Google Warns of New Chrome Zero-Day Attack

Another day, another zero-day attack hitting widely deployed software from a big tech provider.

Google on Friday joined the list of vendors dealing with zero-day attacks, rolling out a major Chrome Desktop update to fix a security defect that’s already been exploited in the wild.

The high-severity vulnerability, tracked as CVE-2023-2033, is described as a type confusion in the Chrome V8 JavaScript engine. 

“Google is aware that an exploit for CVE-2023-2033 exists in the wild,” the company said in a barebones advisory that credits Clément Lecigne of Google’s Threat Analysis Group for reporting the issue.

The company did not provide any additional details of the bug, the in-the-wild exploitation, indicators of compromise (IOCs) or any guidance on the profile of targeted machines.   

Google said access to bug details and links may be kept restricted until a majority of users are updated with a fix. The company said it may also retain restrictions if the bug exists in a third party library that other projects similarly depend on, but haven’t yet fixed.

The patch is being pushed to Chrome 112.0.5615.121 for Windows Mac and Linux and will roll out via the software’s automatic patching mechanism over the coming days/weeks.

The Chrome zero-day patch comes days after Microsoft acknowledged a zero-day in its flagship Windows operating system was being hit by ransomware actors.

Like Google and Microsoft, Apple has also struggled with zero-day exploits and shipped a major patch a week ago to fix a pair of code execution flaws in its iOS, macOS iPadOS platforms.

So far this year, there have been 20 documented in-the-wild zero-day compromises, according to data tracked by SecurityWeek.  Security defects in code from Microsoft, Apple and Google account for 12 of the 20 zero-days in 2023. 

Related: Microsoft Patches Another Already-Exploited Windows Zero-Day

Related: Apple Ships Urgent iOS Patch for Newly Exploited Zero-Days

Related: Adobe Plugs Gaping Security Holes in Reader, Acrobat

Related: Windows Zero-Day Exploited in Nokoyawa Ransomware Attacks

Google Warns of New Chrome Zero-Day Attack




CISA Introduces Secure-by-design and Secure-by-default Development Principles

CISA has described and published a set of principles for the development of security-by-design and security-by-default cybersecurity products.

Pillar Three of the National Cybersecurity Strategy published on March 1, 2023 is titled ‘Shape market forces to drive security and resilience’. Within this section the Administration makes two points very clear. Firstly, security liability must be shifted away from the use of security products to the development of security products; and secondly, federal procurement power will be used to encourage this shift.

Both points were previewed in a speech given by CISA director Jen Easterly at Carnegie Mellon days earlier (February 27, 2023). She noted that insecurity has become normalized, and that the onus is currently on the user to make use of products less risky. She said this must change, so that the user is forced into making usage more rather than less risky.

This requires products to be built with security-by-design and security-by-default principles – and she noted that government has two incentives to ensure this: regulations, and federal procurement power.

Now, on April 13, 2023, CISA published a set of principles (PDF) that developers can employ to achieve these ends. The principles were developed with collaboration between CISA, the NSA and the FBI, and foreign security agencies including those from Australia, Canada, and the UK.

The security-by-design principles acknowledge that they will not prevent all breaches and will likely increase development costs; but also note that they will improve the nation’s cybersecurity and reduce the developers’ ongoing maintenance and patching costs.

Top of the list of design principles is the use of memory safe programming languages. In her earlier speech, Easterly had commented that around two-thirds of known vulnerabilities are ‘memory safety’ vulnerabilities. “Certain programming languages,” she said, “most notably, C and C++, lack the mechanisms to prevent coders from introducing these vulnerabilities into their software. By switching to memory safe programming languages—like Rust, Go, Python, and Java—these vulnerabilities can be eliminated.” The principles add C# and Swift to the memory safe list.

Other principles include the use of a secure hardware foundation, secure software components, parameterized queries to avoid SQL injection attacks, and SAST and DAST testing. These should be supported by code reviews, SBOMs, vulnerability disclosure programs and more.

