South Korean Users Targeted with Android Spyware ‘PhoneSpy’

More than 1,000 mobile phone users in South Korea have been targeted with a powerful piece of Android spyware as part of an ongoing campaign, according to a new report from Zimperium zLabs.

Dubbed PhoneSpy, the malware was designed with extensive spyware capabilities inside, such including data theft, audio and video capture, and location monitoring.

The malware was not found in any Android application stores, a suggestion that the attackers are employing different distribution methods, such as social engineering and web redirects. A total of 23 applications used in this campaign were identified to date, according to a report from Zimperium.

The threat masquerades as various lifestyle applications that allow users to watch TV or videos, or browse photos, but in reality it steals as much data from the infected devices as possible, including calls, messages, photos, and other types of data.

[ READ: Sophisticated APT Group Burned 11 Zero-Days in Mass Spying Operation ]

It also allows an attacker to remotely control the compromised devices, providing them with access to the camera and microphone to take pictures and record audio and video, as well as to the GPS, to get the device’s precise location.

In addition to grabbing calls, contact information, and messages from the infected devices, PhoneSpy can send SMS messages with attacker-controlled content. It can also display a fake login page for the Kakao Talk messaging app to steal users’ credentials.

“While the victims have been limited to South Korea, PhoneSpy is an example of how malicious applications can disguise their true intent. When installed on victims’ devices, they leave personal and corporate data at risk,” Zimperium said.

Related: Amnesty Links Indian Cybersecurity Firm to Spyware Attack on African Activist

Related: Google: Sophisticated APT Group Burned 11 Zero-Days in Mass Spying Operation

Related: Apple Points to Android Malware Infections in Argument Against Sideloading on iOS

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/south-korean-users-targeted-android-spyware-phonespy




Citrix Patches Critical Vulnerability in ADC, Gateway

Citrix this week released patches for a couple of vulnerabilities affecting Citrix ADC, Gateway, and SD-WAN, including a critical bug leading to denial of service (DoS).

The most severe of the two bugs is CVE-2021-22955, a critical security hole that could lead to a DoS condition on appliances that have been configured as a VPN (Gateway) or AAA virtual server.

The security flaw was identified in Citrix Application Delivery Controller (ADC, formerly NetScaler ADC), and Gateway (formerly NetScaler Gateway).

Tracked as CVE-2021-22956, the second flaw could lead to the temporary disruption of the Management GUI, Nitro API, and RPC communication.

Considered low severity, the bug affects ADC and Gateway, as well as SD-WAN WANOP edition models 4000-WO, 4100-WO, 5000-WO, and 5100-WO, Citrix explains in an advisory.

Citrix addressed both vulnerabilities in ADC and Gateway 13.1-4.43 and later releases of 13.1, 13.0-83.27 and later releases of 13.0, 12.1-63.22 and later releases of 12.1, and 11.1-65.23 and later releases of 11.1, and in ADC 12.1-FIPS 12.1-55.257 and later releases of 12.1-FIPS.

CVE-2021-22956, Citrix says, was addressed in SD-WAN WANOP Edition 11.4.2 and later releases of 11.4, and 10.2.9c and later releases of 10.2.

“Please note that the WANOP feature of SD-WAN Premium Edition is not impacted,” Citrix notes.

Affected Citrix customers are encouraged to install the available patches as soon as possible.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged users and administrators to review Citrix’s advisory and apply the necessary updates.

Related: Citrix Patches Hypervisor Vulnerabilities Allowing Host Compromise

Related: Citrix Patches DoS Vulnerabilities in Hypervisor

Related: Citrix Releases Updates to Prevent DDoS Attacks Abusing Its Appliances

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/citrix-patches-critical-vulnerability-adc-gateway




14 New Vulnerabilities Discovered in BusyBox

Researchers from software development company JFrog and industrial cybersecurity firm Claroty have identified a total of 14 new vulnerabilities in BusyBox, and on Tuesday they detailed some of their findings.

The security holes found by Claroty and JFrog can be exploited for denial-of-service (DoS) attacks and in some cases they can lead to information disclosure or remote code execution, but they have all been assigned a severity rating of medium and they are unlikely to ever be exploited for malicious purposes.

