities based on their potential real-world impact, their likelihood of exploitation, and their overall risk, with this risk level being calculated based on impact and likelihood. 

In terms of impact, the percentage of car vulnerabilities with a critical rating went from 25% of the total in 2016, to 10% in 2018, and 12% in 2022. High-impact flaws gradually decreased from 25% to 21% between 2016 and last year.

However, over the past 10 years, the percentage of critical issues dropped by 13% and high-impact issues by 4%. 

In terms of likelihood of exploitation, critical vulnerabilities went from 7% of the total in 2016 to 1% in 2022. High-likelihood issues dropped to 16% in 2022, from 21% in 2016. This, according to IOActive, suggests that vulnerabilities are becoming more difficult to exploit or “the vectors to discover vulnerabilities are becoming less remote”.

“In cybersecurity parlance, there is less ‘low-hanging fruit,’ indicating that between 2018 and 2022, the automotive industry learned from its initial mistakes and is building better,” the cybersecurity firm said.

Advertisement. Scroll to continue reading.

Overall, the percentage of critical- and high-likelihood vulnerabilities decreased by 6% and 5%, respectively, in the past 10 years. 

When it comes to the overall risk, the percentage of high-risk vulnerabilities has increased by 3% and medium-risk issues by 25% in the past 10 years, but critical-risk weaknesses decreased by 17% over the same period. 

The ‘critical risk’ rating is assigned to issues that can be exploited remotely and are easy to discover, with impact including complete component compromise or safety concerns. High-risk flaws are ones that can be exploited from nearby or require limited skills, and their impact includes partial component control, sensitive information disclosure or a potential safety concern.

As for attack vectors, physical hardware attacks dropped from 28% in 2016 to 10% in 2022, but local and networked attack vectors have increased. IOActive has also seen a slight but important rise — from 0% to 1% — in radio frequency attacks, particularly remote keyless entry and Bluetooth attacks.  

IOActive has attributed the positive trends to the automotive industry building cybersecurity into earlier stages of the development process, as well as its efforts to reduce higher likelihood attack vectors and its improved maturity level in deploying cybersecurity practices.  

On the other hand, IOActive has also raised some potential concerns. One of them is that while critical vulnerabilities are less common, threat actors could turn to chaining multiple less severe flaws — such as medium-risk issues, which increased significantly — to achieve their goals, rather than relying on a single critical weakness.

Related: Over $1 Million Offered at New Pwn2Own Automotive Hacking Contest

Related: Automotive Security Threats Are More Critical Than Ever

Related: US Subsidiary of Automotive Hose Maker Nichirin Hit by Ransomware

https://www.securityweek.com/car-cybersecurity-study-shows-drop-in-critical-vulnerabilities-over-past-decade/




Atos Unify Vulnerabilities Could Allow Hackers to Backdoor Systems

Two vulnerabilities discovered earlier this year in Atos Unify products could allow malicious actors to cause disruption and even backdoor the targeted system.

The flaws were found in the unified communications and collaboration solution by researchers at SEC Consult, an Austria-based cybersecurity consulting firm that is part of the Atos Group’s Eviden business.

The vulnerabilities affect the Atos Unify Session Border Controller (SBC), which provides security for unified communications, the Unify OpenScape Branch product for remote offices, and Border Control Function (BCF), which is designed for emergency services.

SEC Consult researchers discovered that the web interface of these products is affected by CVE-2023-36618, which can be exploited by an authenticated attacker with low privileges to execute arbitrary PHP functions and subsequently operating system commands with root privileges.

The second security hole, CVE-2023-36619, can be exploited by an unauthenticated attacker to access and execute certain scripts. An attacker could leverage these scripts to cause a denial-of-service (DoS) condition or change the system’s configuration.

SEC Consult says the vulnerabilities have critical impact, but the vendor has assigned the flaws a ‘high severity’ rating based on their CVSS score.

“Attackers can gain full control (root access) over the appliance, if any low-privileged user credentials are known, and could reconfigure or backdoor the system (e.g. change SIP upstream configuration, etc),” Johannes Greil, head of the SEC Consult Vulnerability Lab, told SecurityWeek.