Security-by-default refers to the practice of delivering products that are secure out-of-the-box, rather than products that must be made secure by the user. The principle notes that ‘hardening guides’ (which can be used by attackers as a roadmap by attackers) should be reversed into ‘loosening guides’ that explain which changes users should make while also listing the resulting security risks. 

This can be achieved by following the security-by-default principles, which include elements such as no default password, mandated MFA, single sign on via modern open standards, and secure logging. “The authoring agencies believe that developing written roadmaps and executive support that prioritize these ideas into an organization’s most critical products is the first step to shifting towards secure software development practices,” notes CISA.

But it’s not solely down to the developer to willingly adopt these principles. Customers are encouraged to insist on buying demonstrably secure-by-design and secure-by-default products. “IT departments should be empowered to develop purchasing criteria that emphasize the importance of Secure-by-Design and Secure-by-Default practices (both those outlined in this document and others developed by the organization),” says CISA. “Furthermore, IT departments should be supported by executive management when enforcing these criteria in purchasing decisions.”

The purpose in developing this set of principles is nothing less than an attempt to improve the cybersecurity of the entire nation in the face of increasing criminal and increasingly dangerous adversarial nation threats. Easterly mentioned two possible incentives: regulation and federal purchasing power. The Administration has already made clear that it will use its purchasing power to help persuade developers to comply.

It follows that there are two important reasons for developers to understand and use the CISA principles. Firstly, it is the right thing to do. Secondly, if there is to be any hope of selling into the federal government, it is the essential thing to do.

Related: White House Cybersecurity Strategy Stresses Software Safety

Related: NSA Publishes Guidance on Mitigating Software Memory Safety Issues

Related: Companies Announced Billions in US Government Cybersecurity Contracts in 2022

Related: AWS Enables Default Server-Side Encryption for S3 Objects

https://www.securityweek.com/cisa-introduces-secure-by-design-and-secure-by-default-development-principles/




Google, CISA Warn of Android Flaw After Reports of Chinese App Zero-Day Exploitation 

An Android vulnerability that was reportedly exploited as a zero-day by a Chinese application against millions of devices has been added to the known exploited vulnerabilities catalog maintained by the US Cybersecurity and Infrastructure Security Agency (CISA) after Google confirmed exploitation. 

Google said on March 21 that it had suspended the popular Chinese shopping application Pinduoduo on its app store after malware was discovered in versions of the app distributed through other websites. The Chinese company at the time denied the allegations.

Google’s decision came after Chinese researchers reported observing malicious behavior associated with Pinduoduo, accusing the company of ensnaring the devices of hundreds of millions of its users into a botnet.

The researchers claimed Pinduoduo apps exploit Android and OEM-specific vulnerabilities, collect user and application data, deploy backdoors, install other apps, and bypass security features. 

Roughly a week after Google announced removing the Pinduoduo app, researchers at mobile security firm Lookout confirmed for Ars Technica that the application does indeed appear to attempt to take control of devices, harvest data, and install other software, with millions of devices potentially being impacted.

Lookout also found that the application has exploited an Android vulnerability tracked as CVE-2023-20963, with exploitation starting before Google released a patch in March.

Google describes CVE-2023-20963 as a high-severity privilege escalation flaw affecting Android’s framework component. The internet giant updated its March 2023 Android security bulletin at some point in April to inform users that “there are indications that CVE-2023-20963 may be under limited, targeted exploitation”.

CISA on Thursday added the vulnerability to its known exploited vulnerabilities (KEV) catalog, which is also known as a ‘must patch’ list due to organizations being strongly urged to address the included flaws. The agency has instructed government organizations to patch it within the next two weeks. 

In addition to CVE-2023-20963, CISA added to its KEV catalog a vulnerability affecting installable survey software made by Novi Survey.

Novi Survey has published an advisory to inform customers about CVE-2023-29492, which the company says allows a remote attacker to execute arbitrary code on the server. 

“The vulnerability does not provide access to survey or response data stored within the system,” Novi explained.

However, the public advisory does not mention anything about in-the-wild exploitation and there do not appear to be any reports about attacks involving the vulnerability. 

