Patch Tuesday: Microsoft Warns of Exploited Windows Zero-Days

Microsoft’s Patch Tuesday machine is humming loudly with software updates to fix at least 76 vulnerabilities in Windows and OS components and the company is warning that some of the bugs have already been exploited in the wild.

Microsoft’s security response team flagged three of the 76 documented flaws in the already-exploited category that typically refers to zero-day malware attacks in the wild.  

As is customary, the world’s largest software maker did not provide any technical details of the exploited vulnerabilities or IOCs (indicators of compromise) to help defenders hunt for signs of compromise.

The most serious of the exploited issues is documented as CVE-2023-21823, a Windows graphics component remote code execution vulnerability. “An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” according to a barebones advisory from Redmond that credits researchers at incident response giant Mandiant with reporting the issue.

The company also called special attention to CVE-2023-21715, a feature bypass vulnerability in Microsoft Publisher that’s in the already-exploited category; and CVE-2023-23376, a privilege escalation flaw in Windows common log file system driver.

Microsoft slapped critical-severity ratings on seven of the 76 bulletins and warned that these issues could lead to remote code execution attacks targeting Microsoft Word, Visual Studio and the Windows iSCSI Discovery Service.

The company also shipped important-severity updates for Microsoft Defender, Microsoft Exchange Server, Microsoft Dynamics, 3D Builder, Sharepoint and Microsoft SQL Server.

The industry-wide Patch Tuesday updates also included security fixes from Adobe (critical bugs in After Effects and Illustrator) and Apple (WebKit zero-day exploitation on iOS and macOS).

According to Adobe’s security bulletins, the Illustrator and After Effects patches carry critical-severity ratings because of the risk of code execution attacks. 

The WebKit flaw, tracked as CVE-2023-23529, is  a type confusion issue that can be exploited for arbitrary code execution by getting the targeted user to access a malicious website. Apple marked this as exploited on its flagship iOS mobile platform.

Related: Apple Patches Actively Exploited WebKit Zero-Day Vulnerability 

Related: Microsoft Patch Tuesday: 97 Windows Vulns, 1 Exploited Zero-Day

Related: Zoom Patches High Risk Flaws on Windows, MacOS Platforms

Related: Microsoft Warns of Under-Attack Windows Kernel Flaw

Patch Tuesday: Microsoft Warns of Exploited Windows Zero-Days




Adobe Plugs Critical Security Holes in Illustrator, After Effects Software

Software maker Adobe on Tuesday released security fixes for at least a half dozen vulnerabilities that expose Windows and macOS users to malicious hacker attacks.

The Mountain View, Calif. company warned that the security problems exist on three of its most popular software products — Photoshop, Illustrator and After Effects.

According to Adobe’s security bulletins, the Illustrator and After Effects patches carry critical-severity ratings because of the risk of code execution attacks.

The company said the Adobe Illustrator vulnerability, tracked as CVE-2022-23187, is a buffer overflow issue that leads to arbitrary code execution. The bug is present for both Windows and macOS users on Illustrator 26.0.3 and earlier versions.

A second critical bulletin was released to cover at least four documented Adobe After Effects vulnerabilities that expose Windows and macOS users to code execution attacks. 

“This update addresses critical security vulnerabilities.  Successful exploitation could lead to arbitrary code execution in the context of the current user,” Adobe said in a bulletin that documents stack-based buffer overflows with serious implications.

Adobe tracks the After Effects bugs as CVE-2022-24094, CVE-2022-24095, CVE-2022-24096, and CVE-2022-24097.

The company also shipped a third bulletin to cover an important-severity flaw in its flagship Adobe Photoshop software.

The Photoshop vulnerability (CVE-2022-24090) affects both Windows and macOS users and Adobe warns that successful exploitation could lead to memory leak in the context of the current user.   

Adobe said it was not aware of any exploits in the wild for any of the flaws patched this month.

Adobe’s patches follow the release of patches from Apple to cover an already exploited WebKit zero-day affecting its iOS, iPadOS and macOS platforms.

