SAP Patches Critical Vulnerabilities With May 2023 Security Updates

German enterprise software maker SAP this week announced the release of 18 new security notes on its May 2023 Security Patch Day, including two ‘hot news’ notes that deal with critical vulnerabilities.

One of the hot news notes resolves five vulnerabilities in the Reprise License Manager (RLM) 14.2 component of SAP 3D Visual Enterprise License Manager.

The most severe of these issues is CVE-2021-44152 (CVSS score of 9.8), an improper authentication/authorization check that could allow an unauthenticated attacker to change the password of any user account.

“This allows an attacker to change the password of any known user, thereby preventing valid users from accessing the system and granting the attacker full access to that user’s account,” a NIST advisory reads.

Of the remaining four bugs, three are high-severity and one is medium-severity.

Manually disabling the affected RLM web interface should resolve the issue, enterprise security firm Onapsis explains.

The second hot news security note released on SAP’s May 2023 Security Patch Day addresses multiple information disclosure vulnerabilities in the BusinessObjects Intelligence Platform, which are collectively tracked as CVE-2023-28762 (CVSS score of 9.1).

Advertisement. Scroll to continue reading.

The most severe of these flaws allows an attacker logged in as administrator to retrieve the login token of any logged-in user or server, without user interaction. This allows the attacker to impersonate any user on the platform to access and modify data and make the system partially or entirely unavailable.

The security note, Onapsis explains in its analysis of the SAP patches, replaces five security notes released in 2022 to address the information disclosure bugs in BusinessObjects, all of which were updated on Tuesday.

SAP released seven new ‘high priority’ notes this week, to resolve vulnerabilities in NetWeaver, IBP Excel add-in, PowerDesigner (Proxy), Commerce, GUI for Windows, and SAPUI5. Seven medium-priority and two low-priority notes were also released on Tuesday.

According to Onapsis, one other security note that SAP has updated this month – but which is not mentioned in the company’s release notes – brings the latest patches for the Chromium browser included in Business Client.

This update is not surprising, considering that Google resolved two zero-day vulnerabilities in Chrome only a few weeks ago.

Related:SAP Patches Critical Vulnerabilities in Diagnostics Agent, BusinessObjects

Related: SAP Releases Five ‘Hot News’ Notes on March 2023 Patch Day

Related:SAP’s February 2023 Security Updates Patch High-Severity Vulnerabilities

https://www.securityweek.com/sap-patches-critical-vulnerabilities-with-may-2023-security-updates/




Microsoft Patch Tuesday: 40 Vulnerabilities, 2 Zero-Days

Microsoft on Tuesday announced patches for 40 newly documented vulnerabilities in its products, including two zero-day flaws.

One of the zero-days, CVE-2023-29336, is described as an elevation of privilege bug in the Win32k driver. Successful exploitation could allow an attacker to gain System privileges.

Microsoft has shared no information on the attacks exploiting this vulnerability, but such issues are typically combined with code execution flaws to spread malware, according to Trend Micro’s Zero Day Initiative (ZDI), which published a summary of the patches. 

Reported by Avast, CVE-2023-29336 impacts systems running Windows 10 and Windows Server 2008, 2012, and 2016.

Reported by ESET and SentinelOne researchers, the second zero-day, CVE-2023-24932, is described as a Secure Boot security feature bypass that could allow an attacker with physical access or administrative privileges to execute self-signed code at the UEFI level.

The issue has been exploited by the BlackLotus UEFI bootkit that first emerged in October 2022, and which can disable security applications and other defense mechanisms on vulnerable machines.

Addressing CVE-2023-24932, Microsoft says, requires revoking boot managers, an irreversible action that could cause issues for some boot configurations.

Advertisement. Scroll to continue reading.

Microsoft’s May 2023 update does not provide a full patch for the vulnerability, but represents the first step in resolving the issue. Automated deployment of the revocation files will be added on July 2023 Patch Tuesday and the revocations will be enforced starting with the first quarter of the next year.

“The May 9, 2023 security update provides configuration options to manually enable protections for the Secure Boot bypass but these protections are not enabled automatically. Before you enable these protections, you must verify your devices and all bootable media are updated and ready for this security hardening change,” the tech giant explains in a knowledge base article.

Some of the critical vulnerabilities patched with Microsoft’s latest updates include remote code execution flaws in Windows Network File System (CVE-2023-24941), Windows Pragmatic General Multicast (CVE-2023-24943), and Windows OLE (CVE-2023-29325).

