Fortinet Patches Critical FortiOS Vulnerability Leading to Remote Code Execution

Fortinet on Tuesday announced security updates that address a critical-severity vulnerability in FortiOS and FortiProxy that could be exploited for remote code execution (RCE).

Tracked as CVE-2023-33308 (CVSS score of 9.8), the bug is described as a stack-based overflow issue impacting the deep inspection function in proxy mode.

“A stack-based overflow vulnerability in FortiOS & FortiProxy may allow a remote attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection,” Fortinet explains in an advisory.

Because the issue only occurs if deep inspection is enabled on proxy policies or firewall policies with proxy mode, disabling the function prevents exploitation, the cybersecurity firm explains.

The vulnerability impacts FortiOS and FortiProxy versions 7.2.x and 7.0.x and was resolved in FortiOS versions 7.4.0, 7.2.4, and 7.0.11, and FortiProxy versions 7.2.3 and 7.0.10.

Fortinet noted that the bug was addressed in a previous release, without an advisory.

On Tuesday, the company also announced patches for a medium-severity FortiOS vulnerability that could allow an attacker to reuse a deleted user’s session.

Advertisement. Scroll to continue reading.

Tracked as CVE-2023-28001, the flaw exists because an “existing websocket connection persists after deleting API admin”.

“An insufficient session expiration vulnerability in FortiOS REST API may allow an attacker to reuse the session of a deleted user, should the attacker manage to obtain the API token,” Fortinet explains.

The vulnerability impacts FortiOS versions 7.2.x and 7.0.x and was addressed in FortiOS version 7.4.0.

Fortinet users are advised to apply the patches as soon as possible. Unpatched Fortinet products are known to have been exploited in malicious attacks.

Related: Fortinet Patches Critical RCE Vulnerability in FortiNAC

Related: Fortinet Patches Critical FortiGate SSL VPN Vulnerability

Related: Fortinet Patches Critical Vulnerability in Data Analytics Solution

https://www.securityweek.com/fortinet-patches-critical-fortios-vulnerability-leading-to-remote-code-execution/




Microsoft Warns of Office Zero-Day Attacks, No Patch Available

Russian spies and cybercriminals are actively exploiting still-unpatched security flaws in Microsoft Windows and Office products, according to an urgent warning from the world’s largest software maker.

In an unusual move, Microsoft documented “a series of remote code execution vulnerabilities” impacting Windows and Office users and confirmed it was investigating multiple reports of targeted code execution attacks using Microsoft Office documents.

Redmond’s security response pros tagged the unpatched Office flaws with the CVE-2023-36884 identifier and hinted that an out-of-band patch may be released before next month’s Patch Tuesday.

From the CVE-2023-36884 bulletin:

“Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents.

An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file.

Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This might include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.”

Advertisement. Scroll to continue reading.

In a separate blog, Microsoft’s threat intelligence team said it flagged a phishing campaign with Office zero-day exploits targeting defense and government entities in Europe and North America. “The campaign involved the abuse of CVE-2023-36884, which included a remote code execution vulnerability exploited via Microsoft Word documents, using lures related to the Ukrainian World Congress,” the company warned.

The Microsoft Office zero-day headlines a monster Patch Tuesday that sees the release of patches for more than 130 documented security defects in the Microsoft Windows ecosystem.

According to data from ZDI, a company that tracks software patches, nine of the flaws are rated ‘critical’, Microsoft’s highest severity rating.

“This volume of fixes is the highest we’ve seen in the last few years,” ZDI noted, warning that at least five bugs are listed in the “exploitation-detected” category.

Software maker Adobe also shipped urgent patches for security flaws in the InDesign and ColdFusion product lines.

The Adobe InDesign update, available for Windows and macOS, fixes a critical-severity code execution flaw and 11 additional memory safety bugs that cause memory leak issues. Adobe credited Yonghui Han of Fortinet’s FortiGuard Labs with privately reporting the bugs.

A second security bulletin was also released with patches for a trio of security defects affecting  Adobe ColdFusion versions 2023, 2021 and 2018.

“These updates resolve critical and important vulnerabilities that could lead to arbitrary code execution and security feature bypass,” Adobe said, calling special attention to CVE-2023-29300, a deserialization of untrusted data bug with a CVSS severity score of 9.8 out of 10. Earlier this year, Adobe disclosed “limited attacks” exploiting a ColdFusion zero-day vulnerability. 