BusyBox is an open source project that brings together many common Unix tools into a single binary. BusyBox is widely used by embedded devices, including IoT products and industrial control systems (ICS).

There are certain requirements for exploiting the vulnerabilities discovered by Claroty and JFrog, including the attacker being able to control all parameters passed to a vulnerable applet, supplying a specially crafted file, and supplying specially crafted command lines.

Researchers conducted a manual review of the BusyBox source code and leveraged fuzzing to identify the vulnerabilities.

“To assess the threat level posed by these vulnerabilities, we inspected JFrog’s database of more than 10,000 embedded firmware images (composed of only publicly available firmware images, and not ones uploaded to JFrog Artifactory),” the researchers explained. “We found that 40% of them contained a BusyBox executable file that is linked with one of the affected applets, making these issues extremely widespread among Linux-based embedded firmware.”

The researchers noted that while the DoS flaws are easy to exploit, they are mitigated by applets typically running as a separate forked process. They also pointed out that the information disclosure vulnerability they have found is not easy to exploit, and the exploitation of the use-after-free bugs that can lead to remote code execution involves an uncommon scenario.

BusyBox developers patched all of the vulnerabilities in August with the release of version 1.34.0. Workarounds are also available.

JFrog and Claroty have published a blog post describing their findings. They have shared technical information for one of the vulnerabilities they have found, CVE-2021-42374, which can lead to information leaks and DoS.

Cybercriminals targeting BusyBox devices and abusing BusyBox commands to achieve their goals is not uncommon — examples include DDoS botnets such as Mirai and Bashlite — but attacks typically leverage poor security practices rather than vulnerabilities in BusyBox.

Related: Nearly 1,000 Vulnerabilities Found in Popular Open Source Projects in 2019

Related: Facebook Open-Sources ‘Mariana Trench’ Code Analysis Tool

Related: Google Expands Open Source Vulnerabilities Database

view counter

Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.

Previous Columns by Eduard Kovacs:
Tags:

https://www.securityweek.com/14-new-vulnerabilities-discovered-busybox




SAP Patches Critical Vulnerability in ABAP Platform Kernel

SAP on Tuesday announced the release of five new and two updated security notes as part of its November 2021 Security Patch Day, including one note that deals with a critical vulnerability in ABAP Platform Kernel.

Rated Hot News, which is SAP’s highest severity rating, the most severe of the new security notes addresses CVE-2021-40501 (CVSS score of 9.6), a missing authorization check vulnerability in ABAP Platform Kernel.

An authenticated business user could exploit the security hole to escalate their privileges on a vulnerable system, which would enable them to read and modify otherwise restricted data.

“The vulnerability affects trusted connections to other systems via RFC and HTTP communication, allowing the user to execute application-specific logic in other systems,” enterprise app security firm Onapsis explains.

SAP also addressed a high-severity missing authorization check in SAP Commerce, which too could allow an authenticated user to escalate privileges. Tracked as CVE-2021-40502 (CVSS score of 8.3), the bug affects all installations that use Commerce Organization.

SAP also released an updated high-priority security note addressing hardcoded credentials in CA Introscope Enterprise Manager, which was initially patched in 2020.

While these are the only two high-priority notes SAP has included in its advisory, Onapsis mentions a third such note (CVSS score of 7.9), which deals with known denial of service (DoS) vulnerabilities in open source dependencies used by Forecasting and Replenishment for Retail (FRP or F&R).

The note was released after the second Tuesday of October but before the second Tuesday of this month, the same as three other medium-priority notes.

SAP included four medium-priority security notes in this month’s advisory, one of which is an update for a September 2021 note. The notes address an information disclosure in GUI for Windows, missing authorization checks in ERP HCM and ERP Financial Accounting, and a leverage of permission in NetWeaver Application Server for ABAP and ABAP Platform.

