Cisco Patches High-Severity Vulnerabilities in IOS Software

Cisco this week published its semiannual IOS and IOS XE software security advisory bundle, which addresses ten vulnerabilities, including six rated ‘high severity’.

The most important are three security bugs that can be exploited by remote, unauthenticated attackers to cause a denial-of-service (DoS) condition.

Tracked as CVE-2023-20080, the first of these flaws impacts the IPv6 DHCP version 6 (DHCPv6) relay and server features of IOS and IOS XE software. Insufficient validation of data boundaries allows an attacker to send crafted DHCPv6 messages to an affected device and cause it to reload unexpectedly.

The second vulnerability, CVE-2023-20072, impacts the fragmentation handling code of tunnel protocol packets and can be exploited by sending crafted fragmented packets to an affected system.

Cisco also addressed CVE-2023-20027, an issue in the implementation of the IPv4 Virtual Fragmentation Reassembly (VFR) feature of IOS and IOS XE software, which exists because large packets are not properly reassembled when VFR is enabled.

The vulnerability can be triggered by sending fragmented packets through a VFR-enabled interface on an affected device.

Another high-severity DoS flaw was resolved in the HTTP-based client profiling feature of IOS XE software for Wireless LAN controllers (WLCs). Tracked as CVE-2023-20067, the issue can be exploited by an adjacent attacker, without authentication.

“This vulnerability is due to insufficient input validation of received traffic. An attacker could exploit this vulnerability by sending crafted traffic through a wireless access point. A successful exploit could allow the attacker to cause CPU utilization to increase, which could result in a DoS condition on an affected device and could cause new wireless client associations to fail,” Cisco explains.

Cisco also addressed an insufficient input validation in the CLI of IOS XE SD-WAN software, which could allow an authenticated attacker to execute commands on the operating system with root-level privileges.

Tracked as CVE-2023-20035, the bug could allow an attacker with limited privileges to take over a vulnerable system.

The sixth high-severity flaw that Cisco addressed this week is CVE-2023-20065, an insufficient restrictions issue in the IOx application hosting subsystem of IOS XE software, which could allow an authenticated attacker to escalate their privileges to those of root.

Cisco’s semiannual IOS and IOS XE software updates also include patches for medium-severity DoS, path traversal, and privilege escalation vulnerabilities.

This week, Cisco also released patches for three other high-severity flaws, including a secure boot issue in Catalyst 9300 series switches, a privilege escalation bug in DNA Center, and a DoS vulnerability in access point (AP) software.

Several medium-severity issues were resolved in SD-WAN vManage software, DNA Center, Adaptive Security Appliance (ASA), Firepower Threat Defense (FTD), IOS and IOS XE software, and AP software.

Cisco says it is not aware of any of these flaws being exploited in malicious attacks. Additional information on the resolved vulnerabilities can be found on Cisco’s product security page.

Related: Vulnerability Exposes Cisco Enterprise Routers to Disruptive Attacks

Related: Cisco Patches Critical Vulnerability in IP Phones

Related: Cisco Patches High-Severity Vulnerabilities in ACI Components

https://www.securityweek.com/cisco-patches-high-severity-vulnerabilities-in-ios-software/




High-Severity Vulnerabilities Found in WellinTech Industrial Data Historian

Cisco’s Talos threat intelligence and research unit this week disclosed the details of two high-severity vulnerabilities discovered last year in WellinTech’s KingHistorian industrial data historian software.

China-based industrial automation software company WellinTech designed KingHistorian for collecting and processing a ‘massive amount’ of industrial control system (ICS) data. 

Talos researchers discovered that the historian is impacted by two flaws. One of them, tracked as CVE-2022-45124, can allow an attacker who can intercept an authentication packet to obtain the username and password of the legitimate user who logged in to the system. 

[ Read: Counting ICS Vulnerabilities: Examining Variations in Numbers Reported by Security Firms ]

The second issue, CVE-2022-43663, can be exploited by sending a specially crafted network packet that triggers a buffer overflow. It’s unclear if the flaw can be exploited for arbitrary code execution or only to crash the process.