The WebKit flaw, tracked as CVE-2023-23529, is described as a type confusion issue that can be exploited for arbitrary code execution by getting the targeted user to access a malicious website.  

Related: Apple Patches Actively Exploited WebKit Zero-Day Vulnerability 

Related: Microsoft Patch Tuesday: 97 Windows Vulns, 1 Exploited Zero-Day

Related: Zoom Patches High Risk Flaws on Windows, MacOS Platforms

Related: Microsoft Warns of Under-Attack Windows Kernel Flaw

https://www.securityweek.com/adobe-plugs-critical-security-holes-in-illustrator-after-effects-software/




GoAnywhere Zero-Day Attack Victims Start Disclosing Significant Impact

Organizations hit by attacks exploiting a recently disclosed zero-day vulnerability affecting the GoAnywhere managed file transfer (MFT) software have started coming forward and disclosing impact. 

The vulnerability, tracked as CVE-2023-0669, was disclosed by GoAnywhere developer Fortra on February 1, after the company became aware of in-the-wild exploitation. Mitigations and indicators of compromise (IoCs) were released immediately, but a patch was only made available a week later. 

Information about the attacks exploiting CVE-2023-0669 and victims of these attacks are now coming to light. 

In a filing with the US Securities and Exchange Commission (SEC), Community Health Systems (CHS), one of the largest healthcare services providers in the United States, revealed that a “security breach experienced by Fortra” resulted in the exposure of personal and protected health information (PHI) belonging to patients of CHS affiliates.

The organization is conducting an investigation, but it currently estimates that roughly one million individuals may have been impacted by the incident. CHS said the breach does not appear to have had any impact on its own information systems and business operation, including the delivery of patient care. 

A source told SecurityWeek that several major companies have been hit by the GoAnywhere zero-day attacks and it’s only a matter of time before they disclose significant breaches. 

Cybersecurity firm Huntress reported last week that it had investigated an attack apparently exploiting CVE-2023-0669 and managed to link it to a Russian-speaking threat actor named Silence. This group has also been tied to TA505, a threat group known for distributing the Cl0p ransomware. 

Indeed, the Cl0p ransomware group has taken credit for the GoAnywhere attack, telling Bleeping Computer that they managed to steal data from more than 130 organizations. However, the hackers have not provided any evidence to back their claims. At the time of writing, there is no mention of Fortra or GoAnywhere on Cl0p’s Tor-based website. 

If confirmed, this would not be the first time cybercriminals linked to the Cl0p ransomware have exploited vulnerabilities in a file transfer service used by major organizations to steal data. 

In late 2020, a group targeted Accellion’s FTA service to steal data belonging to several organizations, including grocery and pharmacy chain Kroger, the Australian Securities and Investments Commission (ASIC), law firm Jones Day, the Office of the Washington State Auditor (SAO), and the Reserve Bank of New Zealand.

At the time of writing, there are more than 1,000 internet-exposed instances of GoAnywhere. However, according to Fortra, exploitation requires access to the application’s admin console, and at least some of the exposed instances are associated with the product’s web client interface, which is not impacted. 

CISA has added CVE-2023-0669 to its Known Exploited Vulnerabilities Catalog, instructing federal agencies to patch the flaw until March 3.

Related: Patch Tuesday: Microsoft Plugs Windows Hole Exploited in Ransomware Attacks

Related: Decade-Old Adobe ColdFusion Vulnerabilities Exploited by Ransomware Gang

Related: PetitPotam Vulnerability Exploited in Ransomware Attacks

https://www.securityweek.com/goanywhere-zero-day-attack-victims-start-disclosing-significant-impact/




Valve waited 15 months to patch high-severity flaw. A hacker pounced

Valve waited 15 months to patch high-severity flaw. A hacker pounced

Researchers have unearthed four game modes that could successfully exploit a critical vulnerability that remained unpatched in the popular Dota 2 video game for 15 months after a fix had become available.

The vulnerability, tracked as CVE-2021-38003, resided in the open source JavaScript engine from Google known as V8, which is incorporated into Dota 2. Although Google patched the vulnerability in October 2021, Dota 2 developer Valve didn’t update its software to use the patched V8 engine until last month after researchers privately alerted the company that the critical vulnerability was being targeted.

