Exploitation of Ivanti Sentry Zero-Day Confirmed

Ivanti has confirmed that a recently discovered vulnerability affecting its Sentry mobile gateway has been exploited in attacks.

The existence of the vulnerability, tracked as CVE-2023-38035 and rated ‘critical severity’, came to light on August 21. Ivanti said the flaw allows an unauthenticated attacker to “access some sensitive APIs that are used to configure Ivanti Sentry on the administrator portal”. 

Mnemonic, the cybersecurity firm that reported the issue to Ivanti, revealed that a hacker could exploit the weakness to “read and write files to the Ivanti Sentry server and execute OS commands as system administrator (root) through use of ‘super user do’ (sudo)”.

The advisory that Ivanti initially made public was not clear on whether the vulnerability has actually been exploited in the wild as a zero-day, only saying that the company was “aware of a limited number of customers impacted by CVE-2023-38035”.

In a knowledge base article that was published later, however, Ivanti clarified that it’s aware of active exploitation of the zero-day against a very limited number of customers. This suggests that the flaw has been exploited in highly targeted attacks, possibly by state-sponsored threat actors. 

Other recently found Ivanti product vulnerabilities — CVE-2023-35078 and CVE-2023-35081 affecting Ivanti Endpoint Manager Mobile (EPMM) — have been exploited in attacks aimed at the Norwegian government. Attacks exploiting the vulnerabilities reportedly also targeted police in Switzerland.

Ivanti also clarified that it learned about CVE-2023-38035 exploitation after CVE-2023-35078 and CVE-2023-35081.

Advertisement. Scroll to continue reading.

The vendor noted that this is not a supply chain attack and that its own systems have not been compromised because it does not use Sentry internally. 

The US Cybersecurity and Infrastructure Security Agency (CISA) also confirmed active exploitation of CVE-2023-38035, adding it to its Known Exploited Vulnerabilities Catalog and instructing government agencies to address it by September 12. 

The Ivanti Sentry vulnerability impacts versions 9.18, 9.17, 9.16 and prior, and the vendor has released RPM scripts that should prevent exploitation against supported versions. The vendor also pointed out that attacks are only possible through the System Manager Portal on port 8443 and the risk of exploitation is low when this port is not exposed to the internet. 

Also on Tuesday, in addition to the Ivanti product vulnerability, CISA added CVE-2023-27532 to its ‘must patch’ list. This is a Veeam Cloud Connect Replication flaw that was seen being exploited by the FIN7 cybercrime group in the spring and more recently by the Cuba ransomware group.

Related: Citrix Zero-Day Exploited Against Critical Infrastructure Organization

Related: Adobe Releases New Patches for Exploited ColdFusion Vulnerabilities

Related: Zero-Day Vulnerability Exploited to Hack Barracuda Email Security Gateway Appliances

https://www.securityweek.com/exploitation-of-ivanti-sentry-zero-day-confirmed/




CISA Warns of Another Exploited Adobe ColdFusion Vulnerability

The US Cybersecurity and Infrastructure Security Agency (CISA) is warning organizations that an Adobe ColdFusion vulnerability patched earlier this year is being exploited in attacks. 

The vulnerability in question is tracked as CVE-2023-26359 and it was added by CISA on Monday to its Known Exploited Vulnerabilities (KEV) Catalog

“These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise,” CISA warned. 

Adobe, which fixed the vulnerability with its March 2023 Patch Tuesday updates, describes CVE-2023-26359 as a critical data deserialization issue that can be exploited for arbitrary code execution. 

CISA has instructed government organizations to address the vulnerability by September 11. Government agencies are required to resolve flaws added to the catalog per the Binding Operational Directive (BOD) 22-01, which focuses on reducing the risk posed by known exploited vulnerabilities. 

CISA’s KEV catalog currently includes 12 ColdFusion flaws, including four discovered this year. Some of these security holes have been chained in attacks.

No information appears to be available on the attacks exploiting CVE-2023-26359, but Adobe ColdFusion vulnerabilities are known to have been leveraged by various types of threat actors in their operations.

Advertisement. Scroll to continue reading.