The vendor was informed about the security holes in December 2022 and released patches earlier this month. 

Cisco has not shared any information on the real world impact resulting from the potential exploitation of these vulnerabilities, but based on previous reports from cybersecurity companies, compromising a historian could be very useful to threat actors.

In January, industrial security firm Claroty disclosed several vulnerabilities found by its researchers in the GE Digital Proficy Historian product. The company warned at the time that the flaws could be exploited for espionage or to cause damage and disruption in industrial environments.

Historian servers can provide access to both IT and OT systems, allowing hackers to leverage compromised devices to gain access to valuable information or move to other systems on the network. 

Related: Vulnerability in ABB Plant Historian Disclosed 5 Years After Discovery

Related: Siemens Drives Rise in ICS Vulnerabilities Discovered in 2022

Related: ICS Vulnerabilities Chained for Deep Lateral Movement and Physical Damage 

https://www.securityweek.com/high-severity-vulnerabilities-found-in-wellintech-industrial-data-historian/




Chrome 111 Update Patches High-Severity Vulnerabilities

Google this week announced a Chrome 111 update that brings patches for eight vulnerabilities, including seven flaws that were reported by external researchers.

All seven of the externally reported issues are high-severity memory safety bugs, with four of them described as use-after-free vulnerabilities, a type of bug that could lead to arbitrary code execution, data corruption, or denial of service.

Based on the bug bounty reward handed out ($10,000), the most important of these vulnerabilities is CVE-2023-1528, a use-after-free flaw in Chrome’s Passwords component.

“It hides the password leak detection dialog before displaying the account selector, which means that the password leak detection dialog shouldn’t be opened before you have selected your Google account. An attacker can gain access to the vulnerable password,” Action1 VP Mike Walters told SecurityWeek in an emailed comment.

Next in line is CVE-2023-1529, an out-of-bounds memory access in WebHID, for which Google paid an $8,000 bug bounty.

“The vulnerability can handle empty input reports. It’s possible for a HID device to define its report descriptor so that one or more reports have no data fields within the report. When these reports are received, the report buffer should contain only the report ID byte and no other data. This can be used to define which reports have some data and to filter out reports without data,” Walters said.

Three other use-after-free issues were addressed in PDF, in the ANGLE graphics engine, and in WebProtect. The internet giant says it paid out a $7,000 bounty for the PDF flaw, but has yet to determine the amounts to be paid for the other two bugs.

The latest Chrome 111 update also brings patches for two out-of-bounds read issues in GPU Video and ANGLE. Per Google’s policy, no bug bounty reward will be issued for these flaws, as they were reported by Google Project Zero security researchers.

The internet giant made no mention of any of these vulnerabilities being exploited in attacks.

The latest Chrome release is now rolling out as version 111.0.5563.110 for Mac and Linux and as versions 111.0.5563.110/.111 for Windows.

Related: Google Discontinuing Chrome Tool for Removing Unwanted Software

Related:Chrome 111 Patches 40 Vulnerabilities

Related: Chrome 110 Patches 15 Vulnerabilities

https://www.securityweek.com/chrome-111-update-patches-high-severity-vulnerabilities/




Zoom Paid Out $3.9 Million in Bug Bounties in 2022

Video communications giant Zoom this week announced that in 2022 it paid out $3.9 million to security researchers who reported vulnerabilities as part of its bug bounty program.

Zoom launched a private bug bounty program on HackerOne in 2019 and has paid out over $7 million in bounty rewards to date. In 2021, the company paid roughly $1.8 million in bug bounty rewards.

Moving forth, the company is working on implementing a new vulnerability impact scoring system that it will use alongside the Common Vulnerability Scoring System (CVSS) to score reports.

The new Vulnerability Impact Scoring System (VISS) will rank vulnerability reports based on 13 different aspects of their impact on Zoom’s infrastructure and technology, as well as on customer data security.

“With the implementation of VISS, Bug Bounty can focus more on measuring responsibly demonstrated impact, rather than the theoretical possibility of exploitation,” Zoom says.