SecurityWeek has reached out to Novi Survey to learn if the company is aware of the attacks and if it has notified customers. It’s unclear if the company has warned customers privately about the threat. 

Google on Thursday called on vendors to be more transparent when it comes to vulnerability exploitation.

“Vendors should make users, supply chain partners, and the community aware of the exploitation and notify victims in a timely manner through public disclosure and direct outreach where possible. […] Additional details of vulnerabilities and exploits should be shared to improve researcher knowledge and defenses,” Google said.

UPDATE: Novi Survey told SecurityWeek that “all the relevant information is in the CVE and in the advisory posted on the blog on our site.”

Related: Veritas Vulnerabilities Exploited in Ransomware Attacks Added to CISA ‘Must Patch’ List

Related: CISA Warns of Plex Vulnerability Linked to LastPass Hack

https://www.securityweek.com/google-cisa-warn-of-android-flaw-after-reports-of-chinese-app-zero-day-exploitation/




Juniper Networks Patches Critical Third-Party Component Vulnerabilities

Networking, cloud and cybersecurity solutions provider Juniper Networks this week published advisories detailing tens of vulnerabilities found across its product portfolio, including critical bugs in third-party components of Junos OS and STRM.

One of the advisories addresses multiple critical-severity vulnerabilities in Expat (libexpat), a third-party stream-oriented XML parser library.

Juniper’s advisory details 15 Expat vulnerabilities resolved with the latest Junos OS releases, seven of which are rated ‘critical severity’ (CVSS score of 9.8). Although disclosed over the past two years, the flaws are not known to be exploited in malicious attacks.

Updates that address these vulnerabilities were released for Junos OS versions 19.4 to 22.2. Juniper recommends using access lists or firewall filters to reduce the risks associated with these bugs.

Juniper also announced that patches for CVE-2022-42889, a critical vulnerability in Apache Commons Text leading to remote code execution, were released for Security Threat Response Manager (STRM).

This week, the networking company also announced patches for multiple high-severity vulnerabilities impacting Junos OS and Junos OS Evolved, the most severe of which could lead to command injection and code execution.

Two high-severity flaws in Junos OS Evolved could allow a low-privileged local attacker to modify files or execute commands with root privileges, or execute administrative commands, respectively.

Multiple high-severity vulnerabilities addressed this week in Junos OS and Junos OS Evolved could allow an attacker to cause a denial-of-service (DoS) condition.

Juniper also resolved a severe bug in Paragon Active Assurance (formerly Netrounds) that could be exploited to bypass existing firewall rules and limitations.

Juniper has also announced patches for multiple medium-severity issues in Junos OS that could allow an attacker to cause a DoS condition, send packets that were intended to be dropped, access sensitive information, bypass an integrity check, cause traffic to be allowed through, or bypass console access controls.

Juniper makes no mention of any of these vulnerabilities being exploited in attacks. Additional details on the addresses flaws can be found on the Juniper Networks security advisories page.

Related:Juniper Networks Patches Over 200 Third-Party Component Vulnerabilities

Related: Juniper Networks Kicks Off 2023 With Patches for Over 200 Vulnerabilities

Related: Juniper Networks Patches Vulnerabilities in Contrail Networking, Junos OS

https://www.securityweek.com/juniper-networks-patches-critical-third-party-component-vulnerabilities/




Google Proposes More Transparent Vulnerability Management Practices

Google today published a white paper calling on vendors to provide more transparency into their vulnerability management practices.

A longtime supporter of collaboration on bug disclosure and patching, the internet giant believes that the endless ‘doom loop’ of vulnerability patching is exhausting defenders and users. In addition, the tools created in response to novel attack trends do not seem to help in improving the situation. 

Breaking this loop, Google says, requires a focus on the fundamentals of secure software development, on adopting best practices for patching, and on ensuring that patching is easy and secure from the start. For that, vendors need to understand the root cause of vulnerabilities and to apply complete fixes.