Related: Adobe Releases New Patches for Exploited ColdFusion Vulnerabilities

Related: Two New Adobe ColdFusion Vulnerabilities Exploited in Attacks

Related: Adobe Warns of ‘Very Limited Attacks’ Exploiting ColdFusion Zero-Day

Related: Decade-Old Adobe ColdFusion Vulnerabilities Exploited by Ransomware Gang

https://www.securityweek.com/cisa-warns-of-another-exploited-adobe-coldfusion-vulnerability/




Flaws in Juniper Switches and Firewalls Can Be Chained for Remote Code Execution

Networking appliances maker Juniper Networks has announced patches for four vulnerabilities in the J-Web interface of Junos OS, which could be combined for unauthenticated, remote code execution.

Tracked as CVE-2023-36844 through CVE-2023-36847, the bugs have a severity rating of ‘medium’. Their chained exploitation, however, is rated ‘critical severity’, Juniper warns in an advisory.

“By chaining exploitation of these vulnerabilities, an unauthenticated, network-based attacker may be able to remotely execute code on the devices,” the company notes.

CVE-2023-36844 and CVE-2023-36845 are described as PHP external variable modification flaws that could allow remote attackers to control environment variables, without authentication.

“Utilizing a crafted request an attacker is able to modify certain PHP environments variables leading to partial loss of integrity, which may allow chaining to other vulnerabilities,” Juniper explains.

CVE-2023-36846 and CVE-2023-36847 are described as missing authentication issues that could allow an attacker to upload arbitrary files, leading to impact on file system integrity.

“With a specific request that doesn’t require authentication an attacker is able to upload arbitrary files via J-Web, leading to a loss of integrity for a certain part of the file system, which may allow chaining to other vulnerabilities,” Juniper notes.

Advertisement. Scroll to continue reading.

Disabling the J-Web interface, or limiting access to trusted hosts only should prevent exploitation of these issues, the company says.

The vulnerabilities impact the SRX series firewalls and EX series switches running Junos OS versions prior to 20.4R3-S8, 21.2R3-S6, 21.3R3-S5, 21.4R3-S4, 22.1R3-S3, 22.2R3-S1, 22.3R2-S2, 22.3R3, 22.4R2-S1, 22.4R3, and 23.2R1.

SRX series and EX series users are advised to update their appliances to the latest Junos OS iterations as soon as possible.

Juniper makes no mention of these vulnerabilities being exploited in the wild.

The Cybersecurity and Infrastructure Security Agency (CISA) warns that the exploitation of these vulnerabilities could lead to denial-of-service (DoS) conditions.

Related: Juniper Networks Patches High-Severity Vulnerabilities in Junos OS

Related: Juniper Networks Patches Critical Third-Party Component Vulnerabilities

Related: Juniper Networks Kicks Off 2023 With Patches for Over 200 Vulnerabilities

https://www.securityweek.com/flaws-in-juniper-switches-and-firewalls-can-be-chained-for-remote-code-execution/




In Other News: US Hacking China, Unfixed PowerShell Gallery Flaws, Free Train Tickets

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:    

Zoom’s Zero Touch Provisioning allows remote hacking of desk phones

An attacker can abuse Zoom’s Zero Touch Provisioning to remotely hack desk phones and eavesdrop on rooms or phone calls, move laterally within the corporate network, or build a botnet of compromised devices. Some of the vulnerabilities involved in the attack have only been partially fixed or not patched at all. 

MaginotDNS cache poisoning attack against DNS servers

Advertisement. Scroll to continue reading.

Researchers have described MaginotDNS, a new cache poisoning attack method targeting DNS servers. MaginotDNS leverages bailiwick vulnerabilities and works against DNS software such as BIND and Microsoft DNS.   

Unfixed PowerShell Gallery vulnerabilities could allow supply chain attacks

A series of vulnerabilities in PowerShell Gallery, the central repository for sharing PowerShell code, can be exploited for typosquatting attacks and they could allow supply chain attacks. Aqua Security reported the issues to Microsoft, but they remain unpatched.  