The tech giant also resolved CVE-2023-24955, a remote code execution flaw in SharePoint Server that was disclosed by the Star Labs team at the Pwn2Own Vancouver 2023 exploit contest.

Microsoft’s May 2023 Patch Tuesday updates address other elevation of privilege and remote code execution bugs, along with information disclosure, denial-of-service, and security feature bypass flaws.

In addition to the 40 Microsoft-specific vulnerabilities, the release notes mention nine Chrome security defects that the tech giant is now addressing in the Chromium-based Edge browser.

Related:Adobe Patches 14 Vulnerabilities in Substance 3D Painter

Related: ICS Patch Tuesday: Siemens, Schneider Electric Address Few Dozen Vulnerabilities

Related:Microsoft Patch Tuesday: 97 Windows Vulns, 1 Exploited Zero-Day

https://www.securityweek.com/microsoft-patch-tuesday-40-vulnerabilities-2-zero-days/




Adobe Patches 14 Vulnerabilities in Substance 3D Painter

Adobe has announced security updates for its Substance 3D Painter product to address more than a dozen vulnerabilities. This is the only product for which the software giant released updates this Patch Tuesday.

According to Adobe, the 3D painting software, specifically version 8.3.0 and earlier, is impacted by 14 vulnerabilities. 

A vast majority are high-severity (‘critical’ based on Adobe’s severity ratings) memory-related vulnerabilities that can be exploited for arbitrary code execution in the context of the targeted user. Some of the less severe issues can result in memory leaks. 

There is no indication that these flaws have been exploited in the wild. The priority rating assigned by the company also suggests that they are unlikely to ever be exploited for malicious purposes.

All of the vulnerabilities were reported to Adobe by researcher Mat Powell through Trend Micro’s Zero Day Initiative (ZDI). 

Powell recently also found similar vulnerabilities in Adobe’s Substance 3D Designer and Substance 3D Stager. Those vulnerabilities were patched by the vendor in April and March, and ZDI has already made public advisories for each security bug. 

The ZDI advisories show that the flaws can be exploited by an attacker by tricking the targeted user into opening a specially crafted file. The same attack vector likely applies to the Substance 3D Painter vulnerabilities as well.

Advertisement. Scroll to continue reading.

Adobe is running a private, invite-only bug bounty program on HackerOne, but researchers interested in helping the company find vulnerabilities in its products can contact Adobe’s security team and provide their HackerOne handle. 

Related: Adobe Acrobat Sign Abused to Distribute Malware

Related: Adobe Warns of ‘Very Limited Attacks’ Exploiting ColdFusion Zero-Day

Related: Adobe Plugs Critical Security Holes in Illustrator, After Effects Software

https://www.securityweek.com/adobe-patches-14-vulnerabilities-in-substance-3d-painter/




Vulnerability in Field Builder Plugin Exposes Over 2M WordPress Sites to Attacks

A cross-site scripting (XSS) vulnerability in the Advanced Custom Fields WordPress plugin could be exploited to inject malicious scripts into websites.

Tracked as CVE-2023-30777, the vulnerability impacts both the free and paid versions of the plugin. Advanced Custom Fields has more than 2 million installs via the official WordPress app store.

The plugin provides site administrators with the ability to easily add fields to WordPress edit screens, posts, pages, and other site elements.

Identified by Patchstack security researcher Rafie Muhammad, CVE-2023-30777 is described as a high-severity reflected XSS bug impacting the plugin’s admin page.

“This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site,” Patchstack notes in an advisory.

The flaw was identified in a function configured as an extra handler for a WordPress hook that has the same name, and which controls the CSS classes for the main body tag in the admin area.

The root cause of the issue is an improper sanitization of output value of the hook, which could lead to XSS if the function handler fails to properly sanitize the returned classes string.

Advertisement. Scroll to continue reading.

According to Patchstack, the vulnerability can be triggered on default plugin installations, either by unauthenticated attackers or by logged-in users with access to the plugin.

The security defect was identified on May 2 and reported to the vendor the same day. A patch was released two days later.

Advanced Custom Fields version 6.1.6 addresses the vulnerability for both free and paid customers. The fix was also included in version 5.12.6 of the plugin.

Users are advised to update their installations as soon as possible. Unpatched WordPress plugins are often exploited in malicious attacks to take over sites and infect their visitors with malware.