Advertisement. Scroll to continue reading.

Greil pointed out that the affected web interface is typically not exposed to the internet and a brief Shodan analysis shows there are no systems that are reachable from the web.

The cybersecurity firm this week published an advisory containing technical information, but proof-of-concept (PoC) exploit code has not been made public. 

Atos has released updates that should patch both Unify vulnerabilities. The vendor has also suggested a series of workarounds that can prevent or reduce the risk of exploitation. 

Related: Details Disclosed for Critical SAP Vulnerabilities, Including Wormable Exploit Chain

Related: Critical Siemens RTU Vulnerability Could Allow Hackers to Destabilize Power Grid

Related: Critical Vulnerabilities Patched in OpenText Enterprise Content Management System

https://www.securityweek.com/atos-unify-vulnerabilities-could-allow-hackers-to-backdoor-systems/




GitLab Patches Critical Pipeline Execution Vulnerability

DevOps platform GitLab this week announced the release of security updates that address a critical-severity vulnerability allowing an attacker to run pipelines as another user.

Tracked as CVE-2023-5009 (CVSS score of 9.6) and affecting all GitLab Enterprise Edition (EE) versions before 16.2.7 and GitLab Community Edition (CE) versions before 16.3.4, the bug is a bypass of another flaw, CVE-2023-3932, which was addressed in August 2023.

According to GitLab’s advisory, the issue allows “an attacker to run pipelines as an arbitrary user via scheduled security scan policies”.

The original vulnerability, CVE-2023-3932, was reported via GitLab’s HackerOne bug bounty program by a researcher who explained that the attacker could trigger the issue via the scan execution policy.

The bug could be triggered without any user interaction, but the attacker needed to know the victim’s GitLab username and the name of a victim’s internal or members-only project.

By exploiting the flaw, the attacker could gain access to projects containing private code, the researcher explained.

CVE-2023-5009 too was reported through the HackerOne platform, and GitLab encourages users to update to GitLab CE and EE versions 16.3.4 and 16.2.7, which resolve the flaw.

Advertisement. Scroll to continue reading.

However, the code hosting platform also notes that for GitLab versions prior to 16.2 the vulnerability only exists if the ‘Direct transfers’ and ‘Security policies’ features are enabled at the same time.

To mitigate the flaw, users that cannot upgrade to a patched version of GitLab can disable one or both these features.

“We strongly recommend that all installations running a version affected by the issues are upgraded to the latest version as soon as possible,” GitLab notes.

The code hosting platform makes no mention of this vulnerability being exploited in malicious attacks.

Related: GitLab Security Update Patches Critical Vulnerability

Related: GitLab Patches Critical Remote Code Execution Vulnerability

Related: Critical Account Takeover Vulnerability Patched in GitLab Enterprise Edition

https://www.securityweek.com/gitlab-patches-critical-pipeline-execution-vulnerability/




Thousands of Juniper Appliances Vulnerable to New Exploit 

Threat intelligence firm VulnCheck has published details on a new exploit targeting a recent Junos OS vulnerability and says that thousands of Juniper Networks appliances that have not been patched are at risk.

The flaw, tracked as CVE-2023-36845, is described as a PHP environment variable manipulation issue in the J-Web interface of Juniper’s SRX series firewalls and EX series switches running specific Junos OS versions.

In mid-August, the networking appliances maker released patches for this bug and three other medium-severity issues, warning that an attacker could chain them to achieve remote code execution (RCE) on a vulnerable device, and that the exploit chain should be considered as having a ‘critical severity’ rating.

Roughly one week after Juniper’s patches and following the release of a proof-of-concept (PoC) exploit chaining two of the vulnerabilities, the first malicious attacks targeting the flaws were observed.

Now, VulnCheck says it has developed a new exploit that targets CVE-2023-36845 only, and which leads to RCE without chaining with other bugs.

What’s more, the threat intelligence firm says that the exploit allows an unauthenticated attacker to execute code without creating a file on the vulnerable Juniper appliance’s system, and that most of the internet-exposed Juniper devices remain vulnerable, as they have not been patched yet.

