Apple Patches iOS Flaws Used in Kaspersky ‘Operation Triangulation’ 

Apple has rolled out a major security-themed iOS update to fix remote code execution vulnerabilities that have already been exploited in the wild.

The patches address a pair of vulnerabilities reported by Russian anti-malware vendor Kaspersky and follow the public documentation of ‘Operation Triangulation,’ a digital spy campaign that used zero-click iMessage exploits.

The patches – iOS 16.5.1, iPadOS 16.5.1, iOS 15.7.7 and iPadOS15.7.7 – cover security defects in kernel and WebKit and have been exploited remotely via maliciously rigged web content.

Apple described the exploited bugs as memory corruption issues in the kernel (CVE-2023-32434 – allows an app to execute arbitrary code with kernel privileges); and WebKit (CVE-2023-32435 – code execution via web content).

The company fixed the same issue in the newest version (iOS 16.5.1), but noted that the attacks have only been seen on devices running versions of iOS released before iOS 15.7. Patches for macOS and watchOS were also released.

Apple’s attribution of these vulnerabilities to Kaspersky comes just two weeks after the Russian cybersecurity firm said it discovered an APT actor launching zero-click iMessage exploits on iOS-powered devices in its corporate network.

Kaspersky’s disclosure came on the same day Russia’s Federal Security Service (FSB) blamed US intelligence agencies for an ongoing spy campaign targeting thousands of iOS devices belonging to domestic subscribers and foreign diplomatic missions.

Advertisement. Scroll to continue reading.

The FSB, the Russian security agency that succeeded the Soviet KGB, said iPhones belonging to diplomats from NATO countries, China, Israel and Syria were infected as part of an alleged “reconnaissance operation by American intelligence services.”

Kaspersky calls the campaign Operation Triangulation and has published additional technical documentation on the spyware used in the attacks.

Related: Kaspersky Dissects Spyware Used in iOS Zero-Click Attacks

Related: Russia Blames US Intelligence for iOS Zero-Click Attacks

Related: NSO Group Used at Least 3 iOS Zero-Click Exploits in 2022

Related: Apple Rolls Out Zero-Day Patches to Older iOS, macOS Devices

https://www.securityweek.com/apple-patches-ios-flaws-used-in-kaspersky-operation-triangulation/




Critical WordPress Plugin Vulnerabilities Impact Thousands of Sites

Web application security firm Defiant warns of critical-severity authentication bypass vulnerabilities in two WordPress plugins with tens of thousands of installations.

The first security defect, tracked as CVE-2023-2986 (CVSS score of 9.8/10), impacts the Abandoned Cart Lite for WooCommerce, a plugin that notifies customers who did not complete the purchase process, and which has more than 30,000 active installations.

In the notification sent, the user is provided with a link that automatically logs them in to continue their purchase, and which contains an encrypted value that identifies the cart.

Because the encryption key used to create the encrypted value is hardcoded in the plugin and because each cart identifier is a sequentially increasing number, an attacker can use the encryption key to create identifiers of other users’ carts.

A successful attack can only be performed against abandoned carts and will likely allow an attacker to log in as customer-level users. However, the attacker may also access administrator-level accounts that are testing the abandoned cart functionality, potentially leading to full site compromise, according to an advisory from Defiant.

The issue has been patched in Abandoned Cart Lite for WooCommerce version 5.15.1, which was released on June 13. Based on WordPress statistics, tens of thousands of websites have not yet applied the fix.

On Tuesday, Defiant also raised an alarm on a critical-severity vulnerability – CVE-2023-2834 (CVSS severity score 9.8/10) – in BookIt, a WordPress plugin with more than 10,000 active installations.

Advertisement. Scroll to continue reading.

The plugin provides a short code to embed an appointment booking calendar into WordPress sites’ pages, allowing users to book appointments by providing their name, email address, and password.

Due to insufficient checks of the user supplied input when booking appointments using the plugin, an unauthenticated attacker can log in as any existing user, if the attacker knows the user’s email address.

Specifically, the plugin verifies the user ID based on the provided email address and, if that email belongs to an existing user account, it associates the request to that account and sets the authentication cookies for it, without performing password verification. “The vulnerability makes it possible for an attacker to gain access to any account on the site, including the administrator account, if the attacker knows their email address,” Defiant added.

The flaw was patched in BookIt version 2.3.8, on June 13. WordPress stats show that thousands of websites are still running a vulnerable version of the plugin.

