Google Patches Vulnerability in Cloud Endpoints Proxy
A researcher has disclosed the details of a privilege escalation vulnerability he discovered in a Google Cloud component. The flaw was patched by Google in late August, but some users will need to manually update their systems to prevent potential exploitation.
The vulnerability was found by security researcher Imre Rad, who disclosed his findings last week on the Full Disclosure mailing list.
Rad found the vulnerability in Extensible Service Proxy (ESP), an open source, Nginx-based proxy that enables API management capabilities for JSON/REST or gRPC API services. Its features include authentication, monitoring and logging. ESP is a component of Google’s Cloud Endpoints API management system, which is designed for securing, monitoring and analyzing APIs.
“If SSO is configured for an ESP fronted application where the identity provider is one of the popular ones (Google or Facebook) or an organization’s internal IdP (e.g. Okta), then those API methods can be invoked by a malicious user assuming the identity of anyone,” the researcher told SecurityWeek.
He noted that not all applications that use ESP are affected — applications based on PHP/Symfony are impacted, and possibly also some less popular frameworks. The researcher believes between 100 and 1,000 applications are affected, but he says this is a “gut feeling.”
The vulnerability impacts ESP v1 and certain configurations — the researcher says ESP v2 is not affected. He also noted that some users will need to manually install the patches.
“Unlike with other services (e.g. MySQL instances of the Cloud SQL product), the ESP software is not operated by Google, so the burden of upgrade is on the customers. (Using ESP on AppEngine may be an exception, I think Google bumps the version there.) In line with this architecture, Google is not in the position to prevent abuse globally by implementing some magical server-side fix,” Rad explained.
Google has awarded a bug bounty for the vulnerability report, but the researcher did not want to disclose the exact amount — he said it was several thousand dollars.
“We rolled out a fix on August 31, 2021 to address this issue and ensure that all services are protected. We’re appreciative of the researcher’s work in identifying and reporting this vulnerability,” a Google spokesperson told SecurityWeek.
Google did not respond to follow-up questions regarding the number of impacted applications and users having to manually update the affected component.
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
Threat Actor Promises Pegasus Spyware Protection, Serves Trojan Instead
A threat group is distributing the little-known Sarwent Trojan via a fake website that impersonates Amnesty International and claims to deliver protection against the Pegasus mobile malware.
According to security researchers at Cisco Talos, the attack targets individuals who believe they might have been targeted by the NSO Group’s Pegasus spyware and might be associated with nation-state activity, but Talos has yet to identify links to a specific threat actor.
Initially detailed in 2016, Pegasus is a controversial surveillance software tool that, despite claims of legitimate use, has been reportedly used by oppressive regimes in campaigns targeting journalists, human rights activists, and other individuals opposing the regime.
Following a detailed Amnesty International report on Pegasus released in July this year, and Apple issuing patches for the ForcedEntry zero-day exploit, many people started searching for protection against the spyware, and adversaries decided to take advantage of that.
A fake website designed to look similar to that of Amnesty International, the threat actor claims to be offering “Amnesty Anti Pegasus,” an anti-virus tool that can supposedly protect against NSO Group’s spyware.
Instead, however, users are served the Sarwent remote access tool (RAT), which allows attackers to easily upload and execute payloads on the compromised machines, as well as to exfiltrate any data deemed to be of interest.
Although low volume, the campaign has snagged victims worldwide, including in the United States, the United Kingdom, Colombia, Czech Republic, India, Romania, Russia, and Ukraine, according to the Cisco Talos report.
The adversary behind the campaign appears to be a Russian speaker that has been using Sarwent since at least January 2021, targeting all types of individuals globally. The threat actor likely used the Trojan or one with a similar backend since 2014, the security researchers say.
“Given the available data, we remain uncertain about the intentions of the actor. The use of Amnesty International’s name, an organization whose work often puts it at odds with governments around the world, as well as the Pegasus brand, a malware that has been used to target dissidents and journalists on behalf of governments, certainly raises concerns about who exactly is being targeted and why,” Cisco Talos said.
Hackers Can Exploit Apple AirTag Vulnerability to Lure Users to Malicious Sites
Apple’s AirTag product is affected by a vulnerability that could be exploited by hackers to lure unsuspecting users to phishing or other types of malicious websites.
Security consultant Bobby Rauch discovered that AirTags, which Apple sells for $30 and advertises as a “supereasy way to keep track of your stuff,” are affected by a stored cross-site scripting (XSS) vulnerability.