Related: Apple Ships Urgent iOS Patch for WebKit Zero-Day

Related: Adobe Patch Tuesday: Critical Flaws Haunt InDesign, ColdFusion

Related: ICS Patch Tuesday: Siemens, Schneider Electric Fix 50 Vulnerabilities

Related: Zero-Day Attacks, MOVEit Turns to Security Service Packs

https://www.securityweek.com/microsoft-warns-of-office-zero-day-attacks-no-patch-available/




Adobe Patch Tuesday: Critical Flaws Haunt InDesign, ColdFusion

Software maker Adobe on Tuesday called attention to critical security flaws in its InDesign and ColdFusion products, warning that the defects expose users to malicious hacker attacks.

The company’s scheduled July Patch Tuesday rollout includes fixes for a dozen documented vulnerabilities in Adobe InDesign, including a bug serious enough to lead to arbitrary code execution attacks.

The Adobe InDesign update, available for Windows and macOS, fixes a critical-severity code execution flaw and 11 additional memory safety bugs that cause memory leak issues. Adobe credited Yonghui Han of Fortinet’s FortiGuard Labs with privately reporting the bugs.

A second security bulletin was also released with patches for a trio of security defects affecting  Adobe ColdFusion versions 2023, 2021 and 2018.

“These updates resolve critical and important vulnerabilities that could lead to arbitrary code execution and security feature bypass,” Adobe said, calling special attention to CVE-2023-29300, a deserialization of untrusted data bug with a CVSS severity score of 9.8 out of 10.

Earlier this year, Adobe disclosed “limited attacks” exploiting a ColdFusion zero-day vulnerability. 

Related: Apple Ships Urgent iOS Patch for WebKit Zero-Day

Advertisement. Scroll to continue reading.

Related: Adobe Warns of Attacks Exploiting ColdFusion Zero-Day

Related: Patch Tuesday: Critical Flaws in ColdFusion, Adobe Commerce

Related: Decade-Old ColdFusion Bugs Exploited by Ransomware Gang

https://www.securityweek.com/adobe-patch-tuesday-critical-flaws-haunt-indesign-coldfusion/




Apple Ships Urgent iOS Patch for WebKit Zero-Day

Apple on Monday rolled out an urgent software update to its iOS and iPadOS mobile operating systems and warned that zero-day exploitation has already been detected.

For the second time since adopting the “rapid security responses” process to address zero-day attacks, Apple pushed iOS 16.5.1 (a) and iPadOS 16.5.1 (a) to devices globally after an anonymous researcher disclosed the underlying vulnerability.

A barebones advisory from Cupertino said the security defect exists in WebKit, the browser engine used by Safari, Mail, AppStore and many other apps on iOS- and macOS-powered devices.

“Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited,” the company said. “The issue was addressed with improved checks.”

The vulnerability has been tagged as CVE-2023-37450.

So far in 2023, there have been 41 publicly documented cases of zero-day attacks with more than one-fifth (22 percent) affecting software code on Apple devices.

Related: Problems Installing Apple’s First iOS Rapid Security Response Patch 

Advertisement. Scroll to continue reading.

Related: Apple Ships Urgent iOS Patch for Exploited Zero-Days

Related: Apple Fixes Exploited Zero-Day With iOS 16.1 Patch

Related: Apple Says WebKit Zero-Day Hitting iOS, macOS Devices

https://www.securityweek.com/apple-ships-urgent-ios-patch-for-webkit-zero-day/




Exploit Code Published for Remote Root Flaw in VMware Logging Software

Virtualization technology giant VMware on Monday warned that exploit code has been publicly released for a pre-authentication remote code execution flaw in its enterprise-facing VMware Aria Operations for Logs product.

In an update to a critical-level advisory originally released in April this year, VMware said it has confirmed that exploit code for CVE-2023-20864 has been published, underscoring the urgency for enterprise network admins to apply available patches.

The vulnerability, which carries a CVSS severity score of 9.8 out of 10, allows an unauthenticated, malicious actor with network access to VMware Aria Operations to execute arbitrary code as root, VMware said in its documentation of the CVE-2023-20864 flaw.

VMware Aria Operations for Logs, (formerly vRealize Log Insight), is a centralized log management tool that promises operational visibility and analytics for troubleshooting and auditing data flowing through private, hybrid and multi-cloud environments.

VMware’s security troubles with the vRealize Logging product line are well known. The company has patched several high-severity issues in the past and confirmed the release of exploit code targeting known software bugs.

The VMWare vRealize product has also been featured in the CISA KEV (Known Exploited Vulnerabilities) must-patch catalog.

Related: VMware Patches Pre-Auth Code Execution Flaw

Advertisement. Scroll to continue reading.