“Prioritizing root cause analysis will enable industry, government, and end users to start rising above the exhausting hamster wheel of vulnerability responses,” the company says.

Vulnerabilities, Google says, pose great risks not only as zero-days, but also if they remain unpatched, weakening both enterprise and end-user security posture. Frequency of patching, automated patching, and how fixes are delivered (as standalone patches or part of system updates) should be a focus for all vendors, the company suggests.

“While the notoriety of zero-day vulnerabilities typically makes headlines, risks remain even after they’re known and fixed, which is the real story. Those risks span everything from lag time in OEM adoption, patch testing pain points, end user update issues and more,” Google says.

With many of the exploited zero-day vulnerabilities identified in 2022 being variants of previously patched security defects, as result of incomplete fixes, Google also calls for increased attention from vendors to ensure that risks are comprehensively addressed.

Furthermore, the company’s paper underlines that the industry should invest in making patch testing and implementation easier for customers, otherwise enterprises might fall behind in adopting fixes that are difficult to apply. More holistic policies to address product lifecycles should also be adopted.

“Products should come with policies about expected lifetime (including expiration dates), and support and notification models for downstream customers,” Google notes.

In today’s paper, the internet giant mentions the creation of the Hacking Policy Council, a group of organizations and leaders determined to improve user security, as a first step in advocating best practices for vulnerability management and disclosure.

The paper also calls for vendors and governments to be more transparent regarding vulnerability exploitation and patching, to support the development of ecosystem-wide mitigations, especially since there are vendors that quietly release security fixes, without warning the community of the identified flaw.

“Vendors should make users, supply chain partners, and the community aware of the exploitation and notify victims in a timely manner through public disclosure and direct outreach where possible. […] Additional details of vulnerabilities and exploits should be shared to improve researcher knowledge and defenses,” Google advocates.

Increased transparency, the internet giant says, will ensure users apply mitigations faster and “will help industry and policymakers understand the scope of the challenge and whether the industry is truly improving in this area.” New policies, however, should not force organizations to over-report events and should be evaluated against their impact on security.

According to Google, better supporting bug hunters is another key point in advancing the ecosystem, through legal frameworks that distinguish between research for defensive purposes and malicious activities but do not compel researchers to inform governments of identified flaws before notifying the vendor.

“We believe anyone, regardless of background, should be able to contribute to vulnerability research. Ultimately, vulnerability reports are information, organizations should not limit their ability to receive useful information from the community,” Google says.

Today, the internet giant announced that it is offering seed funding for the Security Research Legal Defense Fund, a fund meant to protect good-faith security researchers who face legal threats but who do not have access to legal counsel.

“Making progress on these issues requires cooperation among stakeholders including industry, who develop the platforms and services that attackers seek to exploit; researchers, who not only find vulnerabilities but identify and drive mitigations that can close off entire avenues of attack; users, who unfortunately still bear too high of a burden of security; and governments, who create incentive structures that shape the behavior of all these other actors,” Google says.

Related:CISA Announces Vulnerability Disclosure Policy Platform

Related: UK’s NCSC Publishes Guide to Implementing a Vulnerability Disclosure Process

Related:Zero-day Vulnerability Highlights the Responsible Disclosure Dilemma

https://www.securityweek.com/google-proposes-more-transparent-vulnerability-management-practices/




Critical Vulnerability in Hikvision Storage Solutions Exposes Video Security Data

Video surveillance giant Hikvision this week informed customers that it has patched a critical vulnerability affecting its Hybrid SAN and cluster storage products.

The vulnerability, tracked as CVE-2023-28808, has been described by the vendor as an access control issue that can be exploited to obtain administrator permissions by sending specially crafted messages to the targeted device.

The impacted products are used by organizations to store video security data, and an attacker exploiting the vulnerability could gain access to that data. 

In a notification sent by Hikvision to partners — a copy was also shared with SecurityWeek — the company said it’s not aware of in-the-wild exploitation.