While the issue has not been patched by Apple, Rauch disclosed its details this week after becoming frustrated with the tech giant’s vulnerability reporting process.
When AirTag users enable “lost mode” to indicate that they cannot locate the device, they can add their phone number and a custom message that will be displayed to anyone who finds and scans the AirTag with an NFC phone — this includes Android phones.
Rauch noticed that the unique page generated on the found.apple.com domain for each AirTag is affected by a stored XSS vulnerability. More precisely, the XSS flaw can be exploited by inserting a malicious payload into the phone number field on the page.
In a theoretical attack scenario described by the researcher, the attacker enables “lost mode” for their own AirTag and intercepts the request associated with this action. They then inject the malicious payload into the phone number field. The attacker then needs to drop the AirTag device in a location where the targeted user — or anyone, if the attack is opportunistic — picks it up and scans it. Once the AirTag is scanned, the malicious payload is triggered immediately.
Rauch demonstrated the attack by injecting a payload that redirects the victim to an iCloud phishing page. Since it’s an Apple product, the victim might not find an iCloud login page to be suspicious — in reality, users who find and scan an AirTag don’t need to provide any credentials.
In addition to directing users to phishing pages, an attacker could lure users to malware distribution websites, or they could inject a payload for session token hijacking or clickjacking. The researcher also noted that the attacker could leverage the malicious found.apple.com link by sending it directly to the targeted user on a desktop or laptop device — in this case the payload is triggered when the link is accessed and there is no need to scan the AirTag.
Rauch told cybersecurity blogger Brian Krebs that he reported his findings to Apple on June 20, and decided to publicly disclose the vulnerability after becoming frustrated with Apple’s slow progress and refusal to answer his questions about giving him credit for the vulnerability and a possible bug bounty.
SecurityWeek has reached out to Apple for comment and will update this article if the company responds.
This is the second time in recent days that a researcher has disclosed the details of a vulnerability before Apple could release a patch. Researcher Denis Tokarev (aka illusionofchaos) has made public the details of three iOS vulnerabilities that were reported to Apple months ago, but which the tech giant failed to address.
Many cybersecurity experts have complained over the past years about Apple’s bug bounty program, including due to delayed responses and rewards they considered too small. The company said it awarded a total of $3.7 million to the researchers who responsibly disclosed security flaws last year.
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
Three iOS 0-days revealed by researcher frustrated with Apple’s bug bounty
Enlarge/ Pseudonymous researcher illusionofchaos joins a growing legion of security researchers frustrated with Apple’s slow response and inconsistent policy adherence when it comes to security flaws.
Aurich Lawson | Getty Images
Yesterday, a security researcher who goes by illusionofchaos dropped public notice of three zero-day vulnerabilities in Apple’s iOS mobile operating system. The vulnerability disclosures are mixed in with the researcher’s frustration with Apple’s Security Bounty program, which illusionofchaos says chose to cover up an earlier-reported bug without giving them credit.
This researcher is by no means the first to publicly express their frustration with Apple over its security bounty program.
Nice bug—now shhh
illusionofchaos says that they’ve reported four iOS security vulnerabilities this year—the three zero-days they publicly disclosed yesterday plus an earlier bug that they say Apple fixed in iOS 14.7. It appears that their frustration largely comes from how Apple handled that first, now-fixed bug in analyticsd.
This now-fixed vulnerability allowed arbitrary user-installed apps to access iOS’s analytics data—the stuff that can be found in Settings --> Privacy --> Analytics & Improvements --> Analytics Data—without any permissions granted by the user. illusionofchaos found this particularly disturbing, because this data includes medical data harvested by Apple Watch, such as heart rate, irregular heart rhythm, atrial fibrillation detection, and so forth.
Analytics data was available to any application, even if the user disabled the iOS Share Analytics setting.
According to illusionofchaos, they sent Apple the first detailed report of this bug on April 29. Although Apple responded the next day, it did not respond to illusionofchaos again until June 3, when it said it planned to address the issue in iOS 14.7. On July 19, Apple did indeed fix the bug with iOS 14.7, but the security content list for iOS 14.7 acknowledged neither the researcher nor the vulnerability.
Apple told illusionofchaos that its failure to disclose the vulnerability and credit them was just a “processing issue” and that proper notice would be given in “an upcoming update.” The vulnerability and its resolution still were not acknowledged as of iOS 14.8 on September 13 or iOS 15.0 on September 20.