Related: VMware Fixes VM Escape Flaw Exploited at Geekpwn

Related: VMware Confirms Exploit Code for Critical vRealize Flaws

Related: VMware Plugs High-Severity Bugs in vRealize Operations

https://www.securityweek.com/exploit-code-published-for-remote-root-flaw-in-vmware-logging-software/




PoC Exploit Published for Recent Ubiquiti EdgeRouter Vulnerability

A recently patched vulnerability in Ubiquiti EdgeRouter and AirCube devices could be exploited to execute arbitrary code, vulnerability reporting firm SSD Secure Disclosure warns.

Tracked as CVE-2023-31998, the issue is described as a heap overflow vulnerability that can be exploited over a LAN connection.

According to Ubiquiti, an attacker exploiting this bug may interrupt UPnP service to a vulnerable device.

An SSD Secure Disclosure advisory notes that the vulnerability resides in the MiniUPnPd service of the impacted devices and that LAN attackers may exploit it “to overflow an internal heap and potentially execute arbitrary code”.

SSD Secure Disclosure, which provides technical details on the vulnerability itself, reveals that proof-of-concept (PoC) code targeting the issue is also available, but that it targets the bug on Ubiquiti EdgeRouterX devices, which are also impacted.

According to the firm, the issue was resolved in MiniUPnPd, but no CVE identifier was released for it. Vulnerable versions of MiniUPnPd may have been shipped with other networking devices as well.

“It is likely that other products relying either directly on upstream MiniUPnPd, or on router distribution such as OpenWrt, VyOS or DD-WRT still ship today with vulnerable MiniUPnPd,” SSD Secure Disclosure notes.

Advertisement. Scroll to continue reading.

At the end of June, Ubiquiti announced the release of software updates for the impacted UPnP-enabled EdgeRouter (firmware version 2.0.9-hotfix.7) and AirCube (firmware version 2.8.9) devices.

Although there is no indication that the vulnerability has been exploited in attacks, Ubiquiti users are advised to update their devices as soon as possible.

Related: Former Ubiquiti Employee Who Posed as Hacker Sentenced to Prison

Related: Flaw Possibly Affecting 500,000 Ubiquiti Devices Exploited in the Wild

Related: Critical Flaw Exposes Many Ubiquiti Devices to Attacks

https://www.securityweek.com/poc-exploit-published-for-recent-ubiquiti-edgerouter-vulnerability/




Critical Vulnerability Can Allow Takeover of Mastodon Servers

A critical vulnerability in the decentralized social networking platform Mastodon could be exploited to take over servers.

The issue was disclosed last week, when Mastodon announced patches for five vulnerabilities in the open source software, including two rated ‘critical’.

The most important of these is CVE-2023-36460 (CVSS score of 9.9), an arbitrary file creation issue that could lead to complete server compromise.

“Using carefully crafted media files, attackers can cause Mastodon’s media processing code to create arbitrary files at any location. This allows attackers to create and overwrite any file Mastodon has access to, allowing denial-of-service and arbitrary remote code execution,” Mastodon notes in an advisory.

According to security researcher Kevin Beaumont, the vulnerability allows attackers to send a toot (short-form status messages) to achieve a webshell on the Mastodon instance that processes it.

Beaumont has dubbed the vulnerability TootRoot, as its exploitation could provide attackers with root access to Mastodon servers.

The second critical-severity flaw, tracked as CVE-2023-36459, is described as a cross-site scripting (XSS) issue that allows attackers to bypass HTML sanitization via carefully crafted oEmbed data.

Advertisement. Scroll to continue reading.

“This introduces a vector for cross-site-scripting (XSS) payloads that can be rendered in the user’s browser when a preview card for a malicious link is clicked through,” Mastodon explains.

Of the remaining three bugs addressed in Mastodon last week, two are high-severity vulnerabilities leading to denial-of-service (DoS) and information leaks, while the third is a medium-severity flaw allowing attackers to create visually misleading links for phishing.

All five vulnerabilities were resolved with the release of Mastodon versions 4.1.3, 4.0.5, and 3.5.9. All administrators are advised to update their Mastodon instances as soon as possible.

“I’ve done some surveying and a significant percentage of instances haven’t patched, and this one is very likely to see in-the-wild exploitation. Widespread exploitation across many instances is as simple as sending a single toot,” Beaumont warns.

Introduced in 2016 and offering Twitter-like microblogging features, the open source software supports self-hosted social networking services running on independently run nodes, known as Mastodon instances.

Users can choose which Mastodon instance they want to be members of but, since the nodes operate as a federated social network, users can interact with members of other instances as well. Tracking data shows there are over 12,000 Mastodon instances, hosting roughly eight million users.