Unclear intentions

A hacker took advantage of the delay by publishing a custom game mode last March that exploited the vulnerability, researchers from security firm Avast said. That same month, the same hacker published three additional game modes that very likely also exploited the vulnerability. Besides patching the vulnerability last month, Valve also removed all four modes.

Custom modes are extensions or even completely new games that run on top of Dota 2. They allow people with even basic programming experience to implement their ideas for a game and then submit them to Valve. The game maker then puts the submissions through a verification process and, if they’re approved, publishes them.

The first game mode published by Valve appears to be a proof-of-concept project for exploiting the vulnerability. It was titled “test addon plz ignore” (ID 1556548695) and included a description that urged people not to download or install it. Embedded inside the mode was exploit code for CVE-2021-38003. While some of the exploit was taken from proof-of-concept code published in the Chromium bug tracker, the mode developer wrote much of it from scratch. The mode included lots of commented-out code and a file titled “evil.lua” further suggesting the mode was a test.

Avast researchers went on to find three more custom modes that the same developer had published to Valve. These modes—titled “Overdog no annoying heroes” (id 2776998052), “Custom Hero Brawl” (id 2780728794), and Overthrow RTZ Edition X10 XP (id 2780559339)—took a much more covert approach.

Avast researcher Jan Vojtěšek explained:

The malicious code in these new three game modes is much more subtle. There is no file named evil.lua nor any JavaScript exploit directly visible in the source code. Instead, there’s just a simple backdoor consisting of only about twenty lines of code. This backdoor can execute arbitrary JavaScript downloaded via HTTP, giving the attacker not only the ability to hide the exploit code, but also the ability to update it at their discretion without having to update the entire custom game mode (and going through the risky game mode verification process).

The server these three modes contacted was no longer working when Avast researchers discovered the modes. But given they were published by the same developer 10 days after the first mode, Avast says there’s a high likelihood that downloaded code also exploited CVE-2021-38003.

In an email, Vojtěšek described the operation flow of the backdoor this way:

  1. The victim enters a game, playing one of the malicious game modes.

  2. The game loads as expected, but in the background, a malicious JavaScript contacts the game mode’s server.

  3. The game mode’s server code reaches out to the backdoor’s C&C server, downloads a piece of JavaScript code (presumably, the exploit for CVE-2021-38003), and returns the downloaded code back to the victim.

  4. The victim dynamically executes the downloaded JavaScript. If this was the exploit for CVE-2021-38003, this would result in shellcode execution on the victim machine.

Valve representatives didn’t respond to an email seeking comment for this story.

The researchers looked for additional Dota 2 game modes that exploited the vulnerability, but their trail went cold. Ultimately, that means it’s not possible to determine precisely what the developer’s intentions for the modes were, but the Avast post said there were two reasons to suspect they weren’t purely for benign research.

“First, the attacker did not report the vulnerability to Valve (which would generally be considered a nice thing to do),” Vojtěšek wrote. “Second, the attacker tried to hide the exploit in a stealthy backdoor. Regardless, it’s also possible that the attacker didn’t have purely malicious intentions either, since such an attacker could arguably abuse this vulnerability with a much larger impact.”

https://arstechnica.com/?p=1916611




Vulnerability Allows Hackers to Remotely Tamper With Dahua Security Cameras

Researchers have discovered a vulnerability that can be exploited by remote hackers to tamper with the timestamp of videos recorded by Dahua security cameras.

The flaw, tracked as CVE-2022-30564, was discovered last year by India-based CCTV and IoT cybersecurity company Redinent Innovations. Advisories describing the vulnerability were published on Wednesday by both Dahua and Redinent.

Redinent has assigned the vulnerability a ‘high’ severity rating, but Dahua has calculated a 5.3 CVSS score for it, which makes it ‘medium severity’.

According to the Chinese video surveillance equipment maker, the flaw impacts several types of widely used cameras and video recorders, including IPC, SD, NVR, and XVR products. 