Related:Abandoned WordPress Plugin Abused for Backdoor Deployment

Related:Elementor Pro Plugin Vulnerability Exploited to Hack WordPress Websites

Related: Vulnerability in Popular Real Estate Theme Exploited to Hack WordPress Websites

https://www.securityweek.com/vulnerability-in-field-builder-plugin-exposes-over-2m-wordpress-sites-to-attacks/




Fortinet Patches High-Severity Vulnerabilities in FortiADC, FortiOS

Fortinet this week announced its monthly set of security updates that address nine vulnerabilities in multiple products, including two high-severity bugs in FortiADC, FortiOS, and FortiProxy.

Impacting the FortiADC application delivery controller, the most severe of these issues is tracked as CVE-2023-27999 and is described as “an improper neutralization of special elements used in an OS command vulnerability”.

An attacker could exploit the bug via crafted arguments to existing commands, allowing them to execute unauthorized commands. The attacker needs to be authenticated to exploit the vulnerability.

The issue impacts FortiADC versions 7.2.0, 7.1.1, and 7.1.0, and was addressed with the release of FortiADC versions 7.2.1 and 7.1.2.

The second high-severity flaw, CVE-2023-22640, is described as an out-of-bounds write in the sslvpnd component of FortiOS and FortiProxy.

The bug allows an authenticated attacker to send specifically crafted requests to achieve arbitrary code execution, Fortinet explains.

The bug was identified in FortiOS versions 7.2.x, 7.0.x, 6.4.x 6.2.x, and 6.0.x, and FortiProxy versions 7.2.x, 7.0.x, 2.0.x, and 1.x.x. It was addressed with the release of FortiOS versions 7.4.0, 7.2.4, 7.0.11, 6.4.12, and 6.2.14, and in FortiProxy versions 7.2.2 and 7.0.8.

Advertisement. Scroll to continue reading.

This week, Fortinet also released patches for medium-severity flaws in FortiNAC and FortiADC, including hard-coded credentials, improper neutralization of input, path traversal, and weak authentication issues. Multiple low-severity bugs in FortiNAC were also addressed.

Additional information on the resolved vulnerabilities can be found on Fortinet’s PSIRT advisories page.

Fortinet makes no mention of any of these vulnerabilities being exploited in malicious attacks. However, flaws in unpatched Fortinet products are known to be exploited and customers are advised to apply the available security updates as soon as possible.

Related: Fortinet Patches Critical Vulnerability in Data Analytics Solution

Related: Exploitation of Recent Fortinet Zero-Day Linked to Chinese Cyberspies

Related: Fortinet Finds Zero-Day Exploit in Government Attacks After Devices Detect Integrity Breach

https://www.securityweek.com/fortinet-patches-high-severity-vulnerabilities-in-fortiadc-fortios/




Azure API Management Vulnerabilities Allowed Unauthorized Access 

Three vulnerabilities in the Azure API Management service could be exploited to perform various types of malicious actions, cloud security company Ermetic reveals.

A fully managed platform, the Azure API Management service allows organizations to manage, analyze, and secure APIs across environments, making them available to developers, employees, and partners.

The identified vulnerabilities, two server-side request forgery (SSRF) bugs and one file upload path traversal flaw, were the result of URL formatting bypasses and an unrestricted file upload feature. All three have been fully patched, Ermetic says.

Successful exploitation of these vulnerabilities could have allowed an attacker to access internal Azure assets, bypass web application firewalls, cause a denial-of-service (DoS) condition, and upload malicious files to internal servers. 

The first of the SSRF bugs was a bypass of a patch for a different SSRF vulnerability in API Management that Microsoft addressed last year.

The issue existed in the ‘Import from URL’ feature enabling the use in APIs of a schema from a URL. To retrieve the schema, the Azure API Management CORS Proxy sends an HTTP request to the specified URL.

By manipulating values in the request, the researchers were able to bypass the existing SSRF protections and access Azure internal services via a redirect bypass.

Advertisement. Scroll to continue reading.

The second bug was identified in the Azure API Management hosting proxy, where policies for inbound and outbound API processing are set.

Before being sent to the specified backend, requests sent from a specified frontend are first sent to the inbound processing proxy, which allows for a SSRF attack by setting the ‘set-backend-service’ policy to the desired SSRF location.

According to Ermetic, the vulnerability allowed it to access an internal HTTP port 80, at which point Microsoft was informed of the findings.

The third vulnerability was identified in the Azure developer portal for the API Management service, which allows authenticated users to upload files and images and which has a self-hosting feature.

“We found that Azure does not validate the file type and path of the files uploaded. Authenticated users can traverse the path specified when uploading the files, upload malicious files to the developer portal server and possibly execute code on it using DLL hijacking, iisnode config swapping or any other relevant attack vector,” Ermetic explains.