Frustration with this failure of Apple to live up to its own promises led illusionofchaos to first threaten, then publicly drop this week’s three zero-days. In illusionofchaos‘ own words: “Ten days ago I asked for an explanation and warned then that I would make my research public if I don’t receive an explanation. My request was ignored so I’m doing what I said I would.”
We do not have concrete timelines for illusionofchaos‘ disclosure of the three zero-days, or of Apple’s response to them—but illusionofchaos says the new disclosures still adhere to responsible guidelines: “Google Project Zero discloses vulnerabilities in 90 days after reporting them to vendor, ZDI – in 120. I have waited much longer, up to half a year in one case.”
New vulnerabilities: Gamed, nehelper enumerate, nehelper Wi-Fi
The zero-days illusionofchaos dropped yesterday can be used by user-installed apps to access data that those apps should not have or have not been granted access to. We’ve listed them below—along with links to illusionofchaos‘ Github repos with proof-of-concept code—in order of (our opinion of) their severity:
Gamed zero-day exposes Apple ID email and full name, exploitable Apple ID authentication tokens, and read access to Core Duet and Speed Dial databases
Nehelper Wi-Fi zero-day exposes Wi-Fi information to apps that have not been granted that access
The Gamed 0-day is obviously the most severe, since it both exposes Personal Identifiable Information (PII) and may be used in some cases to be able to perform actions at *.apple.com that would normally need to be either instigated by the iOS operating system itself, or by direct user interactions.
The Gamed zero-day’s read access to Core Duet and Speed Dial databases is also particularly troubling, since that access can be used to gain a pretty complete picture of the user’s entire set of interactions with others on the iOS device—who is in their contact list, who they’ve contacted (using both Apple and third-party applications) and when, and in some cases even file attachments to individual messages.
The Wi-Fi zero-day is next on the list, since unauthorized access to the iOS device’s Wi-Fi info might be used to track the user—or, possibly, learn the credentials necessary to access the user’s Wi-Fi network. The tracking is typically a more serious concern, since physical proximity is generally required to make Wi-Fi credentials themselves useful.
One interesting thing about the Wi-Fi zero-day is the simplicity of both the flaw and the method by which it can be exploited: “XPC endpoint com.apple.nehelper accepts user-supplied parameter sdk-version, and if its value is less than or equal to 524288, com.apple.developer.networking.wifi-info entitlement check is skipped.” In other words, all you need to do is claim to be using an older software development kit—and if so, your app gets to ignore the check that should disclose whether the user consented to access.
The Nehelper Enumerate zero-day appears to be the least damaging of the three. It simply allows an app to check whether another app is installed on the device by querying for the other app’s bundleID. We haven’t come up with a particularly scary use of this bug on its own, but a hypothetical malware app might leverage such a bug to determine whether a security or antivirus app is installed and then use that information to dynamically adapt its own behavior to better avoid detection.
Conclusions
Assuming illusionofchaos‘ description of their disclosure timeline is correct—that they’ve waited for longer than 30 days, and in one case 180 days, to publicly disclose these vulnerabilities—it’s hard to fault them for the drop. We do wish they had included full timelines for their interaction with Apple on all four vulnerabilities, rather than only the already-fixed one.
We can confirm that this frustration of researchers with Apple’s security bounty policies is by no means limited to this one pseudonymous researcher. Since Ars published a piece earlier this month about Apple’s slow and inconsistent response to security bounties, several researchers have contacted us privately to express their own frustration. In some cases, researchers included video clips demonstrating exploits of still-unfixed bugs.
We have reached out to Apple for comment, but we have yet to receive any response as of press time. We will update this story with any response from Apple as it arrives.
https://arstechnica.com/?p=1798279
AMD Chipset Driver Vulnerability Can Allow Hackers to Obtain Sensitive Data
Chipmaker AMD has patched a driver vulnerability that could allow an attacker to obtain sensitive information from the targeted system.
The flaw, tracked as CVE-2021-26333 and classified by AMD as medium severity, affects the company’s Platform Security Processor (PSP) chipset driver, which is used by several graphics cards and processors.
According to AMD, which described it as an information disclosure issue, an attacker who has low privileges on the targeted system can “send requests to the driver resulting in a potential data leak from uninitialized physical pages.”