Exploiting Moovit vulnerabilities to get free train tickets and user information

SafeBreach researchers have found a series of vulnerabilities in the products of Moovit, a mobility-as-a-service (MaaS) operator whose solutions are used worldwide. The flaws could have allowed a hacker to get free train tickets and obtain user information. Moovit was informed about the vulnerabilities and it has released patches. Customers do not need to take any action. 

Atlassian patches Confluence Server and Data Center vulnerability

Atlassian has released patches for CVE-2023-28709, a high-severity vulnerability related to third-party dependencies. An attacker could exploit the security hole for DoS attacks. 

Russia-linked attacks on NATO-aligned Ministries of Foreign Affairs

EclecticIQ has detailed a Russia-linked cyberespionage campaign that leverages PDF files purportedly coming from a German embassy to target Ministries of Foreign Affairs in NATO-aligned countries. 

China allegedly discovered cyber reconnaissance system used by US

China claims that an investigation into a cyberattack targeting the Wuhan Earthquake Monitoring Center has led to the discovery of malware that appears to be part of a global cyber reconnaissance system used by US intelligence agencies. 

LinkedIn accounts hacked

The accounts of many LinkedIn users have been hijacked in recent months, according to Cyberint. In some cases, users were locked out of their accounts by LinkedIn due to repeated hacking attempts. The attackers’ goal is currently unclear. The campaign could involve the use of compromised credentials or brute-force attacks targeting accounts with weak passwords. 

Zimbra users targeted in ongoing phishing campaign

ESET has uncovered an ongoing mass-spreading phishing campaign focused on stealing Zimbra account credentials. The attacks started in April 2023 and mainly hit users in Poland, with Ecuador and Italy registering a large number of victims as well. ESET has not attributed the attacks to a known threat actor.

Cuba ransomware targets US critical infrastructure 

The Cuba ransomware cybergang was seen targeting a US critical infrastructure organization and an IT integrator in Latin America recently, in attacks that also show a change in tactics, such as the exploitation of a recent Veeam vulnerability (CVE-2023-27532). The threat actor used tools such as the Bughatch downloader, Burntcigar antimalware killer, Metasploit, and Cobalt Strike, as well as various off-the-shelf tools.

White House pushes federal agencies to ramp up cybersecurity 

The White House has ordered federal agencies to ramp up their cybersecurity stance, after learning that, as of June 2023, many of them failed to comply with the security practices detailed in President Joe Biden’s Executive Order on Improving the Nation’s Cybersecurity. National security adviser Jake Sullivan asked department officials to ensure full compliance by year’s end, CNN reports

Related: In Other News: macOS Security Reports, Keyboard Spying, VPN Vulnerabilities

Related: In Other News: Cybersecurity Funding Rebounds, Cloud Threats, BeyondTrust Vulnerability

https://www.securityweek.com/in-other-news-us-hacking-china-unfixed-powershell-gallery-flaws-free-train-tickets/




Jenkins Patches High-Severity Vulnerabilities in Multiple Plugins

Open source software development automation server Jenkins this week announced patches for high- and medium-severity vulnerabilities impacting multiple plugins.

The patches address three high-severity cross-site request forgery (CSRF) and cross-site scripting (XSS) issues in the Folders, Flaky Test Handler, and Shortcut Job plugins.

Tracked as CVE-2023-40336, the first bug exists because no POST requests were required for an HTTP endpoint in version 6.846.v23698686f0f6 and earlier of the Folders plugin, leading to CSRF.

“This vulnerability allows attackers to copy an item, which could potentially automatically approve unsandboxed scripts and allow the execution of unsafe scripts,” Jenkins explains in an advisory.

The second high-severity bug, CVE-2023-40342, impacts Flaky Test Handler plugin versions 1.2.2 and earlier, which do not escape JUnit test contents when they are displayed in the Jenkins UI, allowing attackers to perform XSS attacks.

Shortcut Job plugin versions 0.4 and earlier do not escape the shortcut redirection URL, leading to an XSS flaw tracked as CVE-2023-40346.

Another high-severity XSS flaw was identified in Docker Swarm plugin versions 1.11 and earlier, which do not escape values returned from Docker before they are inserted into the Docker Swarm Dashboard view. However, no patch was released for this bug.

Advertisement. Scroll to continue reading.