What the company did not say was how many vulnerability reports it received last year and how many of these led to the release of a patch. However, Zoom issued CVE identifiers for tens of critical- and high-severity flaws across its product portfolio.

Earlier this year, Google said it paid out $12 million through its bug bounty programs in 2022. In comparison, Intel paid $935,000 in rewards last year, for a total of over $4.1 million since the beginning of its bug bounty program in 2017.

Related: QNAP Offering $20,000 Rewards via New Bug Bounty Program

Related: Hack the Pentagon 3.0 Bug Bounty Program to Focus on Facility Control Systems

Related:Apple Paid Out $20 Million via Bug Bounty Program

https://www.securityweek.com/zoom-paid-out-3-9-million-in-bug-bounties-in-2022/




Exploitation of 55 Zero-Day Vulnerabilities Came to Light in 2022: Mandiant

Google-owned Mandiant has conducted an analysis of the zero-day vulnerabilities disclosed in 2022 and found that over a dozen of them were used in attacks believed to have been carried out by cyberespionage groups.

The cybersecurity community cannot reach an agreement on the definition of zero-day vulnerability. Some define as zero-day any vulnerability whose details are made public before a patch is released, while others only assign a zero-day classification to flaws that were actually exploited in attacks before a fix was made available. 

Mandiant noted that only vulnerabilities that were exploited in the wild before a patch was released were included in its zero-day analysis. 

According to Mandiant, 55 zero-day vulnerabilities came to light last year. While this is a significant drop from the 81 discovered in 2021, it’s still more than in any other previous year.

Many of the zero-days found last year were not publicly attributed to a known threat actor. Of the ones that were attributed, 13 were linked to cyberespionage groups, including seven believed to have been exploited by Chinese state-sponsored groups.

Chinese hackers targeted vulnerabilities such as CVE-2022-30190 (the Windows flaw known as Follina), and CVE-2022-42475 and CVE-2022-41328 (Fortinet product vulnerabilities).

Two of the zero-days attributed to state-sponsored threat actors were linked to North Korea and two were tied to Russia. Three vulnerabilities were exploited by commercial spyware vendors such as Candiru and Variston. One flaw was seen being exploited by both China and Russia, and spyware vendors as well.

Four of the zero-days spotted in 2022 were likely exploited by financially motivated threat actors, including CVE-2022-29499 (by Lorenz ransomware), and CVE-2022-41091 and CVE-2022-44698 (by Magniber ransomware).   

Of the 55 zero-days that emerged in 2022, 18 impacted Microsoft products, 10 impacted Google products, and 9 were found in Apple products. Other affected vendors included Fortinet, Mozilla, Sophos, Trend Micro, Zimbra, Adobe, Atlassian, Cisco, Mitel, SolarWinds, Zoho, QNAP, and Citrix. 

As for product types, 19 flaws impacted desktop operating systems, followed by browsers (11), security, IT and network management products (10), and mobile operating systems (6). 

“Almost all 2022 zero-day vulnerabilities (53) were exploited for the purpose of achieving either (primarily remote) code execution or gaining elevated privileges, both of which are consistent with most threat actor objectives,” Mandiant noted.

Additional details, including information on why temporary workarounds can cause defender fatigue, are available in Mandiant’s full report. 

Related: Dozens of Exploited Vulnerabilities Missing From CISA ‘Must Patch’ List

Related: 557 CVEs Added to CISA’s Known Exploited Vulnerabilities Catalog in 2022

https://www.securityweek.com/exploitation-of-55-zero-day-vulnerabilities-came-to-light-in-2022-mandiant/




Google Pixel Vulnerability Allows Recovery of Cropped Screenshots

A vulnerability lurking in Google’s Pixel phones for five years allows for the recovery of an original, unedited screenshot from the cropped version of the image.

Referred to as aCropalypse and tracked as CVE-2023-21036, the issue resides in Markup, the image-editing application on Pixel devices, which fails to properly truncate edited images, making the cropped data recoverable.

Reverse engineers Simon Aarons and David Buchanan, who identified the bug, point out that the bug has existed since 2018 and that it was the result of a code change that Markup did not adhere to.