In devising the fileless attack, VulnCheck used as a research base the previously released PoC exploit, which relied on uploading two files to the vulnerable appliance to achieve RCE.

Advertisement. Scroll to continue reading.

VulnCheck discovered that it could leak sensitive information and achieve remote code execution via an HTTP request, by abusing legitimate FreeBSD functions (the vulnerable devices run FreeBSD) and without dropping a single file on the system.

“Just like that, by only using CVE-2023-36845, we’ve achieved unauthenticated and remote code execution without actually dropping a file on disk. Our private exploit establishes a reverse shell, but that’s quite trivial once you’ve reached this point,” VulnCheck notes.

To check the number of potentially affected devices that are exposed to the internet, VulnCheck performed a Shodan search, which returned roughly 15,000 results. An analysis of approximately 3,000 of these devices showed that 79% are not patched against CVE-2023-36845.

“Firewalls are interesting targets to APT as they help bridge into the protected network and can serve as useful hosts for [command-and-control] infrastructure. Anyone who has an unpatched Juniper firewall should examine it for signs of compromise,” VulnCheck notes.

Related: Juniper Networks Patches High-Severity Vulnerabilities in Junos OS

Related: Juniper Networks Patches Critical Third-Party Component Vulnerabilities

Related: Juniper Networks Kicks Off 2023 With Patches for Over 200 Vulnerabilities

https://www.securityweek.com/thousands-of-juniper-appliances-vulnerable-to-new-exploit/




Trend Micro Patches Exploited Zero-Day Vulnerability in Endpoint Security Products

Trend Micro on Tuesday released an advisory to warn customers that a critical vulnerability affecting Apex One and other endpoint security products has been exploited in the wild.

The zero-day flaw, tracked as CVE-2023-41179, impacts Apex One, Apex One SaaS, and Worry-Free Business Security products. 

The vulnerability, related to the products’ ability to uninstall third-party security software, can be exploited for arbitrary code execution.

“To exploit this vulnerability, an attacker would need to be able to log into the product’s administrative console. Because an attacker would need to have stolen the product’s management console authentication information in advance, they would not be able to infiltrate the target network using this vulnerability alone,” Trend Micro noted in a Japanese-language advisory.

It added, “Trend Micro has confirmed that this vulnerability has been used in actual attacks. We recommend updating to the latest version as soon as possible.”

Patches have been released for each of the impacted products. 

Trend Micro typically does not share information about the attacks exploiting vulnerabilities found in its products. 

Advertisement. Scroll to continue reading.

However, there have been a few instances where some information has come to light, including attribution to Chinese threat actors and the possible exploitation of a flaw in an attack targeting Mitsubishi Electric

Several Trend Micro product vulnerabilities have been exploited in attacks in the past few years. CISA currently lists nine such flaws in its Known Exploited Vulnerabilities Catalog. The latest zero-day has yet to be added.

Related: Trend Micro Patches Another Apex One Vulnerability Exploited in Attacks

Related: Trend Micro Patches Two Vulnerabilities Exploited in the Wild

Related: AV Under Attack: Trend Micro Confirms Apex One Exploitation

https://www.securityweek.com/trend-micro-patches-exploited-zero-day-vulnerability-in-endpoint-security-products/




Hacker Conversations: Casey Ellis, Hacker and Ringmaster at Bugcrowd

In this edition of Hacker Conversations, SecurityWeek talks to Casey Ellis, founder, chairman and CTO at Bugcrowd – and hacker. Bugcrowd provides a crowdsourced ethical hacking cybersecurity platform, best known for operating bug bounty programs on behalf of individual organizations.

“A hacker,” says Ellis, “is someone who takes the assumptions of a system and tips them upside down to see what falls out. Hackers will learn how a system works, to the extent they can manipulate it into doing things it was never originally intended to do.” That desire is almost a default condition. “When I see a new technology, the first thing I often do is try to get it to misbehave.”

There are several factors in this definition. For example, it is not computer specific – it could apply to almost any engineering technology. Here we are solely discussing the computer hacker variety.