During their investigation, Ermetic’s security researchers cloned their self-hosted API management instance and managed to traverse and drop unwanted files on their system.

Related: Microsoft Azure Users Warned of Potential Shared Key Authorization Abuse

Related: Severe Azure Vulnerability Led to Unauthenticated Remote Code Execution

Related: CSRF Vulnerability in Kudu SCM Allowed Code Execution in Azure Services

https://www.securityweek.com/azure-api-management-vulnerabilities-allowed-unauthorized-access/




Android Security Update Patches Kernel Vulnerability Exploited by Spyware Vendor

Google’s Android security updates for May 2023 patch more than 40 vulnerabilities, including a kernel flaw exploited as a zero-day by a spyware vendor. 

The latest Android updates patch vulnerabilities in the framework, system, kernel, Arm, Imagination Technologies, MediaTek, Unisoc, and Qualcomm components. 

A vast majority of the security holes have been assigned a ‘high severity’ rating and they can be exploited for privilege escalation, DoS attacks, and information disclosure. 

The vulnerability that was exploited as a zero-day is tracked as CVE-2023-0266 and it has been described by Google as a moderate-severity kernel flaw that can be exploited for local privilege escalation without user interaction. An entry in NIST’s National Vulnerability Database describes it as a high-severity use-after-free in the Linux kernel’s ALSA PCM package.

Exploitation of the vulnerability was first mentioned by Google in late March, when the company described several Android and iOS zero-day vulnerabilities whose exploitation had been linked to commercial spyware vendors.

In the case of CVE-2023-0266, it was used as part of an exploit chain involving several vulnerabilities, including ones impacting Chrome and the Mali GPU kernel driver. The attackers delivered the exploits as links sent to the targeted individual via SMS. The hackers actually targeted the Samsung Internet Browser, which is based on Chromium but lacks some of the important mitigations present in Chrome. 

The targets were users in the United Arab Emirates and the attackers’ goal was to deliver full-featured Android spyware to their devices. The attacks are believed to have been carried out by a customer or partner of a Spanish spyware vendor named Variston, whose activities were brought to light by the tech giant in November 2022. 

Advertisement. Scroll to continue reading.

CVE-2023-0266 was also added in late March to the Known Exploited Vulnerabilities Catalog maintained by the US Cybersecurity and Infrastructure Security Agency (CISA). 

According to data from Google, three Android vulnerabilities that came to light this year have been exploited in attacks. 

Google this week also released a security update for its Pixel phones to patch a couple of vulnerabilities. CVE-2023-0266 was patched in Pixel devices in April. 

Related: Google, CISA Warn of Android Flaw After Reports of Chinese App Zero-Day Exploitation

Related: Android’s April 2023 Updates Patch Critical Remote Code Execution Vulnerabilities

Related: Google Patches Android Zero-Day Exploited in Targeted Attacks

https://www.securityweek.com/android-security-update-patches-kernel-vulnerability-exploited-by-spyware-vendor/




Cisco Warns of Critical Vulnerability in EoL Phone Adapters

Cisco this week raised the alarm on a critical remote code execution (RCE) vulnerability impacting SPA112 2-Port phone adapters, which have reached end-of-life (EoL) status.

Tracked as CVE-2023-20126 (CVSS score of 9.8), the flaw impacts the web-based management interface of the phone adapters and can be exploited without authentication.

The issue, Cisco explains in its advisory, exists because of “a missing authentication process within the firmware upgrade function”.

To exploit the bug, a remote attacker needs to upgrade a device to a crafted firmware version, which would allow them to execute arbitrary code with full privileges.

Given that the SPA112 2-Port phone adapters are no longer supported (they reached EoL on June 1, 2020), Cisco does not plan to release firmware updates to address the vulnerability.

Instead, the tech giant recommends that customers migrate to an ATA 190 Series analog telephone adapter.

Cisco says it is not aware of the vulnerability being exploited in malicious attacks. However, unpatched, vulnerable Cisco devices are known to have been exploited in the wild and organizations should consider eliminating the SPA112 2-Port phone adapters from their environments as soon as possible.

Advertisement. Scroll to continue reading.

Related: Cisco Working on Patch for Vulnerability Reported by NATO Pentester

Related: Cisco Patches Critical Vulnerabilities in Industrial Network Director, Modeling Labs

Related: US, UK: Russia Exploiting Old Vulnerability to Hack Cisco Routers

Related: Cisco Patches Code and Command Execution Vulnerabilities in Several Products

https://www.securityweek.com/cisco-warns-of-critical-vulnerability-in-eol-phone-adapters/




Apple Releases First-Ever Security Updates for Beats, AirPods Headphones

Apple has released the first-ever security updates for its Beats and AirPods products to patch a vulnerability that can be exploited to gain access to headphones through a Bluetooth attack.