The platform has gained significant traction since 2022, as Twitter’s acquisition by Elon Musk sparked concerns.

Related: Critical Vulnerabilities Force Twitter Alternative Hive Social Offline

Related: Security Researchers Looking at Mastodon as Its Popularity Soars

Related: Recently Disclosed Vulnerability Exploited to Hack Hundreds of SugarCRM Servers

https://www.securityweek.com/critical-vulnerability-can-allow-takeover-of-mastodon-servers/




MOVEit app mass-exploited last month patches new critical vulnerability

Stylized photo of desktop computer.

MOVEit, the file-transfer software exploited in recent weeks in one of the biggest cyberattacks ever, has received yet another security update that fixes a critical vulnerability that could be exploited to give hackers access to vast amounts of sensitive data.

On Thursday, MOVEit maker Progress Software published a security bulletin that included fixes for three newly discovered vulnerabilities in the file-transfer application. The most serious of them, tracked as CVE-2023-36934, allows an unauthenticated attacker to gain unauthorized access to the application database. It stems from a security flaw that allows for SQL injection, one of the oldest and most common exploit classes.

The vulnerability contains the same elements—and, likely, the same potentially devastating consequences—as one that came to light in late May when members of the Clop ransomware crime syndicate began mass-exploiting it on vulnerable networks around the world. To date, the Clop offensive has hit 229 organizations and spilled data affecting more than 17 million people, according to statistics tracked by Brett Callow, an analyst with security firm Emsisoft. Casualties include Louisiana and Oregon DMVs, the New York City Department of Education, and energy companies Schneider Electric and Siemens Electric.

There are no known reports of the new vulnerability coming under active exploitation, but given its severity and past experience, Progress Software and security practitioners are urging all MOVEit users to install it right away. Besides CVE-2023-36934, Thursday’s security update patches two additional vulnerabilities. All of them were discovered by security firms HackerOne and Trend Micro.

Developers, meet Bobby Tables

One thing that makes CVE-2023-36934 and the earlier vulnerability exploited by Clop so critical is that they can be exploited by people when they’re not even logged in to the system they’re hacking. Both also stem from bugs that allow for SQL injection, a vulnerability class with a long history of abuse. Often abbreviated as SQLi, it stems from a failure by a web application to properly query backend databases. SQL syntax uses apostrophes to indicate the beginning and end of a data string. The apostrophes allow SQL parsers to distinguish between data strings and database commands.

Improperly written web apps can sometimes interpret inputted data as commands. Hackers can exploit these mistakes by entering strings that include apostrophes or other special characters into web fields that cause backend databases to do things the developers never intended to do. These sorts of attacks have formed the basis for some of the biggest compromises in history. Besides the recent Clop spree, two other notable examples include the 2007 hack of Heartland Payment Systems that allowed convicted hacker Albert Gonzalez to make off with data for 130 million credit cards and the 2011 compromise of HBGary.

SQL injection is the topic of an xkcd cartoon featuring Bobby Tables, a student whose full name is “Robert’); DROP TABLE Students;–?” (without the quotation marks). When the school computer system tries to process his name, it interprets only “Robert” as data and processes the “DROP TABLE” as the dangerous SQL command to delete data. As a result, the school loses an entire year’s worth of records.

A second vulnerability fixed in Thursday’s MOVEit security update is also the result of SQLi bugs. Progress Software said it “could allow an authenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content.”

The third vulnerability fixed, CVE-2023-36933, allows hackers to terminate the MOVEit application unexpectedly. The latter two vulnerabilities carry a severity described as high.

The vulnerabilities affect multiple MOVEit Transfer versions, from 12.0.x to 15.0.x. Given the damage that resulted from Clop’s mass exploitation of the earlier MOVEit vulnerability, the latest patches should be installed as soon as possible. Sorry, admins, but if that requires working late on a Friday or over the weekend, that’s the better option than waking up to a world of hurt on Monday morning. https://arstechnica.com/?p=1952233




After Zero-Day Attacks, MOVEit Turns to Security Service Packs

Faced with a barrage of ransomware attacks hitting zero-days in its MOVEit product line, Progress Software late Thursday announced plans to release regular service sacks promising a “predictable, simple and transparent process for product and security fixes.”

Less than a month after the notorious Cl0p ransomware gang started naming organizations hit by MOVEit zero-day exploits, Progress Software rolled out its first service pack with patches for at least three critical security defects that expose customer database content to malicious attackers.

“We have heard from you that a regular cadence and predictable timeline will enable you to better plan your resources and make it easier to adopt new product updates and fixes. As a part of these Service Packs, we will also be optimizing the installation process to make the upgrade process simpler,” Progress said in a note posted with the first service pack.