Most importantly, however, the act of hacking is amoral; it is driven by curiosity rather than a desire to do bad things. The process of hacking is neither moral (a good action), nor immoral (a bad action); and the term ‘hacker’ simply describes someone who likes to deconstruct and then reconstruct with additional or different outcomes.

Casey Ellis, founder, chairman and CTO at Bugcrowd
Casey Ellis, founder, chairman and CTO at Bugcrowd

It is the use made of these outcomes, for moral or immoral purposes, that forces us to divide hackers into two camps: the ethical hacker (Whitehat) and malicious hacker (Blackhat). The ethical hacker finds ways in which the system can be manipulated so the developer can prevent the malicious hacker from finding and abusing the same manipulations for his or her own benefit (usually financial or political).

Both schools of hacker have the same skill set. The question then is, why do some become immoral while others remain strictly moral; and yet others flip between the two? This is what we sought to discover in conversation with Casey Ellis. 

The motivating factors between the ethical and unethical hacker are many and varied. They could come from a personal moral compass; the vagaries and conflicts with and within national and international law; the hacker’s economic and cultural background; and social pressures arising from and amplified by neurodivergence. Or, indeed, a unique combination of a variety of these factors.

“No one wakes up one day and decides they want to become a drug dealer, or they want to be a stick-up kid. Those decisions are made after a series of events have happened in one’s life,” said actor Michael K. Williams in the Guardian in 2014. The same reasoning could be applied to most malicious hackers.

Advertisement. Scroll to continue reading.

However, while there may be an element of choice between being an ethical or unethical hacker, most hackers cannot stop being hackers. “I think most people that self-identify as a hacker, they know that they kind of can’t turn that off – it’s just a thing that their brain does,” said Ellis.

Moral compass

The accepted meaning of moral compass is clear: an innate or learned ability to understand the difference between what is right and what is wrong, and to act accordingly. It is the most common (and perhaps the easiest) answer given by ethical hackers when asked why they are ethical. The difficulty comes over ‘right’ and ‘wrong’. This distinction is effectively a subjective majority opinion governed by the current society. It may differ between different societies, or even between micro niche societies within one society.

Nevertheless, it is often used by ethical hackers to describe a firm belief that being malicious is bad.

A moral compass is not fixed for life and is more influenced by nurture than nature. Ellis, as an ethical hacker, believes his own moral compass was developed at an early life from his family upbringing. Basically, good parenting. But outside influences can affect most people as they progress through life. 

“You’ve got young people with this incredible power and skill in what they can achieve. That skill outpacing the growth and development of a moral compass is not uncommon. So how do you make sure they don’t accidentally trip over into a life of crime?” It’s something he’s proud of in Bugcrowd: “I love that we’ve actually diverted people from a life of crime because we give them a Whitehat outlet for their skills.”

The law

The influence of hackers on the law, and the law on hackers, should not be underestimated. In the UK, the Computer Misuse Act was a direct response to a ‘hack’ by Robert Schifreen and Steve Gold (two non-malicious young men). They accessed an early form of electronic mailbox (British Telecom’s Prestel) operated by the Duke of Edinburgh, primarily to prove it could be done. They were eventually arrested, prosecuted, found guilty and then released on appeal – hacking was not against the law because there was no law against hacking. And hence the subsequent and consequent Computer Misuse Act.

The US has its Computer Fraud and Abuse Act (CFAA) of 1986, which prohibits accessing a computer without authorization, or in excess of authorization. Technically, it makes independent system research, for whatever reason, illegal. So, in legal terms, an ethical hacker is automatically a malicious hacker under US law – and the influence of this lack of distinction between the two has inevitably adversely affected the development of a moral compass in young hackers.

The effect of the CFAA was eased only as recently as May 2022, with new charging rules published by the DoJ: “The policy for the first time directs that good-faith security research should not be charged. Good faith security research means accessing a computer solely for purposes of good-faith testing, investigation, and/or correction of a security flaw or vulnerability, where such activity is carried out in a manner designed to avoid any harm to individuals or the public, and where the information derived from the activity is used primarily to promote the security or safety of the class of devices, machines, or online services to which the accessed computer belongs, or those who use such devices, machines, or online services. “

Prior to this rule, says Ellis, “Doing anything to a computer without authorization was a felony crime. Even vulnerability research was technically a crime.” So ethical hackers had to be prepared to break the law for good purposes, a law which technically equated a Whitehat with a Blackhat.