Related: Millions of WordPress Sites Patched Against Critical Jetpack Flaw

Related: 1 Million WordPress Sites Impacted by Exploited Plugin Bug

Related: Critical WooCommerce Payments Flaw Leads to Site Takeover

https://www.securityweek.com/critical-wordpress-plugin-vulnerabilities-impact-thousands-of-sites/




Enphase Ignores CISA Request to Fix Remotely Exploitable Flaws

The US Cybersecurity and Infrastructure Security Agency (CISA) this week issued advisories detailing two unpatched vulnerabilities in Enphase products.

An American energy technology company, Enphase builds and sells solar micro-inverters, charging stations, and other energy equipment, mainly focused on residential customers.

On Tuesday, CISA published two ICS advisories to warn of vulnerabilities in Enphase products that could lead to information leaks or command execution. Both are said to be remotely exploitable with low attack complexity.

Tracked as CVE-2023-32274 (CVSS score of 8.6), the first of the flaws impacts the Enphase Installer Toolkit, a mobile solution that aids with the installation and configuration of Enphase Systems.

The application also allows users to connect to the Enphase Envoy communication gateway over wireless networks to perform system setups, and allows them to view system status.

CISA warns that Enphase Installer Toolkit for Android versions 3.27.0 and older contain hardcoded credentials that an attacker could use to gain access to sensitive data.

“Successful exploitation of this vulnerability could allow sensitive information to be obtained by an attacker using hard-coded credentials,” CISA notes.

Advertisement. Scroll to continue reading.

The Enphase Installer Toolkit is currently available for download as version 3.30.0 for both Android and iOS.

The second issue, CVE-2023-33869, is described as a command injection flaw in the Envoy communication gateway version D7.0.88, which could allow an attacker to gain root access to the affected product and execute commands.

According to CISA, Enphase Energy has not responded to requests to work with the agency in addressing these vulnerabilities. Both issues were reported by a security researcher using only the handle ‘OBSWCY3F’.

Update: After SecurityWeek published this story and contacted Enphase for comment, the company responded late Wednesday afternoon to say it has now been in touch with CISA.

“Enphase Energy is in direct contact with CISA and committed to quickly addressing any potential vulnerabilities,” a company spokesperson told SecurityWeek. “Enphase maintains a strong focus on cybersecurity to protect our customers in an increasingly interconnected, data-driven, and modern energy landscape. With positive customer experience at the center, we aim to create and provide high-quality products and services that meet the highest security standards”

Related: CISA Instructs Federal Agencies to Secure Internet-Exposed Devices

Related: CISA: Several Old Linux Vulnerabilities Exploited in Attacks

https://www.securityweek.com/enphase-ignores-cisa-request-to-fix-remotely-exploitable-flaws/




Chrome and Its Vulnerabilities – Is the Web Browser Safe to Use?

Like all major applications, Google’s Chrome suffers from vulnerabilities. During 2022, SecurityWeek reported on 456 vulnerabilities (averaging 38 per month), including nine zero-days. The high number of flaws needing to be patched poses a simple question: is Chrome safe to use?

This high rate of vulnerability disclosures and patches has continued into 2023. Chrome 109 patched 17 and six vulnerabilities in January. Chrome 110 patched 15 vulnerabilities in February; version 111 patched 40 and 8 in March; and version 112 patched 16 in April. April also saw a patch for the second zero-day vulnerability of 2023. Chrome 113 patched 15 vulnerabilities in May, followed by a further 12 vulnerabilities. June started with the third of 2023’s zero-day patches, in Chrome 114, and this was followed by a further 5 patches.

The list is so long it almost becomes boringly repetitive – but it will undoubtedly continue growing through the rest of the year and beyond. The questions raised, however, are not boring. Why are there so many vulnerabilities? Is Chrome realistically safe to use? Can Google do anything to make the product safer? Can users do anything to increase their safety? SecurityWeek talked to Tal Zamir, the CTO at Tel Aviv, Israel-based Perception Point (a detection and response vendor covering major threat surfaces including browsers).

The primary reason for the number of vulnerabilities is basically just statistics. It’s a combination of the size of the codebase, the attraction of the target, and the number of people who use it. “Over the years, Chrome has grown into a huge codebase – almost an operating system like Windows in its size, because it has so many features under the hood,” said Zamir. 

“It might look simple – you think, hey, it’s just a browser application. But in practice, it’s a monster. It’s an application that people use most of the time, most of the day, both in the enterprise and in the consumer space. This is what we use for most of our activities online,” he added.