The flaw is tracked as CVE-2023-27964 and it was reported to Apple by Yun-hao Chung and Archie Pusaka of Google ChromeOS. The vulnerability has been described as an authentication issue.

“When your headphones are seeking a connection request to one of your previously paired devices, an attacker in Bluetooth range might be able to spoof the intended source device and gain access to your headphones,” Apple explained in its advisory.

The firmware update for AirPods (5E133), including the Pro and Max models, was made available on April 11, while the Beats firmware update (5B66), including for Powerbeats Pro and Beats Fit Pro, was released on May 2. 

Firmware updates are delivered automatically to AirPods and Beats headphones while they are charging and in Bluetooth range of the user’s iPhone, iPad, or Mac. Users can check on these devices if their headset is running the latest firmware version.

The availability of the Beats firmware update was announced just as Apple and Google proposed a standard aimed at preventing devices that rely on Bluetooth for location tracking from being misused to track people. 

Devices such as Apple’s AirTag are useful for finding lost or stolen property, but the product can also be abused by stalkers. The tech giants want manufacturers to implement mechanisms that would make it possible to easily detect unwanted tracking. 

Advertisement. Scroll to continue reading.

Related: Apple Patches Actively Exploited WebKit Zero-Day Vulnerability 

Related: Apple Patches Exploited iOS Vulnerability in Old iPhones

Related: iOS Security Update Patches Exploited Vulnerability in Older iPhones

Related: Apple Ships Urgent iOS Patch for Newly Exploited Zero-Days

https://www.securityweek.com/apple-releases-first-ever-security-updates-for-beats-airpods-headphones/




Exploitation of BGP Implementation Vulnerabilities Can Lead to Disruptions

A widely used BGP implementation is affected by three vulnerabilities that can be exploited to cause disruption through denial-of-service (DoS) attacks, according to cybersecurity firm Forescout.

The Border Gateway Protocol (BGP) plays an important role in the way the internet works. It serves as the main routing protocol, allowing autonomous systems (AS) — networks or network groups that have a unified routing policy — to exchange information on routing and reachability.

BGP was not designed with security in mind and it can be abused to redirect traffic for malicious purposes. In addition, BGP incidents can lead to widespread disruption. 

While BGP itself has long been found to be insecure, Forescout researchers decided to also analyze various projects that implement BGP. They have analyzed the open source tools FRRouting, BIRD and OpenBGPd, as well as the closed source software Mikrotik RouterOS, Juniper JunOS, Cisco IOS and Arista EOS.

On Tuesday, the company revealed that FRRouting (FFR), which implements BGP and various other internet routing protocols, is affected by three vulnerabilities that can be exploited for DoS attacks. 

According to its website, FFR is used by ISPs, SaaS infrastructure, web 2.0 businesses, hyperscale services, and Fortune 500 private clouds.

The security holes are tracked as CVE-2022-40302, CVE-2022-40318 and CVE-2022-43681, and they have been described as out-of-bounds read issues related to the processing of malformed BGP OPEN messages. 

Advertisement. Scroll to continue reading.

The developer was informed about the vulnerabilities and released patches.

“Two of these issues (CVE-2022-40302 and CVE-2022-43681) can be triggered before FRRouting validates BGP Identifier and ASN fields. While FRRouting only allows connections between configured peers by default (e.g., OPEN messages from hosts not present in the config files will not be accepted), in this case attackers only need to spoof a valid IP address of a trusted peer,” Forescout explained. 

“Another possibility for the attacker is to take advantage of misconfigurations or attempt to compromise a legitimate peer by exploiting other vulnerabilities. Similar DoS vulnerabilities in FRRouting have already caused notable disruptions, and they must be fixed,” the company added.

Alongside its findings, Forescout has released an open source tool that organizations can use to test the security of internally used BGP suites. The tool can also be used by researchers to find flaws in BGP implementations.

Related: ICS Vulnerabilities Chained for Deep Lateral Movement and Physical Damage 

Related: OT:Icefall Continues With Vulnerabilities in Festo, Codesys Products

Related: Embrace RPKI to Secure BGP Routing, Cloudflare Says

https://www.securityweek.com/exploitation-of-bgp-implementation-vulnerabilities-can-lead-to-disruptions/