Related: SAP Patches Critical Vulnerabilities in Environmental Compliance

Related: SAP Patches Critical Vulnerabilities With September 2021 Security Updates

Related: Nine Critical and High-Severity Vulnerabilities Patched in SAP Products

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

https://www.securityweek.com/sap-patches-critical-vulnerability-abap-platform-kernel




US Offers $10 Million Bounty in Hunt for DarkSide Ransomware Operators

US Goverment Offers $10 Million Reward for Data on Leaders and Members of DarkSide Ransomware Operation

The U.S. government wants to find the people responsible for the Colonial Pipeline ransomware attack and it’s putting up multi-million rewards for data on the operators behind the DarkSide extortion campaign.

The Department of State on Thursday offered up to $10 million for information leading to the identification or location of senior members of the DarkSide gang that caused major gas disruptions earlier this year.

In addition, the U.S. State Department is offering a reward of up to $5 million for information leading to the arrest and/or conviction in any country “of any individual conspiring to participate in or attempting to participate in a DarkSide variant ransomware incident.”

In a statement, the State Department said the DarkSide ransomware group was responsible for the Colonial Pipeline Company ransomware incident in May 2021, which led to the company’s decision to proactively and temporarily shut down the 5,500-mile pipeline that carries 45 percent of the fuel used on the East Coast of the United States. 

“In offering this reward, the United States demonstrates its commitment to protecting ransomware victims around the world from exploitation by cyber criminals,” it added. “The United States looks to nations who harbor ransomware criminals that are willing to bring justice for those victim businesses and organizations affected by ransomware.”

[ READ: REvil Ransomware Gang Hit by Law Enforcement Hack-Back ]

The rewards are being offered under the Department of State’s Transnational Organized Crime Rewards Program (TOCRP).

The latest reward offer follows a recent law enforcement operation against the REvil ransomware gang and signals an aggressive new approach to fighting back against the ransomware epidemic.

In that operation, the Tor servers associated with the REvil ransomware gang were seized in what was described as a “multi-country” hack-back operation that remains active.

The ransomware group’s public blog, which was used to name-and-shame organizations into paying multi-million data recovery ransoms, was knocked offline. A goodbye message from one of the operators read: “The server was compromised, and they were looking for me. Good luck, everyone; I’m off,” 

Threat hunters tracking underground human-operated ransomware operations confirmed the REvil shutdown, which was carried out by foreign partner of the U.S. government.

Several other competing ransomware groups responded to the REvil network takeover by moving cryptocurrency reserves and even publicly complaining about the hack-back operation.

[ READ: Colonial Pipeline CEO Explains $4.4M Ransomware Payment ]

The infamous REvil gang was caught using the Darkside data encryption tool in human-operated ransomware attacks against multiple U.S. companies. These included the Colonial Pipeline cyberattack that forced a shutdown of gas stations and the Kaseya supply-chain compromise.

The U.S. government recently identified approximately $5.2 billion in outgoing Bitcoin transactions that are potentially linked to ransomware payments, mostly to cybercriminal gangs in Russia and Eastern Europe.

Related: REvil Ransomware Gang Hit by Law Enforcement Hack-Back

Related: Black Hat 2021: New CISA Boss Unveils Anti-Ransomware Collab

Related: DarkSide Ransomware Shutdown: An Exit Scam or Running for Hills

Related: Colonial Pipeline CEO Explains $4.4M Ransomware Payment

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/lZyCjS04BxY/us-gov-offering-10m-reward-data-darkside-ransomware-operators




Cisco Plugs Critical Holes in Catalyst PON Enterprise Switches

Enterprise networking giant Cisco has released patches for multiple vulnerabilities across its product portfolio, including critical security defects in Catalyst Passive Optical Network (PON) series switches and the Policy Suite product.

The most severe of these issues are CVE-2021-34795 and CVE-2021-40113 (CVSS 10.0), two flaws in Catalyst PON switches that could be exploited to log in to a vulnerable device using unintentional debugging credentials, or to perform unauthenticated command injection, Cisco said in an advisory.

The company said CVE-2021-34795 exists in the Telnet service of Cisco Catalyst PON series switches ONT and could be exploited to establish a Telnet session to the device using the default credential. The bug would allow the attacker to take over the vulnerable device.