“While Hikvision is not aware of this vulnerability being exploited in the field, we recognize that some of our partners may have installed Hikvision equipment that is affected by this vulnerability and we strongly encourage them to work with their customers to install the patch and ensure proper cyber hygiene,” the company told partners. 

Hikvision noted in its advisory that an attacker needs to have network access to the targeted device in order to exploit CVE-2023-28808. 

However, Arko Dhar, the CTO of Redinent, the India-based CCTV and IoT cybersecurity company credited for finding the vulnerability, told SecurityWeek that many impacted systems are exposed to the internet and remote exploitation is possible. 

“The Hybrid SAN storage is primarily meant to store CCTV video recordings. But it can also be configured to store business data as well. The impact is very wide – an attacker can delete video recordings and business data at the same time, delete backups and cause significant impact to the business,” Dhar warned.

Redinent’s researchers discovered the vulnerability in late December 2022 and the flaw was reported to the vendor through CERT India in January. 

Hikvision announced on April 10 that patches are included in version 2.3.8-8 for Hybrid SAN and version 1.1.4 for cluster storage devices. The vendor has provided detailed instructions for installing the updates. 

Related: Vulnerability Allows Hackers to Remotely Tamper With Dahua Security Cameras

Related: Critical Vulnerability in Hikvision Wireless Bridges Allows CCTV Hacking

Related: QNAP Patches Critical Vulnerability in Network Surveillance Products

https://www.securityweek.com/critical-vulnerability-in-hikvision-storage-solutions-exposes-video-security-data/




Fortinet Patches Critical Vulnerability in Data Analytics Solution

Cybersecurity solutions provider Fortinet this week announced the release of security updates across multiple products, including patches for a critical vulnerability in FortiPresence.

Offering analytics, heat maps, and reporting, FortiPresence is a data analytics solution available as a hosted cloud service or as a virtual machine, for private installations.

This week, Fortinet announced that a critical missing authentication vulnerability in the FortiPresence infrastructure server may be exploited to access Redis and MongoDB instances.

Tracked as CVE-2022-41331 (CVSS score of 9.3), the vulnerability can be exploited by a remote, unauthenticated attacker, through crafted authentication requests.

The security defect impacts FortiPresence versions 1.0, 1.1, and 1.2, and was addressed with the release of FortiPresence version 2.0.0.

As part of its April 2023 vulnerability advisories published this week, Fortinet also announced patches for multiple high-severity flaws in FortiOS, FortiProxy, FortiSandbox, FortiDeceptor, FortiWeb, FortiClient for Windows and macOS, FortiSOAR, FortiADC, FortiDDoS, FortiDDoS-F, FortiAnalyzer, and FortiManager.

The addressed issues could lead to cross-site scripting (XSS) attacks, unauthorized API calls, command execution, arbitrary code execution, arbitrary file creation, privilege escalation, information disclosure, arbitrary file retrieval, and man-in-the-middle (MitM) attacks.

Additionally, Fortinet released an advisory detailing a vulnerability in the Linux kernel version used in FortiAuthenticator, FortiProxy, and FortiSIEM, which could allow an attacker with low privileges to write to page cache and escalate privileges on the system.

Tracked as CVE-2022-0847 and also referred to as Dirty Pipe, the flaw was introduced in Linux kernel version 5.8 and was addressed last year in Linux 5.16.11, 5.15.25 and 5.10.102.

Several medium- and low-severity vulnerabilities impacting FortiNAC, FortiOS, FortiProxy, FortiADC, FortiGate, and FortiAuthenticator were also addressed.

Customers are advised to update their installations as soon as possible. Although the company does not mention any of these vulnerabilities being exploited in attacks, unpatched Fortinet products are known to have been targeted in malicious attacks, including by nation-state threat actors.

Additional information on the addressed vulnerabilities can be found on Fortinet’s PSIRT advisories page.