Specifically, when switching from Android 9 to Android 10, the parseMode() function was modified to overwrite a file with a truncated one if the argument ‘wt’ was passed to it. Previously, the argument ‘w’ was needed for the same operation.

Because Markup’s behavior was not changed and it continued to use the argument ‘w’, while it did crop the image, it did not tell the OS to overwrite the original with the smaller version, resulting in the truncated data being left at the end of the file instead.

“The end result is that the image file is opened without the O_TRUNC flag, so that when the cropped image is written, the original image is not truncated. If the new image file is smaller, the end of the original is left behind,” Buchanan explains.

The researcher also points out that the change from ‘w’ to ‘wt’ was only documented in 2021, when a bug report was submitted.

Google addressed the vulnerability with the March 2023 security update for Pixel devices, which patches more than 120 bugs, aside from the issues resolved with the March 2023 Android update.

Aarons and Buchanan released proof-of-concept (PoC) code targeting the vulnerability and explain that, even if the flaw is patched, it still represents a potential privacy issue: any screenshots cropped before the patch can be at least partially restored to the original.

“You can patch it, but you can’t easily un-share all the vulnerable images you may have sent. The bug existed for about 5 years before being patched, which is mind-blowing given how easy it is to spot when you look closely at an output file,” Buchanan points out.

Related: Google Describes Privacy, Security Improvements in Android 14

Related:Android’s February 2023 Updates Patch 40 Vulnerabilities

Related:Arm Vulnerability Leads to Code Execution, Root on Pixel 6 Phones

https://www.securityweek.com/google-pixel-vulnerability-allows-the-recovery-of-cropped-screenshots/




Organizations Notified of Remotely Exploitable Vulnerabilities in Aveva HMI, SCADA Products

Organizations that use human-machine interface (HMI) and supervisory control and data acquisition (SCADA) products from UK-based industrial software maker Aveva have been informed about the existence of several potentially serious vulnerabilities.

Security advisories published last week by Aveva and the US Cybersecurity and Infrastructure Security Agency (CISA) inform users about three vulnerabilities in the InTouch Access Anywhere HMI and Plant SCADA Access Anywhere products. Software updates that patch all vulnerabilities are available from the vendor. 

CISA initially published its advisory in 2022, when it informed organizations about a single high-severity path traversal issue discovered by Jens Regel, a consultant at German cybersecurity firm Crisec. CISA has now updated its initial advisory to add information about additional flaws.

The vulnerability found by Regel, tracked as CVE-2022-23854, can allow an unauthenticated attacker with network access to the secure gateway to read files on the system outside the secure gateway web server.

The researcher told SecurityWeek that InTouch Access Anywhere Gateway instances are often exposed to the internet, allowing remote attackers to exploit the vulnerability directly from the web. A Shodan search shows roughly 1,100 internet-exposed systems, but Regel believes that not all of them are affected by the flaw.

“The path traversal vulnerability makes it possible to access any files on the host system and read the content. You just have to know which path they are on,” the researcher explained. “If an attacker gains access to sensitive information, such as configuration files in which access data is stored, for example, this can become a real problem.”

He added, “No user interaction is necessary. The vulnerability can be exploited very easily using a command line tool such as curl.” 

Regel actually disclosed his findings in September 2022 on the Full Disclosure mailing list, when he also released a proof-of-concept (PoC) exploit. His disclosure came after the vendor had released a hotfix for the vulnerability. 

Aveva has now published an advisory describing this vulnerability, along with two other flaws affecting the InTouch Access Anywhere and Plant SCADA Access Anywhere products. 

These flaws impact third-party components. One is a critical OpenSSL bug that can lead to denial-of-service (DoS) attacks or arbitrary code execution, and the other is a medium-severity issue related to the use of a vulnerable version of jQuery. 

CISA has updated its 2022 advisory to add information about the OpenSSL and jQuery vulnerabilities. 