The second CVE-2021-40113 bug affects the web-based management interface of the enterprise switches and could be exploited remotely, without authentication. Because user-supplied input isn’t sufficiently validated, the flaw allows an attacker to execute commands as root.

[ READ: ‘Dangerous Code Execution Flaw in Linux Kernel Module ]

A third vulnerability Cisco addressed in the same products (Catalyst PON switch CGP-ONT-1P, CGP-ONT-4P, CGP-ONT-4PV, CGP-ONT-4PVC, and CGP-ONT-4TVCW models) could be exploited remotely without authentication to modify the configuration of the device. The bug is tracked as CVE-2021-40112 (CVSS 8.6).

This week, Cisco also patched a critical security hole in the key-based SSH authentication mechanism of Policy Suite. Tracked as CVE-2021-40119 (CVSS score of 9.8), the issue could allow an unauthenticated, remote attacker to log into a vulnerable device as root.

The vulnerability exists because static SSH keys are used across installations, meaning that an adversary could extract the keys from an attacker-controlled system and then log in to a vulnerable system.

On Wednesday, Cisco also announced patches for a high-severity vulnerability (CVE-2021-34739, CVSS score 8.1) in small business switches that could allow an attacker to replay valid user session credentials to access a vulnerable device remotely.

READ: High-Severity Flaws in Cisco Security Appliances, Business Switches ]

A high-severity flaw (CVE-2021-34741, CVSS score of 7.5) in AsyncOS software for Cisco Email Security Appliance (ESA) could be exploited by a remote attacker to cause a denial of service condition. The issue exists because of insufficient input validation of incoming emails and does not require authentication for successful exploitation.

Additionally, Cisco released patches for multiple medium-severity security errors in Webex, Umbrella, Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM), Unified Communications, Common Services Platform Collector (CSPC), Prime Access Registrar, and AnyConnect Secure Mobility Client for Windows.

However, the company also announced that a couple of medium-severity issues identified in Small Business 200, 300, and 500 series switches and RV series routers will remain unpatched, as these products have reached end-of-life.

Cisco said it was not aware of any of these vulnerabilities being exploited in the wild.

Related: Cisco Patches High-Severity DoS Vulnerabilities in ASA, FTD Software

Related: High-Severity Flaws in Cisco Security Appliances, Business Switches

Related: Cisco Patches Critical Vulnerabilities in IOS XE Software

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/_K3GcqAFbXs/cisco-plugs-critical-holes-catalyst-pon-enterprise-switches




Linux Foundation Fixes ‘Dangerous’ Code Execution Kernel Bug

Researchers are calling attention to a newly discovered security defect in a kernel module that ships with all major Linux distributions, warning that remote attackers can exploit the bug to take complete control of a vulnerable system.

The vulnerability — CVE-2021-43267 — is described as a heap overflow in the TIPC (Transparent Inter-Process Communication) module that ships with the Linux kernel to allow nodes in a cluster to communicate with each other in a fault-tolerant way.

“The vulnerability can be exploited either locally or remotely within a network to gain kernel privileges, allowing an attacker to compromise the entire system,” according to a warning from SentinelOne’s Max Van Amerongen, the security researcher who found — and helped fix — the underlying vulnerability.

Van Amerongen said he discovered the bug almost by accident using Microsoft’s CodeQL, an open-source semantic code analysis engine that helps ferret out security defects at scale.

[ READ: Google Triples Bounty for Linux Kernel Exploitation ]

He said the flaw was introduced in the Linux kernel in September 2020 when a new user message type called MSG_CRYPTO was added to allow peers to send cryptographic keys. Looking at the code, Van Amerongen found a “clear-cut kernel heap buffer overflow” with remote exploit implications.

Although the vulnerable TIPC module comes with all major Linux distributions, it needs to be loaded in order to enable the protocol and trigger the vulnerability.

The Linux foundation shipped a patch on October 29 and confirmed the underlying vulnerability affects kernel versions between 5.10 and 5.15.

SentinelOne said Thursday it had not seen evidence of in-the-wild abuse.

“This vulnerability can be exploited both locally and remotely. While local exploitation is easier due to greater control over the objects allocated in the kernel heap, remote exploitation can be achieved thanks to the structures that TIPC supports,” Van Amerongen notes. 