Related:Fortinet Patches Critical Unauthenticated RCE Vulnerability in FortiOS

Related: Exploitation of Recent Fortinet Zero-Day Linked to Chinese Cyberspies

Related: Fortinet Patches Critical Code Execution Vulnerabilities in FortiNAC, FortiWeb

https://www.securityweek.com/fortinet-patches-critical-vulnerability-in-data-analytics-solution/




Windows Zero-Day Exploited in Nokoyawa Ransomware Attacks

A Windows zero-day vulnerability fixed by Microsoft with its April 2023 Patch Tuesday updates has been exploited by cybercriminals in ransomware attacks, according to Kaspersky.

Microsoft’s latest round of security updates addresses roughly 100 vulnerabilities, including CVE-2023-28252, which has been described as a privilege escalation flaw affecting the Windows Common Log File System (CLFS) driver.

Microsoft warned that the vulnerability has been exploited in the wild, but did not share any information on the attacks.

Kaspersky, Mandiant and Chinese cybersecurity firm DBAppSecurity have been credited for reporting CVE-2023-28252, and Kaspersky on Tuesday shared some details about the attacks exploiting the vulnerability.

CLFS is a log file subsystem described by Microsoft as a general-purpose logging service that can be used by software clients running in user- or kernel-mode. The vulnerability affecting CLFS allows an authenticated attacker to elevate privileges to System.

According to Kaspersky, a cybercrime group known for conducting ransomware operations has been exploiting the vulnerability as part of attacks whose goal is to deliver the Nokoyawa ransomware.

“This group is notable for its use of a large number of similar but unique Common Log File System (CLFS) driver exploits that were likely developed by the same exploit author. Since at least June 2022, we’ve identified five different exploits used in attacks on retail & wholesale, energy, manufacturing, healthcare, software development and other industries,” Kaspersky noted.

The Nokoyawa ransomware family, which is designed to target Windows systems, emerged in February 2022. The malware encrypts files on compromised systems, but the cybercriminals also claim to steal valuable information that they threaten to leak unless a ransom is paid.

Code similarities suggest ties to the Karma and Nemty ransomware families, while attack chain similarities connect it to the notorious Hive operation, disrupted recently by law enforcement. 

Kaspersky has not shared too many details on the vulnerability in an effort to prevent abuse. The company plans on releasing additional information nine days after Patch Tuesday. 

Kaspersky pointed out that dozens of CLFS vulnerabilities were discovered in the past five years and at least three of them — not including CVE-2023-28252 — have been exploited in the wild. 

Related: Veritas Vulnerabilities Exploited in Ransomware Attacks Added to CISA ‘Must Patch’ List

Related: Patch Tuesday: Microsoft Warns of Exploited Windows Zero-Days

Related: Microsoft Pins Outlook Zero-Day Attacks on Russian Actor, Offers Detection Script

https://www.securityweek.com/windows-zero-day-exploited-in-nokoyawa-ransomware-attacks/




SAP Patches Critical Vulnerabilities in Diagnostics Agent, BusinessObjects

German enterprise software maker SAP announced the release of 19 new notes on its April 2023 Security Patch Day, as well as five updates to previously released notes.

Of the 24 notes included in SAP’s security updates (PDF), five are rated ‘hot news’, the highest severity rating. Two of these are new notes and three are updates to previously released security notes.

The most important of the new notes deals with two critical vulnerabilities in SAP Diagnostics Agent that could be exploited to execute commands on all monitored SAP systems. The bugs are tracked as CVE-2023-27497 (CVSS score of 10) and CVE-2023-27267 (CVSS score of 9).

Designed to connect the SAP solutions manager to managed systems, the Diagnostics Agent collects information for reporting purposes.

The two critical vulnerabilities addressed this week were identified in the OSCommandBridge and the EventLogService Collector components and can be exploited without authentication to execute scripts on all connected Diagnostics Agents.

“In conjunction with insufficient input validation, attackers were able to execute malicious commands on all monitored SAP systems, highly impacting their confidentiality, integrity, and availability,” enterprise application security company Onapsis explains.

The second new hot news note released on SAP’s April 2023 Security Patch Day addresses a critical information disclosure flaw (CVE-2023-28765, CVSS score of 9.8) in the BusinessObjects platform.