The larger the codebase, the greater the number of vulnerabilities. That’s a reality of computing. The more an application is used, the greater the number of attackers looking for ways to attack it. This will include both criminals and nation states and is again inescapable. It’s worth noting that according to Statcounter (May 2023), Chrome had a 62.87% share of the global browser market. Safari was second with 20.7%, while Edge came in third with just 5.32%.

We cannot expect Google to do more to secure its code. This again is an inescapable feature of business life. Google would have to reduce both the quantity and speed with which it introduces new features, and that goes against the grain of ensuring and perhaps increasing market share. Microsoft has always been in catch-up mode for browsers, but now there is a full-fledged battle over the best (that is, most profitable) integration of AI into their products.

Advertisement. Scroll to continue reading.

“Microsoft is giving Google a real fight,” said Zamir. “This is especially in the enterprise space but also for consumers who are tempted to go with the Microsoft bundles. I predict that it will become even harder for Google to fight and keep its first place in the browser space. In this fight, it will add new features and try to innovate even faster. When you do this, you typically put security as a secondary consideration. Speed is the need – you need to be in front of the users with shiny new things, and security might lag. It doesn’t mean that Google will neglect security. It definitely invests in the security of Chrome – but I think security will be secondary to the new features.”

Where Google cannot be criticized is over its reactive approach to Chrome security. The policy is to seek (by its own research teams and bug bounty program), and then remedy and patch vulnerabilities before they can be abused by attackers.

This is a reactive rather than proactive approach. While Google itself is largely forced by business realities to be reactive on security – and most companies are in the same position – the user can take a more proactive approach. This inevitably involves the addition of specialist security products, such as that from Perception Point, to protect the application and its use.

This raises one further question – if small security firms can protect Chrome, why cannot Google (one of the largest developers in the world) develop similar protection inside Chrome? “Google definitely could,” said Zamir, “if it was willing to invest many years of engineering.” 

Technically, it is possible, but economically it is infeasible. We come back to the ‘shiny new thing’ image. For Chrome, the shiny new things are the additional features that make it attractive to users. Invisibly embedded complex security controls do not qualify as shiny new things, so will always be pushed down the priority line. But for a third party security vendor, security is the shiny thing.

This is the reality of modern cybersecurity. You cannot assume that any application is secure or that the app vendor will keep you safe. All users must take their own responsibility for the security of the products they use. Google Chrome is the unlucky example we chose for this discussion – but the principles will apply to almost all commercial applications.

Related: Google Attempts to Explain Surge in Chrome Zero-Day Exploitation

Related: Google Pays $45,000 for High-Severity Vulnerabilities Found in Chrome

Related: Researcher Says Google Paid $100k Bug Bounty for Smart Speaker Vulnerabilities

https://www.securityweek.com/chrome-and-its-vulnerabilities-is-the-web-browser-safe-to-use/




Researchers Flag Account Takeover Flaw in Microsoft Azure AD OAuth Apps

Researchers at security startup Descope have discovered a major misconfiguration in Microsoft Azure AD OAuth applications and warned that any business using ‘Log in with Microsoft’ could be exposed to full account takeover exploits.

The security defect, nicknamed nOAuth, is described as an authentication implementation flaw that can affect Microsoft Azure AD multi-tenant OAuth applications. 

According to an advisory documenting the issue, Descope noted that a malicious actor can modify email attributes in Microsoft Azure AD accounts and exploit the one-click “Log in with Microsoft” feature with the email address of any victim they want to impersonate. 

“In usual OAuth and OpenID Connect implementations, the user’s email address is used as the unique identifier by applications. However, in Microsoft Azure AD, the “email” claim returned is mutable and unverified so it cannot be trusted,” Descope explained.

The company said the combined effect allows an attacker that created their Azure AD tenant to use “Log in with Microsoft” with a vulnerable app and a specially crafted “victim” user, resulting in a complete account takeover. Descope released a demo video showing the simplicity of potential exploitation.

Descope, a startup in the customer identity space, reported the issue to Microsoft earlier this year and worked with Redmond on new mitigations to protect businesses from privilege escalation attacks.

Microsoft described the issue as “an insecure anti-pattern used in Azure AD (AAD) applications” where use of the email claim from access tokens for authorization can lead to an escalation of privilege. 

Advertisement. Scroll to continue reading.

“An attacker can falsify the email claim in tokens issued to applications. Additionally, the threat of data leakage exists if applications use such claims for email lookup,” Microsoft acknowledged.  