Jenkins also announced fixes for medium-severity vulnerabilities in the Folders, Config File Provider, NodeJS, Blue Ocean, Fortify, and Delphix plugins.

According to the advisory, these flaws could lead to information disclosure, credential leaks, CSRF attacks, HTML injection, and credential ID enumeration.

Fixes were included in Blue Ocean version 1.27.5.1, Config File Provider version 953.v0432a_802e4d2, Delphix version 3.0.3, Flaky Test Handler version 1.2.3, Folders version 6.848.ve3b_fd7839a_81, Fortify version 22.2.39, NodeJS version 1.6.0.1, and Shortcut Job version 0.5.

Additionally, Jenkins warned that no patches have been released for three medium-severity flaws in the Maven Artifact ChoiceListProvider (Nexus), Gogs, and Favorite View plugins that could lead to credential exposure, information disclosure, and CSRF attacks.

The Tuleap Authentication plugin was updated to version 1.1.21 to resolve a low-severity vulnerability allowing attackers to obtain a valid authentication token.

Related: Jenkins Server Vulnerabilities Chained for Remote Code Execution

Related: Cisco Patches High-Severity Vulnerabilities in Enterprise Applications

Related: Ivanti Patches Critical Vulnerability in Avalanche Enterprise MDM Solution

https://www.securityweek.com/jenkins-patches-high-severity-vulnerabilities-in-multiple-plugins/




Companies Respond to ‘Downfall’ Intel CPU Vulnerability 

Several major companies have published security advisories in response to the recently disclosed Intel CPU vulnerability named Downfall. 

Discovered by Google researchers and officially tracked as CVE-2022-40982, Downfall is a side-channel attack method that allows a local attacker — or a piece of malware — to obtain potentially sensitive information such as passwords and encryption keys from the targeted device.

Cloud environments are also impacted and it may be possible to launch remote attacks via a web browser, but more research is needed to demonstrate such an attack. 

Intel Core and Xeon processors released over the past decade are impacted. The chip maker is releasing firmware updates, as well as mitigations, in response to the vulnerability.

The flaw impacts memory optimization features in Intel processors and the attack leverages two techniques dubbed Gather Data Sampling (GDS) and Gather Value Injection (GVI).

The GDS method has been described as “highly practical” and Google researchers created a proof-of-concept (PoC) exploit that can steal encryption keys from OpenSSL. 

Several organizations have released advisories in response to the Downfall vulnerability since its disclosure on August 8. 

Advertisement. Scroll to continue reading.

OpenSSL

The OpenSSL Project published a blog post this week pointing out that while the Downfall attack has been demonstrated against OpenSSL, it’s “highly general microarchitectural side-channel attack which can compromise the security of essentially any software”.

“Because OpenSSL provides accelerated implementations of many cryptographic primitives using x86 SIMD instructions, if an attacker executes an attack using this vulnerability on a process performing cryptographic operations using OpenSSL, there is an elevated risk that the information they are able to extract will include cryptographic key material or plaintexts, as this material is likely to have been recently processed in the victim process using SIMD instructions. In other words, the risk to key material or other cryptographic material is particularly high,” the OpenSSL Project explained. 

AWS, Microsoft Azure, Google Cloud

AWS said its customers’ data and cloud instances are not affected by Downfall and no action is required. The cloud giant did note that it has “designed and implemented its infrastructure with protections against this class of issues”.

Microsoft said it rolled out updates to its Azure infrastructure to patch the vulnerability. In most cases — except customers that have opted out of automatic updates — users do not need to take any action. 

Google Cloud also said no customer action is required. The company has applied available patches on its server fleet. However, some products require additional updates from its partners or vendors.

Cisco

Cisco said its UCS B-Series M6 blade servers and UCS C-Series M6 rack servers use Intel CPUs that are vulnerable to Downfall attacks. 

Citrix

Citrix has published an advisory informing customers that ​​CVE-2022-40982 only impacts Citrix Hypervisor when running on vulnerable Intel CPUs.

Dell

Dell has released BIOS patches for Alienware, ChengMing, G series, Precision, Inspiron, Latitude, OptiPlex, Vostro, and XPS computers.