Software vendors typically use a service pack to deliver a collection of updates, fixes, features or enhancements to an application.  Service packs are delivered in the form of a single installable package.

Progress Software said the service packs would apply to its MOVEit products, including MOVEit Transfer and MOVEit Automation.

The initial service pack provides cover for CVE-2023-36934, a critical-severity bug in the Progress MOVEit Transfer tool.  The company described it as a SQL injection vulnerability that allows an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. 

“An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content,” the company said of the most serious bug.

The service pack also includes patches for CVE-2023-36932, which covers multiple high-severity Progress MOVEit Transfer  vulnerabilities that allows authenticated attackers to gain unauthorized access to the MOVEit Transfer database. “An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content,” Progress said.

Advertisement. Scroll to continue reading.

Progress Software also included a fix for CVE-2023-36933, a high-severity bug that allows an attacker to invoke a method which results in an unhandled exception.  “Triggering this workflow can cause the MOVEit Transfer application to terminate unexpectedly.”

Related: MOVEit Users Urged to Patch Third Critical Vulnerability

Related: Ransomware Group Naming Victims of MOVEit Zero-Days

Related: New MOVEit Flaws Found as Attack Victims Come Forward

https://www.securityweek.com/after-zero-day-attacks-moveit-turns-to-security-service-packs/




In Other News: Healthcare Product Flaws, Free Email Security Testing, New Attack Techniques

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:

Details disclosed for unauthenticated RCE vulnerability in IBM i DDM 

Silent signal has disclosed the technical details of CVE-2023-30990, a vulnerability in IBM i’s distributed data management (DDM) service, which allows an unauthenticated, remote attacker to execute arbitrary code. IBM has patched the flaw. 

Details disclosed for Siemens vulnerabilities that could threaten power grids

Advertisement. Scroll to continue reading.

SEC Consult has published a technical advisory for several vulnerabilities affecting Siemens’ Sicam A8000 remote terminal units (RTUs), including a critical flaw that could allow malicious hackers to destabilize a power grid.

Vulnerability in Medtronic cardiac device data management product

CISA and healthcare technology firm Medtronic have informed users about the existence of a critical vulnerability affecting Medtronic’s Paceart Optima cardiac device data management product. Exploitation can lead to DoS attacks or remote code execution. The vendor has released a patch and there is no evidence of exploitation in the wild. 

ImmuniWeb adds email security test to its free product

Web security firm ImmuniWeb has added email security testing to its free product, which also includes cloud security, mobile app security, dark web exposure, SSL security, and website security testing. 

Tool for sending phishing messages to Teams users

A member of the US Navy’s Red Team has released an open source tool named TeamsPhisher that allows users to bypass security features and deliver phishing messages and attachments to Microsoft Teams users whose organizations allow external communications. Microsoft does not seem too concerned, pointing out that social engineering is involved. 

Chinese APT targeting European government entities

Check Point has a report on a campaign dubbed SmugX. The campaign is the work of a Chinese threat actor targeting foreign and domestic policy-focused government entities in Europe. The attackers have exploited HTML smuggling to deliver malware. 

Silentbob’s cloud attack delivering cryptominer

Cloud security firm Aqua Security has detailed a campaign it has linked to TeamTNT, a threat group known for targeting cloud and container environments to deploy cryptocurrency miners. The campaign is in its early stages, with infrastructure being prepared for a worm-like expansion across misconfigured Docker APIs and JupyterLAb instances. 

Malicious NPM packages used in supply chain and phishing attacks

ReversingLabs has discovered over a dozen malicious packages in the NPM repository, which were used to power both phishing attacks and software supply chain compromises. Some of the packages supported the harvesting of Microsoft credentials, while others would implant credential harvesting scripts in software. Mimicking legitimate NPM modules, the malicious packages were published between May 11 and June 13.

AI-generated books flood Amazon

A flurry of AI-generated ebooks flooded Amazon, taking the spotlight in the detriment of real, legit books. Described as ‘nonsensical and incoherent’, these books could potentially facilitate click-farming, generating illicit revenue – Amazon Kindle Unlimited pays authors by the number of pages read — and also raise concerns of quality control and authenticity.

Related: In Other News: Hospital Infected via USB Drive, EU Cybersecurity Rules, Free Security Tools

Related: In Other News: Microsoft Win32 App Isolation, Tsunami Hits Linux Servers, ChatGPT Credentials Exposed on Dark Web

https://www.securityweek.com/in-other-news-healthcare-product-flaws-free-email-security-testing-new-attack-techniques/