While TIPC itself isn’t loaded automatically by the system and has to be enabled by end users, Van Amerongen said the ability to configure it from an unprivileged local perspective and the possibility of remote exploitation “makes this a dangerous vulnerability” for those that use it in their networks

“As this vulnerability was discovered within a year of its introduction into the codebase, TIPC users should ensure that their Linux kernel version is not between 5.10-rc1 and 5.15,” he added. 

Related: GitHub Announces General Availability of Code Scanning Feature

Related: Google Triples Bounty for Linux Kernel Exploitation

Related: GitHub Discloses Details of Easy-to-Exploit Linux Vulnerability

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/uTYxjQPwCYI/linux-foundation-fixes-dangerous-code-execution-kernel-bug




MITRE, CISA Announce 2021 List of Most Common Hardware Weaknesses

MITRE and the DHS’s Cybersecurity and Infrastructure Security Agency (CISA) have announced the release of the “2021 Common Weakness Enumeration (CWE) Most Important Hardware Weaknesses” list.

Composed of the most frequent and critical errors that result in serious hardware vulnerabilities, the list includes a total of 12 entries, with five additional weaknesses that scored just outside the final list also mentioned.

The list is meant to raise awareness of common hardware weaknesses and to help prevent hardware vulnerabilities at the source, MITRE says.

In addition to instructing designers and programmers on how errors can be eliminated during product development, the list can help analysts and engineers plan security testing and evaluation, as well as consumers to ask suppliers to deliver more secure hardware.

The list is also expected to help managers and CIOs assess the progress of their efforts to secure hardware and to decide where resources should be directed to build tools and automation processes to mitigate a wide class of vulnerabilities, MITRE notes.

The final 2021 CWE Most Important Hardware Weaknesses list includes the 12 entries that scored highest during analysis.

 2021 CWE Most Important Hardware Weaknesses

Five other weaknesses (the Hardware Weaknesses on the Cusp) scored just outside of the final list, but risk-decision makers and those performing mitigations should still consider these in their analyses, MITRE says.

Although the methodology used to create the list resulted in a ranking for the 12(+5) CWEs, the hardware team and the Hardware CWE Special Interest Group (SIG) believe that the list should not be viewed as a hierarchical, ordered set when it comes to the importance of each weakness.

“The entries should be thought of as a set of mostly equal hardware weakness concerns based on our methodology,” MITRE notes.

Future versions of the CWE Most Important Hardware Weaknesses are expected to include other entries, aiming to deliver a list considered to be the most useful for the community.

The United States Cybersecurity and Infrastructure Security Agency (CISA) encourages users and administrators to review the list and the recommended mitigations, to determine which are suitable to adopt.

“The 2021 Hardware List is a compilation of the most frequent and critical errors that can lead to serious vulnerabilities in hardware. An attacker can often exploit these vulnerabilities to take control of an affected system, obtain sensitive information, or cause a denial-of-service condition,” CISA notes.

Related: OWASP Top 10 Updated With Three New Categories

Related: What We Learn from MITRE’s Most Dangerous Software Weaknesses List

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/CcKvBH0s8Xs/mitre-cisa-announce-2021-list-most-common-hardware-weaknesses




HelpSystems Expands Shopping Spree With Digital Guardian Acquisition

Minnesota-based IT management and software powerhouse HelpSystems expanded its year-long cybersecurity shopping spree with a new deal to acquire data loss prevention specialists Digital Guardian.

Financial terms of the acquisition were not released.   

Digital Guardian is a late-stage Massachusetts-based startup that raised $173 million over multiple venture capital funding rounds.  The company has gained traction in large and mid-sized organizations looking for DLP tools to protect sensitive data and corporate assets.

Digital Guardian also provides a managed service that operates as an extension of an enterprise security team to protect sensitive data from threats originating inside and outside the organization.

[ READ: Inside the Battle to Control Enterprise Security Data Lakes ]

HelpSystems said the Digital Guardian’s technology will plug right into a data security portfolio that swelled in 2021 through multiple acquisitions of prominent cybersecurity startups.