“Microsoft recommends never using the email claim for authorization purposes. If your application uses the email claim for authorization or primary user identification purposes, it is subject to account and privilege escalation attacks,” the software giant said.

Microsoft is also urging developers to review the authorization business logic of their applications and follow documented guidance to protect applications from unauthorized access.  

Related: Descope Targets Customer Identity Market with Massive $53M Seed Round

Related: Microsoft Warns of High-Severity Vulnerability in Azure AD

Related: Microsoft Fixes Privilege Escalation Flaw in Azure AD Connect

Related: Microsoft Patches Azure Cosmos DB Code Execution Flaw

https://www.securityweek.com/researchers-flag-account-takeover-flaw-in-microsoft-azure-ad-oauth-apps/




Asus Patches Highly Critical WiFi Router Flaws

Taiwanese computer hardware manufacturer Asus on Monday shipped urgent firmware updates to address vulnerabilities in its WiFi router product lines and warned users of the risk of remote code execution attacks.

In an advisory, Asus documented at least nine security defects and multiple security weaknesses that allow code execution, denial-of-service, information disclosure and authentication bypasses.

The most serious of the nine vulnerabilities, a highly critical bug with a CVSS severity rating of 9.8/10, dates back to 2018 and exposes routers to code execution attacks.

The vulnerability, tagged as CVE-2018-1160, is a memory corruption issue in Netatalk before 3.1.12. “This is due to lack of bounds checking on attacker-controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution,” according to the advisory.

The Asus firmware update also patches CVE-2022-26376 (CVSS 9.8/10), a memory corruption vulnerability in the httpd unescape functionality of Asuswrt prior to 3.0.0.4.386_48706 and Asuswrt-Merlin New Gen prior to 386.7.

“A specially-crafted HTTP request can lead to memory corruption. An attacker can send a network request to trigger this vulnerability,” Asus confirmed.

The company, which has struggled with security problems in the past, listed the affected WiFi routers as Asus GT6, GT-AXE16000, GT-AX11000 PRO, GT-AX6000, GT-AX11000, GS-AX5400, GS-AX3000, XT9, XT8, XT8 V2, RT-AX86U PRO, RT-AX86U, RT-AX86S, RT-AX82U, RT-AX58U, RT-AX3000, TUF-AX6000 and TUF-AX5400.

Advertisement. Scroll to continue reading.

“If you choose not to install this new firmware version, we strongly recommend disabling services accessible from the WAN side to avoid potential unwanted intrusions. These services include remote access from WAN, port forwarding, DDNS, VPN server, DMZ, port trigger,” the company cautioned.

Asus is also strongly recommending that its users “periodically audit both your equipment and your security procedures” to stave off a wave of malware attacks targeting router infrastructure.

“Update your router to the latest firmware. We strongly recommend that you do so as soon as new firmware is released,” the company said, adding that users should set up up separate passwords wireless network and router-administration pages

Related: Supply-Chain Attack Used to Install Backdoors on ASUS Computers

Related: Severe Vulnerabilities Allow Hacking of Asus Gaming Router

Related: Chinese UEFI Rootkit Found on Gigabyte and Asus Motherboards

https://www.securityweek.com/asus-patches-highly-critical-wifi-router-flaws/




Western Digital Blocks Unpatched Devices From Cloud Services

Western Digital has blocked access to its cloud services for devices running firmware versions impacted by a known and critical security vulnerability.

The move, which began on June 15, comes one month after the company released firmware updates for its My Cloud product line to address multiple security defects, including a critical path traversal bug that leads to remote code execution (RCE).

The issue is tracked as CVE-2022-36327 and carries CVSS severity score of 9.8/10. According to a NIST advisory, the flaw “could allow an attacker to write files to locations with certain critical filesystem types.”

The flaw impacts Western Digital’s My Cloud Home, My Cloud Home Duo, SanDisk ibi, and My Cloud OS 5 devices and requires the attackers to first trigger an authentication bypass vulnerability.

On May 15, Western Digital released My Cloud OS 5 firmware version 5.26.202 to resolve this bug and three other medium-severity issues, including an uncontrolled resource consumption flaw leading to denial-of-service (DoS), a path traversal issue leading to sensitive information disclosure, and a server-side request forgery (SSRF) bug leading to the exploitation of other vulnerabilities.

On May 26, the company released firmware version 9.4.1-101 to resolve the SSRF bug in My Cloud Home, My Cloud Home Duo, and SanDisk ibi devices.