Social and cultural background

The social and cultural background of young hackers is also instrumental in their development. Cultural is easiest to consider: one country’s freedom fighter is another country’s terrorist. It’s a form of relativity – perception is governed by your starting point.

“Good and bad can get a bit fuzzy,” says Ellis. “One of my favorite questions I like to throw into conversations is, ‘Do you consider the NSA and GCHQ to be Blackhat or Whitehat organizations?’”

The influence of social background is more complex: there are many examples of social backgrounds being influential in the development of both Blackhat and Whitehat hackers. Nevertheless, there are many examples where social background can be considered a contributing factor to criminality.

As a natural hacker grows up, he or she is faced with the need to make a living. In some parts of the world, even in so-called ‘advanced’ societies, it is sometimes easier to make a living through crime than it is through ‘legitimate’ employment. 

“There are areas of the world,” explains Ellis, “with such an established infrastructure around the criminal enterprise that it’s easy to get a job in crime. It’s almost a case of jumping on LinkedIn, responding to a job offer, and becoming a criminal.” In some of these areas, it is easier to work in crime than it is to get lawful employment – and a hacker has a skill set attractive to criminals.

Some areas of eastern Europe have a reputation for producing hackers. Ellis has a separate theory for this. “There’s a depth of technical prowess that exists in that part of the world – and my theory is it’s really a product of the Cold War. You have all these parents being put through state-funded astrophysics and science and engineering courses as part of the USSR’s war effort.”

But then the Cold War ended. The parents had nothing to do, but they did have kids. “So, you’ve got all this knowledge and intelligence and critical system thinking being dumped into that part of the world, and then suddenly, it’s got no outlet. I think, to me, that explains a big part of why there’s so much talent in that part of the world.”

But neither social nor cultural background is enough to explain the existence of hackers, nor their delineation into ethical or unethical hacking.

The influence of neurodiversity

The incidence of neurodiversity among hackers is interesting. There is ample empirical evidence to suggest a higher ratio of neurodivergence among hackers than among ‘normal people’ (affectionately known as ‘normies’) – but no scientific evidence. As the name suggests, neurodivergence implies a difference in the way the brain operates between divergents and normies.

There are two categories of neurodivergence with relevance to hacking skills: ADHD and ASD (formerly known as Asperger’s Syndrome). Ellis is ADHD. Daniel Kelley (here in the Hacker Conversations series) is ASD. While there are many degrees in both conditions, there are also similarities and differences between them. Both can hyperfocus, while ADHD is comparatively more extrovert in personality, and ASD is more introvert and socially unskilled.

“Systems are usually built by neurotypical people and used by neurotypical people,” says Ellis. “So, having a neurodivergent come in and say, ‘Hey, here’s the thing you missed’ makes sense. It’s there in the name – they’re thinking in a different way.” But at the same time, Ellis rejects the idea that neurodivergence is a pre-requisite for hacking – the insatiable curiosity and desire to deconstruct and reconstruct differently is more important.

The common element between the two forms of neurodivergence is the ability to hyperfocus, often for hours on end. “When I got my diagnosis,” said Ellis, “I thought, yeah that makes total sense because my mind flips between things very, very quickly. But if I line up and hyperfocus on getting something done, I’m pretty much unstoppable at that point.” Ellis learned that through understanding his ADHD condition, it became a superpower and not a disability. That helps, but does not create, a hacker.

ASD has a different effect. The lack of social skills in an uncompensated ASD youngster can sometimes constrain that person to a more solitary life, often alone with a computer. If that condition is supplemented by high intelligence, exploring the world through and with the computer becomes natural. Under these conditions, the combination of hyperfocus, an unformed moral compass, an ill-defined legal definition of malicious hacking, and the prevalent social background can all combine into directing that person onto the wrong path.

Again, there is no evidence to show that this does happen, but there are plenty of examples to show that it can happen.