Just this year, HelpSystems acquired Agari (email security), Beyond Security (vulnerability management), Vera (data security and control), PhishLabs (email security) and Digital Defense (network security)..

“In addition to extending HelpSystems’ DLP capability, this acquisition further improves the company’s ability to categorize, or classify, data and protect it across a wide set of applications and operating systems,” HelpSystems said in a statement announcing the latest purchase.

HelpSystems is owned by private equity firms HGGC, TA Associates, Charlesbank Capital Partners, and Harvest Partners.

Related: HelpSystems Acquires Vera to Broaden Data Security Portfolio

Related: For Microsoft, Security is a $10 Billion Business

Related: Inside the Battle to Control Enterprise Security Data Lakes

view counter

Ryan Naraine is Editor-at-Large at SecurityWeek and host of the popular Security Conversations podcast series. He is a journalist and cybersecurity strategist with more than 20 years experience covering IT security and technology trends.
Ryan has built security engagement programs at major global brands, including Intel Corp., Bishop Fox and Kaspersky GReAT. He is a co-founder of Threatpost and the global SAS conference series. Ryan’s career as a journalist includes bylines at major technology publications including Ziff Davis eWEEK, CBS Interactive’s ZDNet, PCMag and PC World.
Ryan is a director of the Security Tinkerers non-profit, and a regular speaker at security conferences around the world.
Follow Ryan on Twitter @ryanaraine.

Previous Columns by Ryan Naraine:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/Vrngud9osXU/helpsystems-expands-shopping-spree-digital-guardian-acquisition




Shrootless: macOS Vulnerability Found by Microsoft Allows Rootkit Installation

Microsoft on Thursday published information on a vulnerability in Apple’s macOS platform that could allow an attacker to bypass System Integrity Protection (SIP) and modify operating system files.

Tracked as CVE-2021-30892 and named “Shrootless” by Microsoft, the vulnerability exists in the method used to install Apple-signed packages with post-install scripts.

To successfully exploit the vulnerability, an attacker needs to create a specially crafted file that would allow them to hijack the installation process of said packages.

Apple introduced SIP in macOS Yosemite to restrict root users from performing actions leading to system integrity compromise, but the newly addressed security error could allow an attacker to install a malicious kernel driver (rootkit), deploy persistent malware, or overwrite system files.

Also referred to as rootless, SIP locks the system from boot time, to keep the platform protected, and can only be modified when the machine is in recovery mode.

Apple also improved SIP restrictions to harden it, but included several exceptions (entitlements) for specific Apple processes, such as system updates, which have unrestricted access to SIP-protected directories.

What Microsoft discovered was that the entitlement for the daemon system_installd allows for child processes to bypass SIP filesystem restrictions.

Such is the case with Apple-signed packages (.pkg files). Should post-install scripts be included in the package, system_installd executes them by invoking the default shell, zsh.

“When zsh starts, it looks for the file /etc/zshenv, and—if found—runs commands from that file automatically, even in non-interactive mode. Therefore, for attackers to perform arbitrary operations on the device, a fully reliable path they could take would be to create a malicious /etc/zshenv file and then wait for system_installd to invoke zsh,” Microsoft explains.

The tech giant also explains that zshenv could be abused as a general attack technique, given that there’s an equivalent of /etc/zshenv for each user, “which has the same function and behavior but doesn’t require root permissions to write to.”

Apple addressed the vulnerability with the macOS Big Sur 11.6.1 update, which started rolling out on October 26, containing patches for 23 other vulnerabilities. This week Apple also released iOS 15.1 and iPadOS 15.1, with patches for 22 security flaws.

Related: PoC Exploit Released for macOS Gatekeeper Bypass

Related: Apple Ships iOS 15 with MFA Code Generator

Related: Apple Patches Recent Sudo Vulnerability in macOS

view counter

Ionut Arghire is an international correspondent for SecurityWeek.

Previous Columns by Ionut Arghire:
Tags:

http://feedproxy.google.com/~r/securityweek/~3/dN5IcBVibg0/shrootless-macos-vulnerability-found-microsoft-allows-rootkit-installation