An attacker can exploit the vulnerability to modify a device’s system time by sending it a specially crafted packet. 

Redinent says there are thousands of internet-exposed cameras that can be targeted directly by hackers. Exploitation from the local network is also possible. However, the company noted that an attacker needs to have knowledge of an APIs parameters in order to exploit the vulnerability. 

“An attacker can make modification to the timestamp of the video feed, leading to inconsistent date and time showing up on the recorded video, without the need of knowing the username and password of the camera. It has a direct impact on digital forensics,” Redinent explained in its advisory.

Dahua device vulnerabilities may be targeted by DDoS botnets, but in the case of CVE-2022-30564, it would most likely be exploited in highly targeted attacks whose goal is to tamper with evidence, rather than cybercrime operations. 

The issue was reported to the vendor in the fall of 2022. Dahua has released patches for each of the impacted devices. 

In December, Redinent disclosed a vulnerability affecting Hikvision wireless bridges. Exploitation of the flaw could lead to remote CCTV hacking. 

Related: Backdoor Found in Dahua Video Recorders, Cameras

Related: CISA Warns of Hikvision Camera Flaw as U.S. Aims to Rid Chinese Gear From Networks

Related: FCC: Telecom Firms Requested $5.6 Billion to Replace Chinese Gear

https://www.securityweek.com/vulnerability-allows-hackers-to-remotely-tamper-with-dahua-security-cameras/




Chrome 110 Patches 15 Vulnerabilities

Google this week announced that the first stable release of Chrome 110 brings 15 security fixes, including 10 that address vulnerabilities reported by external researchers.

Of the externally reported bugs, three are rated ‘high severity’. These include a type confusion flaw in the V8 engine, an inappropriate implementation issue in full screen mode, and an out-of-bounds read vulnerability in WebRTC.

Tracked as CVE-2023-0696, the first of the security defects is described as a heap corruption that can be exploited remotely via a crafted HTML page. Google paid a $7,000 bug bounty to the reporting researcher.

The second high-severity flaw, CVE-2023-0697, impacts Chrome for Android and could allow a remote attacker to use a crafted HTML page to spoof the contents of the security UI. Google rewarded the reporting researcher $4,000 for this bug.

CVE-2023-0698, the third issue, could be exploited remotely via an HTML page to perform an out-of-bounds memory read. The reporting researcher received a $2,000 bug bounty for the find, Google notes in its advisory.

Chrome 110 also resolves five medium-severity vulnerabilities reported by external researchers, including a use-after-free flaw in GPU, an inappropriate implementation bug in Download, a heap buffer overflow defect in WebUI, and two type confusion issues in Data Transfer and DevTools.

Google says it handed out over $26,000 in bug bounty rewards to the reporting researchers.

The internet giant makes no mention of any of these vulnerabilities being exploited in attacks.

The latest Chrome release is rolling out to users as versions 110.0.5481.77/.78 for Windows, and version 110.0.5481.77 for Mac and Linux.

The iOS and Android versions of the browser have been updated to 110.0.5481.83 and 110.0.5481.63/.64, respectively.

Related: Security Update for Chrome 109 Patches 6 Vulnerabilities

Related: Chrome 109 Patches 17 Vulnerabilities

Related: High-Severity Memory Safety Bugs Patched With Latest Chrome 108 Update

https://www.securityweek.com/chrome-110-patches-15-vulnerabilities/




OpenSSL Ships Patch for High-Severity Flaws

The OpenSSL Project on Tuesday shipped a major security update to cover at least eight documented security flaws that expose OpenSSL users to malicious hacker attacks.

The most serious of the bugs, a type confusion issue tracked as CVE-2023-0286, may allow an attacker to pass arbitrary pointers to a memcmp call, enabling them to read memory contents or launch denial-of-service exploits.

The OpenSSL maintainers slapped a high-severity rating on the flaw but notes that the vulnerability is most likely to only affect applications which have implemented their own functionality for retrieving CRLs over a network.

Organizations running OpenSSL versions 3.0, 1.1.1 and 1.0.2 are urged to apply available upgrades immediately.