HP

HP has started releasing SoftPaqs that address Downfall for its business and consumer PCs, workstations, and retail PoS systems. 

Lenovo

Lenovo has started releasing BIOS updates that address the vulnerability for its desktops (including all-in-one), notebooks, laptops, servers and appliances.  

NetApp

NetApp said multiple products incorporate Intel chips and it’s working on determining which of them are impacted. To date it has confirmed that some AFF and FAS storage systems are affected, but several products are still being analyzed.

OVH

The cloud giant OVH has confirmed that Downfall impacts OVHcloud products. The company has summarized the steps it has taken and the actions that administrators need to conduct in response to the vulnerability.  

SuperMicro

SuperMicro released a security bulletin to inform users about recent Intel firmware patches, including for Downfall, and said it has developed a BIOS update in response to the vulnerabilities. 

VMware

VMware informed customers that hypervisors may be affected by CVE-2022-40982 if they are using an impacted Intel CPU, but hypervisor patches are not needed to address the vulnerability. Instead, impacted customers need to obtain firmware updates from their hardware vendors.

Xen

Xen said all versions of its hypervisor are affected if running on devices with vulnerable Intel CPUs. In addition to recommending firmware updates from hardware vendors, the organization has provided mitigations, but warned that they could significantly impact performance. 

Linux distributions

Several Linux distributions have released advisories, patches and mitigations for systems using Intel processors. The list includes SUSE, CloudLinux, RedHat, Ubuntu and Debian.

https://www.securityweek.com/companies-respond-to-downfall-intel-cpu-vulnerability/




Google Brings AI Magic to Fuzz Testing With Eye-Opening Results

Google has sprinkled the magic of artificial intelligence into its open source fuzz testing infrastructure and the results suggest LLM (large language model) algorithms will radically alter the bug-hunting space.

Google added generative-AI technology to its OSS-FUZZ project (a free service that runs fuzzers for open source projects and privately alerts developers to the bugs detected) and discovered a massive improvement in code coverage when LLMs are used to create new fuzz targets.

“By using LLMs, we’re able to increase the code coverage for critical projects using our OSS-Fuzz service without manually writing additional code. Using LLMs is a promising new way to scale security improvements across the over 1,000 projects currently fuzzed by OSS-Fuzz and to remove barriers to future projects adopting fuzzing,” the company said in a note with results from a months-long experiment.

Fuzz testers, or fuzzers, are used in vulnerability research to pinpoint security vulnerabilities by sending random input to an application. If the program contains a vulnerability that leads to an exception, crash or server error, researchers can parse the results of the test to pinpoint the cause of the crash.

However, the art of fuzzing is heavily dependent on manual effort to write fuzz targets and functions to test sections of code, leading Google software engineers to test whether LLMs could be used to boost the effectiveness of the six-year-old OSS-Fuzz service.

The company said the OSS-Fuzz project has helped to find and verify fixes for more than 10,000 security bugs in open source software but researchers believed the tool could likely find even more bugs with increased code coverage. 

“The fuzzing service covers only around 30% of an open source project’s code on average, meaning that a large portion of our users’ code remains untouched by fuzzing,” Google said.

Advertisement. Scroll to continue reading.

To test whether an LLM could successfully write new fuzz targets, Google’s software engineers built an evaluation framework that connects OSS-Fuzz to its LLM to pinpoint under-fuzzed, high-potential portions of the sample project’s code for evaluation.

The company explained that the evaluation framework sitting between the OSS-Fuzz and the LLM then creates a prompt that the LLM will use to write the new fuzz target.  “At first, the code generated from our prompts wouldn’t compile, however after several rounds of prompt engineering and trying out the new fuzz targets, we saw projects gain between 1.5% and 31% code coverage,” the company said.

In one sample project — tinyxml2 — Google said code coverage improved from 38% to 69% without any interventions from humans. 

“The case of tinyxml2 taught us: when LLM-generated fuzz targets are added, tinyxml2 has the majority of its code covered,” the engineers said. “To replicate tinyxml2’s results manually would have required at least a day’s worth of work — which would mean several years of work to manually cover all OSS-Fuzz projects.”