Starting June 15, devices running firmware versions prior to 5.26.202 or 9.4.1-101 can no longer connect to Western Digital cloud services, the company notes in an advisory.

Advertisement. Scroll to continue reading.

While My Cloud OS 5 users can still access their data on these devices locally, My Cloud Home, My Cloud Home Duo, and SanDisk ibi users will not be able to access their data until they update their devices to the latest firmware release, the company explains.

By blocking unpatched devices from accessing My Cloud services, Western Digital essentially prevents them from falling victim to cyberattacks that could potentially lead to severe data compromise.

Related: Western Digital Confirms Ransomware Group Stole Customer Information

Related: Western Digital Shuts Down Services Due to Cybersecurity Breach

Related: Western Digital Finds Replay Attack Protection Flaw Affecting Multiple Vendors

https://www.securityweek.com/western-digital-blocks-unpatched-devices-from-cloud-services/




MOVEit Customers Urged to Patch Third Critical Vulnerability

Progress Software is urging MOVEit customers to apply patches to a third critical vulnerability in the file transfer software in less than one month.

Tracked as CVE-2023-35708, the latest vulnerability is described as an SQL injection flaw that could allow an unauthenticated attacker to escalate privileges and access the MOVEit Transfer database.

“An attacker could submit a crafted payload to a MOVEit Transfer application endpoint which could result in modification and disclosure of MOVEit database content,” Progress explains in an advisory.

The vulnerability impacts MOVEit Transfer versions before 2021.0.8 (13.0.8), 2021.1.6 (13.1.6), 2022.0.6 (14.0.6), 2022.1.7 (14.1.7), and 2023.0.3 (15.0.3). 

Proof-of-concept (PoC) code targeting the bug was released on June 15, prompting swift response from Progress, which notes that the bug was made public “in a way that did not follow normal industry standards”. 

CVE-2023-35708 is the third critical SQL injection flaw that Progress patches in its MOVEit products in roughly three weeks, after a zero-day vulnerability was disclosed on May 31 and a second critical bug patched a week later.

The first issue, CVE-2023-34362, started being widely exploited in late May, but security researchers found evidence suggesting that exploitation may have started two years ago.

Advertisement. Scroll to continue reading.

More than 100 organizations have been impacted by attacks targeting the MOVEit zero-day, with the recent campaign attributed to the Cl0p ransomware gang, which has started publicly naming some of the victims.

Known victims to date include the U.S. Department of Energy, Louisiana’s Office of Motor Vehicles, Oregon’s Department of Transportation, the Nova Scotia government, British Airways, the British Broadcasting Company, Aer Lingus, U.K. drugstore chain Boots, University of Rochester, the Illinois Department of Innovation & Technology (DoIT), and the Minnesota Department of Education (MDE).

Victims are in Austria, France, Germany, Luxembourg, the Netherlands, Switzerland, the UK, and the US. Most of the victims are in the US, Malwarebytes notes.

The second issue, CVE-2023-35036, was disclosed on June 9, but does not appear to have been exploited in the wild. Progress says it has no evidence that CVE-2023-35708 has been exploited either, but urges customers to apply the latest patches as soon as possible.

“All MOVEit Transfer customers must take action and apply the patch to address the June 15th CVE-2023-35708 vulnerability discovered in MOVEit Transfer,” the company underlines.

To prevent unauthorized access to the MOVEit Transfer environment, customers should disable HTTP and HTTPS traffic – allowing for localhost access only – apply the available patches (the June 15th patch also resolves the previous vulnerabilities), and then re-enable HTTP and HTTPS traffic.

Progress has released both DLL drop-in patches and full MOVEit Transfer installers to resolve the bugs. Additional instructions on applying the patches can be found in the company’s advisory.

Related: Chrome 114 Update Patches Critical Vulnerability

Related: Fortinet Patches Critical FortiGate SSL VPN Vulnerability

Related: Cisco Patches Critical Vulnerability in Enterprise Collaboration Solutions

https://www.securityweek.com/moveit-customers-urged-to-patch-third-critical-vulnerability/




SquareX Launches Bug Bounty Program for Browser Security Product

Hot on the heels of a $6 million seed funding round, cybersecurity startup SquareX today announced a six-week bug bounty program focused on its new cloud-based browser security solution.

Integrating with the browser as an extension, the solution protects users from malware and also allows them to remain private online, through temporary containers that SquareX calls ‘disposable browsers’.