The open-source project also documented seven moderate-severity issues that require urgent attention.

According to an OpenSSL advisory, these include:

  • A timing based side channel vulnerability (CVE-2022-4304) exists in the OpenSSL RSA Decryption implementation which could be sufficient to recover a plaintext across a network in a Bleichenbacher style attack. To achieve a successful decryption an attacker would have to be able to send a very large number of trial messages for decryption. The vulnerability affects all RSA padding modes: PKCS#1 v1.5, RSA-OEAP and RSASVE.  “An attacker that had observed a genuine connection between a client and a server could use this flaw to send trial messages to the server and record the time taken to process them.”
  • A read buffer overrun can be triggered in X.509 certificate verification, specifically in name constraint checking. The read buffer overrun (CVE-2022-4203) might result in a crash which could lead to a denial of service attack. “In theory it could also result in the disclosure of private memory contents (such as private keys, or sensitive plaintext) although we are not aware of any working exploit leading to memory contents disclosure as of the time of release of this advisory,” the group said.

The group also patched multiple memory corruption issues that exposes OpenSSL users to denial-of-service conditions.

Related: OpenSSL Flaw Severity Downgraded From Critical to High

Related: OpenSSL Vulnerability Can Be Exploited to Change Application Data

Related: High-Severity DoS Vulnerability Patched in OpenSSL

Related: OpenSSL Patches Remote Code Execution Vulnerability

https://www.securityweek.com/openssl-ships-patch-for-high-severity-flaws/




Vulnerability Provided Access to Toyota Supplier Management Network

A severe vulnerability in the web portal of Toyota’s global supplier management network allowed a security researcher to gain access to sensitive information.

The issue was identified by US-based researcher Eaton Zveare in Toyota’s Global Supplier Preparation Information Management System (GSPIMS), a web portal that provides Toyota employees and suppliers with access to ongoing projects, surveys, information on purchases, and more.

The issue, Zveare says, was related to the implementation of JWT (JSON Web Token) authentication and could allow access to any account to anyone using a valid email address.

Essentially, JWT is a session token that is typically generated when logging in to a website, and which is then used to authenticate the user to secure sections of the website or APIs.

What the researcher discovered was that Toyota’s GSPIMS contained a function that would allow users to generate a JWT based on the provided email address, without requiring a password.

With corporate Toyota email addresses easy to guess – as they are using the format [email protected] – the researcher was able to guess an email address by searching the internet for Toyota employees that might be involved in the supply chain.

Next, Zveare used that email address to generate a valid JWT and used it to access the GSPIMS. After some reconnaissance on the portal, he discovered an account with system administrator privileges and used the same method to access it.

The system admin account, the researcher says, provided access to everything on the portal, including information on over 14,000 user accounts, control over roles each account could have, details on all available projects, surveys, and various classified documents.

According to the researcher, the GSPIMS also provides the system admin with the option to log in as any of the available 14,000 users, to supervise their activities. The function that generates the JWT based on email address was apparently implemented to enable this option, but it also created a backdoor into the network.

An attacker with system admin access to GSPIMS could have created a rogue account for persistence, exfiltrated all available data, tampered with or deleted the data, and fetched the corporate email and roles of all 14,000 user accounts to target them in phishing attacks.

The researcher reported the vulnerability to Toyota on November 3, 2022. The car maker patched the issue shortly after.

Related: Toyota Discloses Data Breach Impacting Source Code, Customer Email Addresses

Related:Toyota’s Japan Production Halted Over Suspected Cyberattack

Related:Vulnerabilities Expose Lexus, Toyota Cars to Hacker Attacks

https://www.securityweek.com/vulnerability-provided-access-to-toyota-supplier-management-network/




Patch Released for Actively Exploited GoAnywhere MFT Zero-Day

A patch has been released for the GoAnywhere managed file transfer (MFT) software zero-day vulnerability whose existence came to light recently. News of active exploitation emerged roughly a week ago, but details about the attacks are still not available. 