The fence

Hacking is not binary, fixed as either ethical or unethical. There may be a fence between the two sides, but that fence has gates, and the potential to move from one side of the fence to the other – even if temporarily – exists.

Ellis cites his perception of two examples. The first is the Uber hack that ultimately led to the prosecution Uber’s CISO, Joe Sullivan. The perpetrators, suggests Ellis, “were basically kids on an internet safari where they came into possession of some pretty valuable data.”

They were neither ethical nor unethical at that point – just kids having fun. But when they came to that fence, they made the wrong choice, “and decided to go down the path of trying to get money for what they had found.”

His second example is the more recent Optus breach in Australia. It starts with the same type of internet safari as the Uber incident: hunters just looking around the internet, rattling cages and seeing what fell out. “So, strictly speaking, probably not legal, but they’re not necessarily causing any harm in the process,” said Ellis. “They’re just looking for bugs.”

Then they found an unsecured API within Optus that allowed them to enumerate the entire customer database. They did this and found themselves at the fence – and like the Uber hackers, they chose the wrong side.

But they didn’t stay on the wrong side. “They tapped out, and said, ‘That’s it, we’re not doing this anymore,” explained Ellis. “They even posted a message saying if there had been a bug bounty program or a clear way to communicate the vulnerabilities to Optus, none of this would have happened. We would have just told you guys you’ve got a problem so you can fix it.”

Ellis had two primary motivations for the founding of Bugcrowd: a commercial enterprise to build a unique security platform, and help for hackers who come to that fence.

Commercially, the platform is a countermeasure to the recognized asymmetry of malicious cyberattacks. A small team of defenders must defend against multiple diverse attackers coming from all angles, all the time. It only takes one of these attackers to cause a breach.

Bugcrowd doesn’t reverse this, but it improves defense. It provides its own small diverse army of highly skilled ethical hackers providing results-based continuous pentesting.

For hackers who may come to that fence, it provides a monetary incentive to choose the right side – an ethical and not unrewarded outlet for their skills. The principle is simple: hacking is a skill set that is amoral, neither moral nor immoral. Society provides many incentives for hackers to choose the immoral side of the fence. Bugcrowd and organizations like it, attempt to redress the balance to help hackers choose the moral side.

In Ellis’ own words, with the right help, “Hackers should be viewed as part of the internet’s immune system.”

Related: Hacker Conversations: Youssef Sammouda, Bug Bounty Hunter

Related: Inside the Mind of the Hacker: The Speed and Efficiency of Hackers in Adopting New Technologies

Related: Hackers Receive $500,000 in One Week via Bugcrowd

Related: Bugcrowd Raises $30 Million in Series D Funding Round

https://www.securityweek.com/hacker-conversations-casey-ellis-hacker-and-ringmaster-at-bugcrowd/




Google Extends Chromebook Lifespan, Promises 10 Years of Automatic Updates

Google has announced that it is committed to provide regular automatic updates, with security patches, for all recent Chromebook iterations for a period of 10 years.

Portable computers running Google’s ChromeOS, Chromebooks have been in users’ hands since 2012, and have become one of the most used types of devices within the education sector.

To prolong their lives and ensure they remain secure to use, Google said it plans to extend the automatic security updates period for some of these devices, starting next year.

“Chromebooks get automatic updates every four weeks that make your laptop more secure and help it last longer. And starting next year, we’re extending those automatic updates so your Chromebook gets enhanced security, stability and features for 10 years after the platform was released,” the search marketing giant said.

By default, the prolonged automatic security update lifecycle will apply only to Chromebooks that have been released since 2021. However, Chromebooks released before 2021 and in use may also be enrolled for receiving extended security updates for 10 years from the platform’s release, after they receive their last automatic update, should users and administrators choose to do so.

However, Google warned that some of the features and services available for newer Chromebooks may not be available for devices released prior to 2021.

The company attempted to reassure users of Chromebook devices that have reached the end of the automatic updates lifecycle that, even past this moment, built-in security features will continue to keep them safe.

Advertisement. Scroll to continue reading.