Due to missing password protection enforcement, an attacker with basic privileges can access the lcmbiar file, which could allow them to access user passwords.

“Depending on the authorizations of the impersonated user, an attacker could completely compromise the system’s confidentiality, integrity, and availability,” Onapsis notes.

This week, SAP also released updates for the Chromium browser in Business Client and updated two hot news security notes dealing with an improper access control issue and with a directory traversal vulnerability in NetWeaver.

SAP released only one high priority note this week, to address CVE-2023-29186, a directory traversal bug in NetWeaver’s BI_CONT AddOn component.

“A report of the AddOn allows a remote attacker with administrative privileges to overwrite arbitrary and potentially critical OS files. This could make the affected system completely unavailable. The patch completely disables the vulnerable report,” Onapsis explains.

The remaining notes released on SAP’s Security Patch Day address medium- and low-severity vulnerabilities in Landscape Management, SapSetup, NetWeaver, Fiori, GUI for HTML, CRM, SAP Web Dispatcher and Internet Communication Manager, ABAP Platform, Commerce, and Application Interface Framework.

Related: SAP Releases Five ‘Hot News’ Notes on March 2023 Patch Day

Related: SAP’s February 2023 Security Updates Patch High-Severity Vulnerabilities

Related: SAP’s First Security Updates for 2023 Resolve Critical Vulnerabilities

https://www.securityweek.com/sap-patches-critical-vulnerabilities-in-diagnostics-agent-businessobjects/




Microsoft Patches Another Already-Exploited Windows Zero-Day

For the second month in a row, Microsoft is pushing out urgent patches to cover an already-exploited vulnerability in its flagship Windows operating system.

The vulnerability, flagged as zero-day by researchers at Mandiant, is described as an elevation of privilege issue in the Windows Common Log File System driver.

In an advisory documenting the CVE-2023-28252, Redmond warns that an attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

As is customary, Microsoft did not provide any additional details on the zero-day exploitation or release IOCs (indicators of compromise) to help defenders hunt for signs of infections.

The latest zero-day warning headlines a busy Patch Tuesday that includes fixes for at least 98 documented vulnerabilities across the Windows ecosystem. It comes exactly a month after Redmond confirmed a major no-interaction Outlook vulnerability exploited by Russian hackers since at least April 2022.

So far this year, there have been at least 19 in-the-wild zero-day attacks. Security defects in code from Microsoft feature in about one-third of all observed exploitation in 2023.

According to ZDI, organizers of the Pwn2Own exploit contest, none of the bugs disclosed over Teams during Pwn2Own Vancouver are being addressed by Microsoft this month.

In a blog post, ZDI also recommends that Windows users pay attention to CVE-2023-21554, a  Microsoft Message Queuing remote code execution vulnerability with a CVSS score of 9.8 out of 10.

“[This bug] allows a remote, unauthenticated attacker to run their code with elevated privileges on affected servers with the Message Queuing service enabled. This service is disabled by default but is commonly used by many contact center applications,” ZDI said.

The Microsoft patches come on the same day Adobe rolled out security fixes for at least 56 vulnerabilities in a wide range of products, some serious enough to expose Windows and macOS users to code execution attacks.

Adobe called special attention to its APSB23-24 bulletin that covers critical-severity security flaws in the widely deployed Adobe Acrobat and Reader software.

“Successful exploitation could lead to arbitrary code execution, privilege escalation, security feature bypass and memory leak,” Adobe said in a warning addressed to both Windows and macOS users. 

The company documented at least 16 vulnerabilities in the Acrobat and Reader updates and said it was not aware of any in-the-wild exploitation. 

Related: Apple Ships Urgent iOS Patch for Newly Exploited Zero-Days

Related: Adobe Plugs Gaping Security Holes in Reader, Acrobat

Related: Samsung Mobile Chipsets Vulnerable to Baseband Code Execution Exploits

Related: Microsoft: No-Interaction Outlook Zero Day Exploited Since Last April

https://www.securityweek.com/microsoft-patches-another-already-exploited-windows-zero-day/