Headless browsers running in data centers, these containers keep users safe from threats when they check emails, stream content, create documents, or access banking and ecommerce accounts.

Singapore-based SquareX has made its solution available in beta to a limited number of users and is now looking for help in identifying and squashing security bugs in its product as it is gearing up for the official launch.

Running from June 15 to July 27, the bug bounty program welcomes hackers, security researchers, and the wider community to test the browser-based solution and report any security defects that might emerge.

As part of the program, SquareX promises a total of $25,000 in bug bounty rewards to the reporting researchers.

The highest payout is $2,000, for critical-severity vulnerabilities. Reporting researchers may earn $1,000 for high-severity issues, $500 for medium-severity bugs, and $100 for low-severity flaws.

Advertisement. Scroll to continue reading.

Within the scope of the program, SquareX lists the malware.rip and malwareriplabs.com websites and subdomains, along with the Disposable File Viewer launched via malware.rip.

Reports are accepted for container escapes, internet access within the container, flaws allowing access to other user sessions, attacks on Kubernetes, and bugs allowing extended lifetime of the container.

The reports, the company says, should include information on the impacted web application, a description of the flaw and its impact, steps to replicate the issue, proof-of-concept code, and screenshots or video recordings of the problem.

Reporting researchers may also need to provide copies of an identity card and PayPal account details, when asked.

Additional information can be found on the bug bounty program’s web page.

Related: Adobe Inviting Researchers to Private Bug Bounty Program

Related: Google Launches Bug Bounty Program for Mobile Applications

Related: QNAP Offering $20,000 Rewards via New Bug Bounty Program

https://www.securityweek.com/squarex-launches-bug-bounty-program-for-browser-security-product/




Microsoft Patches Critical Windows Vulns, Warns of Code Execution Risks

Microsoft’s security response team on Tuesday rolled out a massive batch of software updates to address major security gaps in its flagship Windows operating system and software components.

Redmond’s monthly Patch Tuesday updates cover at least 70 documented vulnerabilities affecting the Windows ecosystem, including six critical issues that expose users to dangerous code execution attacks.

According to Microsoft, none of the vulnerabilities have been publicly discussed or exploited in the wild.

Windows network administrators are being urged to pay special attention to a trio of highly critical bugs in Windows Pragmatic General Multicast (PGM), the protocol used  to deliver packets between multiple network members in a reliable manner.

All three Windows Pragmatic General Multicast (PGM) vulnerabilities carry a CVSS severity score of 9.8/10 and can be exploited by a remote, unauthenticated attacker to execute code on an affected system.

The three high-severity bugs are tracked as CVE-2023-29363, CVE-2023-32014 and CVE-2023-32015.

“This is the third month in a row for PGM to have a CVSS 9.8 bug addressed, and it’s beginning to be a bit of a theme,” said Trend Micro’s ZDI, an outfit that closely tracks vulnerability warnings.  “While not enabled by default, PGM isn’t an uncommon configuration. Let’s hope these bugs get fixed before any active exploitation starts.”

Advertisement. Scroll to continue reading.

Security experts are also highlighting CVE-2023-32021, a remote code execution bug in Microsoft Exchange Server that allows attackers to bypass issues that were previous exploited in the wild.

“While this does require the attacker to have an account on the Exchange server, successful exploitation could lead to executing code with SYSTEM privileges,” ZDI explained.

The June patch batch also includes a fix for CVE-2023-3079, a type confusion flaw in Chrome (Chromium) that has already been exploited in malware attacks.

The Microsoft patches come on the same day Adobe released patches for critical flaws in multiple products, including a dozen issues that expose Adobe Commerce users to code execution attacks.

Adobe documented at least 12 security problems in the widely deployed Adobe Commerce (formerly Magento) product and warned that successful exploitation could lead to arbitrary code execution, security feature bypass and arbitrary file system read. A critical-severity bulletin from Adobe said the Magento Open Source product is also vulnerable to the documented issues.

Adobe said it was not aware of any exploits in the wild for any of the issues addressed in this month’s updates.       

Related: Microsoft Patch Tuesday: 40 Vulnerabilities, 2 Zero-Days

Related: Adobe Inviting Researchers to Private Bug Bounty Program

Related: Microsoft Plugs Windows Hole Used in Ransomware Attacks

Related: Adobe Patches Gaping Security Holes in Reader, Acrobat

https://www.securityweek.com/microsoft-patches-critical-windows-vulns-warn-of-code-execution-risks/