[ Read: Counting ICS Vulnerabilities: Examining Variations in Numbers Reported by Security Firms ]

The UK’s National Cyber Security Centre (NCSC) has also been credited recently for finding a vulnerability in Aveva’s Plant SCADA and Telemetry Server products. The government agency discovered a critical vulnerability that could allow an unauthenticated attacker to remotely read data, cause a DoS condition, and tamper with alarm states. 

Advisories describing the security hole were published last week by CISA and Aveva. 

The NCSC has not responded to SecurityWeek’s questions about the Aveva vulnerabilities and its ICS vulnerability research in general. The agency was recently also credited for information exposure and command execution vulnerabilities found in Honeywell’s OneWireless Wireless Device Manager product. 

Related: Critical Vulnerabilities Allow Hackers to Take Full Control of Wago PLCs

Related: Critical Vulnerabilities Patched in ThingWorx, Kepware IIoT Products

https://www.securityweek.com/organizations-notified-of-remotely-exploitable-vulnerabilities-in-aveva-hmi-scada-products/




Google tells users of some Android phones: Nuke voice calling to avoid infection

Images of the Samsung Galaxy S21, which runs with an Exynos chipset.
Enlarge / Images of the Samsung Galaxy S21, which runs with an Exynos chipset.

Google is urging owners of certain Android phones to take urgent action to protect themselves from critical vulnerabilities that give skilled hackers the ability to surreptitiously compromise their devices by making a specially crafted call to their number.  It’s not clear if all actions urged are even possible, however, and even if they are, the measures will neuter devices of most voice-calling capabilities.

The vulnerability affects Android devices that use the Exynos chipset made by Samsung’s semiconductor division. Vulnerable devices include the Pixel 6 and 7, international versions of the Samsung Galaxy S22, various mid-range Samsung phones, the Galaxy Watch 4 and 5, and cars with the Exynos Auto T5123 chip. These devices are ONLY vulnerable if they run the Exynos chipset, which includes the baseband that processes signals for voice calls. The US version of the Galaxy S22 runs a Qualcomm Snapdragon chip.

A bug tracked as CVE-2023-24033 and three others that have yet to receive a CVE designation make it possible for hackers to execute malicious code, Google’s Project Zero vulnerability team reported on Thursday. Code-execution bugs in the baseband can be especially critical because the chips are endowed with root-level system privileges to ensure voice calls work reliably.

“Tests conducted by Project Zero confirm that those four vulnerabilities allow an attacker to remotely compromise a phone at the baseband level with no user interaction, and require only that the attacker know the victim’s phone number,” Project Zero’s Tim Willis wrote. “With limited additional research and development, we believe that skilled attackers would be able to quickly create an operational exploit to compromise affected devices silently and remotely.”

Earlier this month, Google released a patch for vulnerable Pixel models. Samsung has released an update patching CVE-2023-24033, but it has not yet been delivered to end users. There’s no indication Samsung has issued patches for the other three critical vulnerabilities. Until vulnerable devices are patched, they remain vulnerable to attacks that give access at the deepest level possible.

The threat prompted Willis to put this advice at the very top of Thursday’s post:

Until security updates are available, users who wish to protect themselves from the baseband remote code execution vulnerabilities in Samsung’s Exynos chipsets can turn off Wi-Fi calling and Voice-over-LTE (VoLTE) in their device settings. Turning off these settings will remove the exploitation risk of these vulnerabilities.

The problem is, it’s not entirely clear that it’s possible to turn off VoLTE, at least on many models. A screenshot one S22 user posted to Reddit last year shows that the option to turn off VoLTE is grayed out. While that user’s S22 was running a Snapdragon chip, the experience for users of Exynos-based phones is likely the same.

And even if it is possible to turn off VoLTE, doing so in conjunction with turning off Wi-Fi may turn phones into little more than tiny tablets running Android. VoLTE came into widespread use a few years ago, and since then most carriers in North America have stopped supporting older 3G and 2G frequencies.

Samsung representatives said in an email that the company in March released security patches for five of six vulnerabilities that “may potentially impact select Galaxy devices” and will patch the sixth flaw next month. The email didn’t answer questions asking if any of the patches are available to end users now or whether it’s possible to turn off VoLTE.