“With Verified Boot, for example, your Chromebook does a self-check every time it starts up. If it detects that the system has been tampered with or corrupted in any way, it will typically repair itself, reverting back to its original state,” Google added.

Related: Google Paid $12M in Bug Bounties in 2022

Related: New Chrome and Chrome OS Security Features for Enterprises

Related: Google Adds Passkey Support to Android, Chrome

https://www.securityweek.com/google-extends-chromebook-lifespan-promises-10-years-of-automatic-updates/




Kubernetes Vulnerability Leads to Remote Code Execution

A high-severity vulnerability in Kubernetes can be exploited to achieve remote code execution (RCE) on all Windows endpoints within the cluster, Akamai’s security researchers warn.

Tracked as CVE-2023-3676 (CVSS score of 8.8), the vulnerability impacts Kubernetes’ processing of YAML files, which are used within the container orchestration system for configuration, management, secret handling, and more.

Kubernetes relies on YAML for cluster configuration, and vulnerabilities in YAML files have been subject to numerous research projects over the past years.

Using previously identified vulnerabilities as a starting point for new research, Akamai discovered that an attacker with ‘apply’ privileges could inject code to be executed on the Windows machines within the Kubernetes cluster with System privileges.

The issue, Akamai explains, is related to how Kubernetes’ kubelet service processes YAML files containing information on where a shared directory (between the pod and the host) can be mounted.

By using a subPath subproperty, a user can mount a shared directory or file to a desired location, and kubelet validates the parameters in the YAML file to ensure that no symlinks are created when using subPath.

“The function takes as a parameter the subPath that was supplied by the user in the YAML file. It then uses this path to create a PowerShell command meant to determine the path type. The formatted PowerShell command is then immediately invoked by the ‘exec.Command’ function call,” Akamai explains.

Advertisement. Scroll to continue reading.

The presence of this command and of unsanitized user-supplied input leads to a command injection bug that an attacker can exploit to insert any PowerShell command or threat.

“An attacker can abuse this subPath evaluation to reach the vulnerable code and execute any command they want with SYSTEM privileges (kubelet’s own context) from remote nodes, and gain control over all Windows nodes in the cluster,” Akamai explains.

Akamai, which has published a proof-of-concept (PoC) YAML file and a video showcasing the code’s execution, says that the discovery of this vulnerability led to the identification of more command injection flaws in Kubernetes, which are collectively tracked as CVE-2023-3955 and CVE-2023-3893.

After the bugs were patched, Kubernetes started “passing parameters from environment variables instead of from user input”, meaning that they are treated as strings, instead of being evaluated as expressions by PowerShell, Akamai explains.

CVE-2023-3676 impacts all Kubernetes versions below 1.28. Users are advised to update their instances as soon as possible.

Recommended workarounds include disabling the use of Volume.Subpath, using the Open Policy Agent (OPA) open source agent to create rules to block certain YAML files, and employing role-based access control (RBAC) to limit the number of users who can perform actions on a cluster.

“CVE-2023-3676 requires low privileges and, therefore, sets a low bar for attackers: All they need to have is access to a node and apply privileges. High impact coupled with ease of exploitation usually means that there is a higher chance of seeing this attack (and similar attacks) on organizations,” Akamai notes.

Related: Attackers Abuse Kubernetes RBAC to Deploy Persistent Backdoor

Related: Dero, Monero Cryptojackers Fighting for Same Kubernetes Clusters

Related: Over 380,000 Kubernetes API Servers Exposed to Internet: Shadowserver

https://www.securityweek.com/kubernetes-vulnerability-leads-to-remote-code-execution/




Azure HDInsight Flaws Allowed Data Access, Session Hijacking, Payload Delivery

Orca Security has published details on eight cross-site scripting (XSS) vulnerabilities impacting Azure HDInsight, which could be exploited to access data, hijack sessions, or deliver malicious payloads.

The flaws were identified by the cloud security firm in several Apache services, such as Hadoop, Spark, Kafka, and Oozie, all operating under the Azure HDInsight umbrella.

An open source analytics service, Azure HDInsight allows organizations to use open source frameworks in their Azure environment for big data analysis, management, and processing.