During the experiment, Google said the LLM was able to automatically generate a working target that rediscovered CVE-2022-3602 (see OpenSSL advisory), which was in an area of code that previously did not have fuzzing coverage. “Though this is not a new vulnerability, it suggests that as code coverage increases, we will find more vulnerabilities that are currently missed by fuzzing,” Google added.

The company plans to open source the evaluation framework to allow researchers to test their own automatic fuzz target generation.  

Related: Microsoft Puts ChatGPT to Work on Automating Cybersecurity

Related: Cybersecurity Investors Pivot to Safeguarding AI Training Models

Related: ChatGPT Creator OpenAI Ready to Pay Hackers for Security Flaws

Related: OpenAI Unveils Million-Dollar Cybersecurity Grant Program

https://www.securityweek.com/google-brings-ai-magic-to-fuzz-testing-with-eye-opening-results/




Cisco Patches High-Severity Vulnerabilities in Enterprise Applications

Cisco on Wednesday announced security updates for several enterprise applications to patch high-severity vulnerabilities leading to privilege escalation, SQL injection, directory traversal, and denial-of-service (DoS).

The most severe of these impacts the web management interface of Cisco Unified Communications Manager (Unified CM) and Unified Communications Manager Session Management Edition (Unified CM SME).

Tracked as CVE-2023-20211 (CVSS score of 8.1), the bug is described as an improper validation of user-supplied input that could allow a remote, authenticated attacker to perform an SQL injection attack.

“An attacker could exploit this vulnerability by authenticating to the application as a user with read-only or higher privileges and sending crafted HTTP requests to an affected system. A successful exploit could allow the attacker to read or modify data in the underlying database or elevate their privileges,” Cisco explains.

Cisco addressed the flaw with the release of Unified CM and Unified CM SME versions 12.5(1)SU8 and also released a patch file for version 14 of the applications.

The tech giant warns that proof-of-concept (PoC) exploit code targeting the vulnerability has been released.

On Wednesday, Cisco also announced patches for CVE-2023-20224, an elevation of privilege bug in the ThousandEyes Enterprise Agent, Virtual Appliance installation type.

Advertisement. Scroll to continue reading.

Also rooted in the insufficient input validation of user-supplied input, the issue could allow an attacker to authenticate to an affected device via crafted commands. The attacker could then execute commands with root privileges.

The tech giant notes that the attacker must have valid credentials to exploit this vulnerability. The bug was addressed in ThousandEyes Enterprise Agent version 0.230.

While Cisco has not mentioned this, KoreLogic, the company whose researchers discovered the vulnerability, made public technical details this week.

Another insufficient input validation issue, this time in the Duo Device Health Application, could allow attackers to conduct directory traversal attacks and overwrite arbitrary files. Tracked as CVE-2023-20229, the flaw was resolved in version 5.2.0 of the application.

Cisco also announced patches for two DoS vulnerabilities in ClamAV, the free antimalware toolkit that the company included in Secure Endpoint Connectors for Linux, macOS, and Windows, and in Secure Endpoint Private Cloud.

The first of these, CVE-2023-20197, was identified in the filesystem image parser for Hierarchical File System Plus (HFS+) of ClamAV. PoC code targeting the bug has been released publicly, Cisco warns.

Cisco says it is not aware of any of these vulnerabilities being exploited in malicious attacks. However, users are advised to update their installations as soon as possible, as known vulnerabilities in Cisco appliances are often exploited in the wild.

Additional information on the addressed vulnerabilities can be found on Cisco’s product security page.

*updated the patched ThousandEyes Enterprise Agent version and added that KoreLogic has released technical details

Related: Critical Cisco SD-WAN Vulnerability Leads to Information Leaks

Related: Vulnerability in Cisco Enterprise Switches Allows Attackers to Modify Encrypted Traffic

Related: PoC Exploit Published for Cisco AnyConnect Secure Vulnerability

https://www.securityweek.com/cisco-patches-high-severity-vulnerabilities-in-enterprise-applications/




Exploitation of Citrix ShareFile Vulnerability Spikes as CISA Issues Warning 

Exploitation attempts targeting a remote code execution flaw in Citrix’s ShareFile product have spiked just as the US Cybersecurity and Infrastructure Security Agency (CISA) added it to its Known Exploited Vulnerabilities Catalog. 