A Google representative, meanwhile, declined to provide the specific steps for carrying out the advice in the Project Zero writeup. Readers who figure out a way are invited to explain the process (with screenshots, if possible) in the comments section.

Because of the severity of the bugs and the ease of exploitation by skilled hackers, Thursday’s post omitted technical details. In its product security update page, Samsung described CVE-2023-24033 as a “memory corruption when processing SDP attribute accept-type.”

“The baseband software does not properly check the format types of accept-type attribute specified by the SDP, which can lead to a denial of service or code execution in Samsung Baseband Modem,” the advisory added. “Users can disable WiFi calling and VoLTE to mitigate the impact of this vulnerability.”

Short for the Session Description Protocol, SDP is a mechanism for establishing a multimedia session between two entities. Its main use is supporting streaming VoIP calls and video conferencing. SDP uses a offer/answer model in which one party advertises a description of a session and the other party answers with the desired parameters.

The threat is serious, but once again, it applies only to people using an Exynos version of one of the affected models. And once again, Google issued a patch earlier this month for Pixel users.

Until Samsung or Google says more, users of devices that remain vulnerable should (1) install all available security updates with a close eye out for one patching CVE-2023-24033, (2) turn off Wi-Fi calling, and (3) explore the settings menu of their specific model to see if it’s possible to turn off VoLTE. This post will be updated if either company responds with more useful information.

Post updated to correct the definition of SDP.

https://arstechnica.com/?p=1925040




Federal agency hacked by 2 groups thanks to flaw that went unpatched for 4 years

Federal agency hacked by 2 groups thanks to flaw that went unpatched for 4 years
Getty Images

Multiple threat actors—one working on behalf of a nation-state—gained access to the network of a US federal agency by exploiting a four-year-old vulnerability that remained unpatched, the US government warned.

Exploit activities by one group likely began in August 2021 and last August by the other, according to an advisory jointly published by the Cybersecurity and Infrastructure Security Agency, the FBI, and the Multi-State Information Sharing and Analysis Center. From last November to early January, the server exhibited signs of compromise.

Vulnerability not detected for 4 years

Both groups exploited a code-execution vulnerability tracked as CVE-2019-18935 in a developer tool known as the Telerik user interface (UI) for ASP.NET AJAX, which was located in the agency’s Microsoft Internet Information Services (IIS) web server. The advisory didn’t identify the agency other than to say it was a Federal Civilian Executive Branch Agency under the CISA authority.

The Telerik UI for ASP.NET AJAX is sold by a company called Progress, which is headquartered in Burlington, Massachusetts, and Rotterdam in the Netherlands. The tool bundles more than 100 UI components that developers can use to reduce the time it takes to create custom Web applications. In late 2019, Progress released version 2020.1.114, which patched CVE-2019-18935, an insecure deserialization vulnerability that made it possible to remotely execute code on vulnerable servers. The vulnerability carried a severity rating of 9.8 out of a possible 10. In 2020, the NSA warned that the vulnerability was being exploited by Chinese state-sponsored actors.

“This exploit, which results in interactive access with the web server, enabled the threat actors to successfully execute remote code on the vulnerable web server,” Thursday’s advisory explained. “Though the agency’s vulnerability scanner had the appropriate plugin for CVE-2019-18935, it failed to detect the vulnerability due to the Telerik UI software being installed in a file path it does not typically scan. This may be the case for many software installations, as file paths widely vary depending on the organization and installation method.”

More unpatched vulnerabilities

To successfully exploit CVE-2019-18935, hackers must first have knowledge of the encryption keys used with a component known as the Telerik RadAsyncUpload. Federal investigators suspect the threat actors exploited one of two vulnerabilities discovered in 2017 that also remained unpatched on the agency server.

Attacks from both groups used a technique known as DLL side loading, which involves replacing legitimate dynamic-link library files in Microsoft Windows with malicious ones. Some of the DLL files the group uploaded were disguised as PNG images. The malicious files were then executed using a legitimate process for IIS servers called w3wp.exe. A review of antivirus logs identified that some of the uploaded DLL files were present on the system as early as August 2021.