The eight vulnerabilities, tracked under five different CVE identifiers – CVE-2023-36881, CVE-2023-35394, CVE-2023-38188, CVE-2023-35393, CVE-2023-36877 – were identified through the manipulation of variables and function exploitation.

“All 8 XSS vulnerabilities discovered in various platforms and components in Azure HDInsight primarily resulted from the lack of proper input sanitization. This omission allowed malicious characters to be rendered once the dashboard was loaded, demonstrating inadequate output encoding that fails to neutralize these characters when rendered,” Orca explains.

The first issue, tracked as CVE-2023-36881, was initially discovered in the Apache Ambari Background operations, which had multiple default parameters that could be modified to perform an XSS attack.

The same CVE identifier is used to track the issue in the Ambari Managed Notifications component and the Ambari YARN Queue Manager. The flaw can be exploited by manipulating alert notifications, by tampering with the Access Control functions, and by injecting JS code into specific YARN configurations.

Advertisement. Scroll to continue reading.

CVE-2023-35394, Orca explains, is an XSS vulnerability in Azure HDInsight’s Jupyter Notebook service that could be exploited to achieve remote code execution by bypassing the Caja compiler’s sanitization process.

The Apache Hadoop ResourceManager UI within Azure HDInsight was found vulnerable to manipulation of the container endpoint and port (CVE-2023-38188).

Apache Hive 2 was also found vulnerable to container endpoint manipulation (CVE-2023-35393), while the Apache Oozie Web Console allowed for XSS attacks to be performed via filter manipulation (CVE-2023-36877).

Orca has reported all vulnerabilities to Microsoft, which addressed them with the August 2023 Patch Tuesday security updates for Azure HDInsight.

Related: XSS Vulnerabilities in Azure Led to Unauthorized Access to User Sessions

Related: Azure API Management Vulnerabilities Allowed Unauthorized Access

Related: Researchers Flag Account Takeover Flaw in Microsoft Azure AD OAuth Apps

https://www.securityweek.com/azure-hdinsight-flaws-allowed-data-access-session-hijacking-payload-delivery/




Zero Day Summer: Microsoft Warns of Fresh New Software Exploits

Microsoft’s struggles with zero-day exploits rolled into a new month with a fresh warning that two new Windows vulnerabilities are being targeted by malware attacks in the wild.

As part of its scheduled batch of Patch Tuesday security fixes, Redmond’s security response team flagged the two zero-days — CVE-2023-36761 and CVE-2023-36802 — in the “exploitation detected” category and urged Windows sysadmins to urgently apply available fixes.

The most serious of the two bugs is described as a privilege escalation flaw in Microsoft Streaming Service Proxy that carries a CVSS severity score of 7.8/10.

“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft cautioned. 

The Microsoft Streaming Service Proxy is part of the enterprise-facing Microsoft Stream video communications service.

Microsoft credited the discovery of the flaw to IBM X-Force security researcher Valentina Palmiotti and its internal threat-intelligence and malware-hunting teams.

The second zero-day, confirmed in Microsoft Word, is an information-disclosure issue credited to Redmond’s internal bug finders.  “Exploiting this vulnerability could allow the disclosure of NTLM hashes,” the company said.

Advertisement. Scroll to continue reading.

As is customary, Microsoft did not release any additional details on the live attacks or indicators of compromise (IOCs) to help defenders hunt for signs of compromise.

The two zero-days headline a hefty Patch Tuesday for Microsoft customers.  In all, the company shipped patches for approximately 65 documented flaws (counting by published CVEs)

The patches cover bugs in Windows operating system and software components that include Microsoft Office, Azure, Exchange Server and Windows Defender.

Related: Apple Patches Actively Exploited iOS, macOS Zero-Days

Related: Adobe Says Critical PDF Reader Zero-Day Being Exploited 

Related: Cisco ASA Zero-Day Exploited in Akira Ransomware Attacks

Related: Google Patches Chrome Zero-Day Reported by Apple

https://www.securityweek.com/zero-day-summer-microsoft-warns-of-fresh-new-software-exploits/