The vulnerability affecting the ShareFile file sharing and collaboration product is tracked as CVE-2023-24489 and it has been assigned a ‘critical’ severity rating. It can allow an unauthenticated attacker to upload arbitrary files and possibly achieve remote code execution.

When details of the security hole were disclosed by Assetnote in early July — Assetnote researchers discovered the flaw — the company warned that there had been between 1,000 and 6,000 internet-exposed ShareFile instances. 

Citrix announced the availability of patches for CVE-2023-24489 on June 13 and exploitation started in late July, with threat intelligence firm GreyNoise seeing attack attempts coming from a handful of IP addresses.

CISA added CVE-2023-24489 to its Known Exploited Vulnerabilities Catalog on Wednesday, instructing government organizations to address it by September 6. On the same day, GreyNoise reported seeing a “huge spike” in exploitation attempts, coming from 72 unique IPs.  

It’s worth noting that GreyNoise has not recorded any other attacks between late July and now. 

It’s unclear what the attackers are trying to achieve, but Citrix vulnerabilities have been known to be exploited by both financially motivated cybercriminals and state-sponsored threat actors.   

Advertisement. Scroll to continue reading.

News of a spike in CVE-2023-24489 exploitation comes just days after NCC Group reported seeing 2,000 Citrix NetScaler instances that had been backdoored following exploitation of a recent vulnerability tracked as CVE-2023-3519. The flaw has been exploited since at least June, including against critical infrastructure organizations, when it still had a zero-day status. 

Related: Over 20,000 Citrix Appliances Vulnerable to New Exploit

https://www.securityweek.com/exploitation-of-citrix-sharefile-vulnerability-spikes-as-cisa-issues-warning/




Ivanti Patches Critical Vulnerability in Avalanche Enterprise MDM Solution

Ivanti has released patches for seven critical- and high-severity vulnerabilities in Avalanche, its enterprise mobile device management (MDM) solution.

The most severe of the flaws is CVE-2023-32563 (CVSS score of 9.8), a directory traversal bug that can be exploited to execute arbitrary code remotely.

Reported by security researchers with Trend Micro’s ZDI, the issue exists in the ‘updateSkin’ method of the MDM solution and can be exploited without authentication.

“The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of System,” ZDI’s advisory reads.

The latest Avalanche iteration also resolves multiple stack-based buffer overflow bugs that are collectively tracked as CVE-2023-32560 (CVSS score of 8.8).

The vulnerability resides in Wavelink Avalanche Manager, which uses a fixed-size stack-based buffer when processing certain types of data, explained Tenable, whose researchers discovered the issue.

An unauthenticated, remote attacker can trigger the vulnerability by sending a crafted message to the service, which could lead to service disruption or code execution.

Advertisement. Scroll to continue reading.

Two other high-severity remote code execution vulnerabilities were patched with the latest Avalanche release, both discovered and reported through ZDI.

The flaws, CVE-2023-32562 and CVE-2023-32564, are the result of a “lack of proper validation of user-supplied data”, allowing an attacker to upload arbitrary files and potentially execute code with System privileges.

All three remaining vulnerabilities – CVE-2023-32561, CVE-2023-32565, and CVE-2023-32566 – are described as authentication bypass flaws in various components of the MDM solution.

Ivanti patched all seven vulnerabilities in Avalanche version 6.4.1.207, which was released earlier this month. Both Tenable and ZDI, however, released details on these vulnerabilities only this week.

While there’s no mention of any of these issues being exploited in the wild, vulnerabilities in Ivanti products are known to have been targeted in malicious attacks.

Related: Exploitation of Ivanti EPMM Flaw Picking Up as New Vulnerability Is Disclosed

Related: Ivanti Zero-Day Vulnerability Exploited in Attack on Norwegian Government

Related: Five Eyes Agencies Call Attention to Most Frequently Exploited Vulnerabilities

https://www.securityweek.com/ivanti-patches-critical-vulnerability-in-avalanche-enterprise-mdm-solution/