Fortra, known until recently as HelpSystems, alerted GoAnywhere MFT users on February 1 about a ‘zero-day remote code injection exploit’. The company has since released two other security notifications, each of them providing mitigations and indicators of compromise (IoCs).

GoAnywhere users are now being informed that a patch has been made available. Users are advised to urgently install GoAnywhere MFT 7.1.2.

“Particularly for customers running an admin portal exposed to the Internet, we consider this an urgent matter,” the company said. 

GoAnywhere zero-day patch
GoAnywhere zero-day patch

There does not appear to be any information about the attacks exploiting the vulnerability. It’s unclear if it has been leveraged by state-sponsored threat actors or profit-driven cybercriminals.  

A CVE identifier has yet to be assigned to the flaw. 

Users have been told to check log files for a particular line that indicates a system has been targeted in an attack exploiting the zero-day vulnerability. If the log files show signs of compromise, users should check their installation for suspicious administrator users.

A researcher has published technical details on the flaw, as well as a proof-of-concept (PoC) exploit.

A Shodan search shows nearly 1,000 internet-exposed instances of GoAnywhere. However, the vendor pointed out that exploitation requires access to the application’s admin console, and at least some of the exposed instances appear to be associated with the product’s web client interface, which is not affected. 

Related: Zero-Day Vulnerability Exploited to Hack Over 1,000 Zimbra Email Servers

Related: US Agencies Warn of APTs Exploiting Recent ADSelfService Plus Zero-Day

Related: Accellion Failed to Notify Customers of FTA Zero-Day

https://www.securityweek.com/patch-released-for-actively-exploited-goanywhere-mft-zero-day/




VMware Says No Evidence of Zero-Day Exploitation in ESXiArgs Ransomware Attacks

VMware has urged customers to take action as unpatched ESXi servers continue to be targeted in ESXiArgs ransomware attacks.

Hackers are exploiting CVE-2021-21974, a high-severity ESXi remote code execution vulnerability related to OpenSLP that VMware patched in February 2021. Following successful exploitation, unidentified threat actors have deployed file-encrypting ransomware that targets virtual machines. 

Technical details and a proof-of-concept (PoC) exploit for CVE-2021-21974 have been around for nearly two years, but there is no indication that in-the-wild exploitation has been observed until now. 

In a blog post published on its Security Response Center on Monday, VMware said there is no evidence that the attacks involve exploitation of a zero-day vulnerability. 

“Most reports state that End of General Support (EOGS) and/or significantly out-of-date products are being targeted with known vulnerabilities which were previously addressed and disclosed in VMware Security Advisories,” the virtualization giant said. 

Attacks are possible because many organizations are running old and unpatched software.

“I’ve assessed nearly 500 owned boxes this evening, all of them are on old software releases. A shocking amount of orgs run ESXi on long end of life versions,” researcher Kevin Beaumont said on Monday. 

ESXiArgs ransomware attacks appear to have started on or around February 3. As of February 7, Censys shows nearly 2,500 compromised servers and Shodan shows more than 1,600. Most of the hacked systems are located in France, followed by the United States. 

On compromised systems, the hackers drop a ransom note instructing victims to pay roughly $50,000 in bitcoins in order to recover their files and prevent them from getting leaked. While the cybercriminals claim to have stolen data that they will sell unless a ransom is paid, there does not appear to be any evidence to date that files have actually been stolen in ESXiArgs attacks.

As for the malware used in these attacks, it seems to target files associated with virtual machines. 

In some cases, the malware’s encryption routine can partially fail, which could allow some victims to recover their data without paying a ransom. However, recovering files that have been properly encrypted seems impossible for the time being.

Cyble has published a technical analysis of the malware, including information on VM configuration file modifications, file encryption, persistence, and cleanup. 

Government cybersecurity agencies around the world, including in the United States, have issued alerts over the ESXiArgs ransomware attacks.

Related: VMware Patches VM Escape Flaw Exploited at Geekpwn Event

Related: VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities

https://www.securityweek.com/vmware-says-no-evidence-of-zero-day-exploitation-in-esxiargs-ransomware-attacks/