The advisory said little about the nation-state-sponsored threat group, other than to identify the IP addresses it used to host command-and-control servers. The group, referred to as TA1 in Thursday’s advisory, began using CVE-2019-18935 last August to enumerate systems inside the agency network. Investigators identified nine DLL files used to explore the server and evade security defenses. The files communicated with a control server with an IP address of 137.184.130[.]162 or 45.77.212[.]12. The traffic to these IP addresses used unencrypted Transmission Control Protocol (TCP) over port 443. The threat actor’s malware was able to load additional libraries and delete DLL files to hide malicious activity on the network.

The advisory referred to the other group as TA2 and identified it as XE Group, which researchers from security firm Volexity have said is likely based in Vietnam. Both Volexity and fellow security firm Malwarebytes have said the financially motivated group engages in payment-card skimming.

“Similar to TA1, TA2 exploited CVE-2019-18935 and was able to upload at least three unique DLL files into the C:\Windows\Temp\ directory that TA2 executed via the w3wp.exe process,” the advisory stated. “These DLL files drop and execute reverse (remote) shell utilities for unencrypted communication with C2 IP addresses associated with the malicious domains.”

The breach is the result of someone in the unnamed agency failing to install a patch that had been available for years. As noted earlier, tools that scan systems for vulnerabilities often limit their searches to a certain set of pre-defined file paths. If this can happen inside a federal agency, it likely can happen inside other organizations.

Anyone using the Telerik UI for ASP.NET AJAX should carefully read Thursday’s advisory as well as the one Progress published in 2019 to ensure they’re not exposed.

https://arstechnica.com/?p=1924743




Mozilla Patches High-Severity Vulnerabilities With Release of Firefox 111

Mozilla announced this week the release of Firefox 111, which patches over a dozen vulnerabilities, including potentially serious issues.

Of the 13 CVEs, seven have been assigned a ‘high’ severity rating. Three of them only impact Firefox for Android, and they can allow a hacker to hide fullscreen notifications — this can lead to user confusion or spoofing attacks — and open third-party apps without a prompt.

Other high-severity flaws patched with the latest Firefox updates can lead to arbitrary code execution and information disclosure. 

Cybersecurity firm Sophos has analyzed the patches and highlighted two vulnerabilities: CVE-2023-28161 and CVE-2023-28163. Sophos said in a blog post:

  • CVE-2023-28161: One-time permissions granted to a local file were extended to other local files loaded in the same tab. With this bug, if you opened a local file (such as downloaded HTML content) that wanted access, say, to your webcam, then any other local file you opened afterwards would magically inherit that access permission without asking you. As Mozilla noted, this could lead to trouble if you were looking through a collection of items in your download directory – the access permission warnings you’d see would depend on the order in which you opened the files.
  • CVE-2023-28163: Windows Save As dialog resolved environment variables. This is another keen reminder to sanitise thine inputs, as we like to say. In Windows commands, some character sequences are treated specially, such as %USERNAME%, which gets converted to the name of the currently logged-on user, or %PUBLIC%, which denotes a shared directory, usually in C:\Users. A sneaky website could use this as a way to trick you into seeing and approving the download of a filename that looks harmless but lands in a directory you wouldn’t expect (and where you might not later realise it had ended up). 

Cybersecurity agencies in Canada and the US have informed users about the latest Firefox patches, urging them to read the advisories and apply the necessary updates. 

Firefox vulnerabilities are not as targeted by threat actors as flaws affecting Chrome, but users should not ignore the potential risks. CISA’s known exploited vulnerabilities catalog lists 10 Firefox vulnerabilities discovered over the past decade.

In addition, Mozilla announced this week that it’s looking into making the Firefox Relay email and phone number masking tool available directly within Firefox.

Related: Emergency Firefox Update Patches Two Actively Exploited Zero-Day Vulnerabilities

Related: Firefox Updates Patch 10 High-Severity Vulnerabilities

https://www.securityweek.com/mozilla-patches-high-severity-vulnerabilities-with-release-of-firefox-111/