AMD has advised users to update the PSP driver to version 5.17.0.0 through Windows Update or update the Chipset Driver to version 3.08.17.735.
Kyriakos Economou, co-founder of cybersecurity research and development company ZeroPeril, has been credited for discovering the vulnerability. In a technical advisory detailing the findings, the researcher noted that attacks are possible due to information disclosure and memory leakage bugs.
He claims that an attacker could leverage the vulnerability to obtain registry key mappings containing NTLM hashes of authentication credentials, or to obtain data that could be useful for bypassing exploit mitigations such as Kernel Address Space Randomization (KASLR).
“For example, [the NTLM hashes] can be used to steal credentials of a user with administrative privilege and/or be used in pass-the-hash style attacks to gain further access inside a network” the advisory reads.
Economou also noted that AMD’s list of impacted products may be incomplete. The vulnerability has been confirmed to impact Ryzen 2000 and 3000 series CPUs, which are currently not mentioned in AMD’s advisory.
Eduard Kovacs (@EduardKovacs) is a contributing editor at SecurityWeek. He worked as a high school IT teacher for two years before starting a career in journalism as Softpedia’s security news reporter. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
Mirai Botnet Starts Exploiting OMIGOD Flaw as Microsoft Issues More Guidance
Microsoft on Thursday published additional guidance on addressing recently disclosed vulnerabilities in the Open Management Infrastructure (OMI) framework, along with new protections to resolve the bugs within affected Azure Virtual Machine (VM) management extensions.
Microsoft’s guidance was published just as researchers noticed that one of the vulnerabilities is already being exploited in the wild. It appears that the Mirai botnet is attempting to compromise vulnerable systems and that it also closes port 5896 (OMI SSL port) to keep other attackers out.
An open-source Web-Based Enterprise Management (WBEM) implementation, OMI allows for the management of Linux and UNIX systems and is used in various Azure services and Azure Virtual Machine (VM) management extensions.
As part of the September 2021 patches, Microsoft addressed four issues in OMI, one critical bug leading to unauthenticated remote code execution and three high-severity flaws allowing an attacker to elevate privileges. The issues were identified by security researchers with Wiz, which named the RCE defect OMIGOD.
The OMIGOD vulnerability, officially tracked as CVE-2021-38647, is the one reportedly exploited by the Mirai botnet.
According to Microsoft, OMIGOD “only impacts customers using a Linux management solution (on-premises SCOM or Azure Automation State Configuration or Azure Desired State Configuration extension) that enables remote OMI management.”
Microsoft has released additional protections for the affected extensions and encourages customers to update them for both cloud and on-premises deployments. Where automatic updates are enabled, the patches should become globally available by September 18, without a reboot. Otherwise, manually updating the affected components is required.
Affected extensions include System Center Operations Manager (SCOM), Azure Automation State Configuration (DSC Extension), Azure Automation State Configuration (DSC Extension), Log Analytics Agent, Azure Diagnostics (LAD), Azure Automation Update Management, Azure Automation, Azure Security Center, and Container Monitoring Solution.
OMI as a standalone package was patched in August and customers are advised to manually update it to version 1.6.8-1 or above to remain protected.
“New VM’s in these regions will be protected from these vulnerabilities post the availability of updated extensions,” Microsoft says.
The tech giant also notes that VMs deployed within a Network Security Group (NSG) or protected by a perimeter firewall, where access to Linux systems that expose the OMI ports is restricted, should be safe from the RCE flaw.
Azure customers running Linux VMs are advised to apply the available patches as soon as possible, especially since a proof-of-concept (PoC) exploit targeting the flaws is already publicly available.
U.S. Agencies Warn of APTs Exploiting Recent ADSelfService Plus Zero-Day
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Federal Bureau of Investigation (FBI), and the Coast Guard Cyber Command (CGCYBER) have sounded the alarm over in-the-wild attacks targeting a recently disclosed vulnerability in Zoho’s ManageEngine ADSelfService Plus product.
Tracked as CVE-2021-40539 and rated critical severity (CVSS score of 9.8), the vulnerability has been exploited since August 2021 to execute code remotely and take over vulnerable systems.
Affecting the representational state transfer (REST) application programming interface (API) URLs of the self-service password management and single sign-on solution, the issue is an authentication bypass bug that affects all ADSelfService Plus builds up to 6113.
“The FBI, CISA, and CGCYBER assess that advanced persistent threat (APT) cyber actors are likely among those exploiting the vulnerability,” reads a joint advisory issued on Thursday.
Academic institutions, critical infrastructure (communications, finance, IT, logistics, manufacturing, transportation, and others), and defense contractors are at risk of compromise because of their use of ADSelfService Plus.
“Successful exploitation of the vulnerability allows an attacker to place webshells, which enable the adversary to conduct post-exploitation activities, such as compromising administrator credentials, conducting lateral movement, and exfiltrating registry hives and Active Directory files,” the advisory reads.
An attacker able to successfully exploit CVE-2021-40539 can upload a .zip archive containing a JavaServer Pages (JSP) webshell posing as an x509 certificate. The attacker then leverages Windows Management Instrumentation (WMI) for lateral movement. Adversaries also attempt to access domain controllers and expand access.
“Confirming a successful compromise of ManageEngine ADSelfService Plus may be difficult—the attackers run clean-up scripts designed to remove traces of the initial point of compromise and hide any relationship between exploitation of the vulnerability and the webshell,” the joint advisory reads.
The security defect was addressed in ADSelfService Plus build 6114 and customers are advised to update to it as soon as possible. Furthermore, the FBI, CISA, and CGCYBER strongly recommend that organizations keep ADSelfService Plus disconnected from the Internet.
Endpoint Security Platform Kolide Banks $17 Million Investment
Endpoint security platform Kolide on Thursday announced that it has raised $17 million in Series B funding, for a total of $27 million raised to date.
The funding round was led by Boston-based venture capital OpenView Partners. Matrix Partners, who led Kolide’s Series A, also invested in the new round.
Kolide sells a Security-as-a-Service (SaaS) platform that engages with employees to address issues identified on Linux, Mac, and Windows devices, rather than only alerting security teams of the identified gaps.
The security firm uses Slack messages to tell employees when their device no longer meet security standards set by their organization, and also instructs them on how to address the identify the issues and verify whether they did that correctly.
With many organizations migrating to remote-work over the past year, Kolide said it has seen major growth, as it could both help security teams gain visibility into devices, and provide remote employees with transparency into how they were being surveilled.
The company plans to invest the new funds in growth and in expanding its go-to market strategy, as well as into hiring new talent to add more capabilities to its product.
Severe Vulnerabilities Could Expose Thousands of Azure Users to Attacks
Four of the fixes that Microsoft released as part of its September 2021 Patch Tuesday updates deal with vulnerabilities in the Open Management Infrastructure (OMI) software agent embedded in Azure services.
Assessed with severity ratings of critical and high, the vulnerabilities, collectively dubbed OMIGOD, could be exploited to execute code remotely or gain elevated privileges on vulnerable Linux virtual machines running on Azure.
“We conservatively estimate that thousands of Azure customers and millions of endpoints are affected,” said cloud security company Wiz, whose researchers identified the flaws. “In a small sample of Azure tenants we analyzed, over 65% were unknowingly at risk.”
An open source project written in C, OMI helps users manage configurations across environments and is used widely in various Azure services, including Azure Automation, Azure Insights, and more. OMI is similar to Windows Management Instrumentation (WMI) and is deployed automatically when an Azure customer creates a Linux virtual machine.
The most severe of the newly addressed security issues is CVE-2021-38647 (CVSS score of 9.8), which could allow a remote, unauthenticated attacker to execute code on a vulnerable machine. Because of this bug, any request without an authentication header has its privileges automatically set to root.
“With a single packet, an attacker can become root on a remote machine by simply removing the authentication header,” security researchers with Wiz explain.
Considered high severity, all of the three other security holes addressed in OMI could lead to privilege escalation. These are tracked as CVE-2021-38648 (CVSS score of 7.8), CVE-2021-38645 (CVSS score of 7.8), and CVE-2021-38649 (CVSS score of 7.0).
Exploitation of CVE-2021-38648, Wiz researchers explain, involves omitting the authentication part of a previously recorded legitimate command execution request from the omicli and reissuing that request. Regardless of the permissions the user has, the command will be run as root.
These vulnerabilities potentially affect over half of Azure instances, all of which are Linux machines, provided they use Azure services such as Automation, Automatic Update, Operations Management Suite (OMS), Log Analytics, Configuration Management, or Diagnostics, among others.
With OMI available for installation on any Linux machine, others might be affected as well. In fact, Microsoft says that patches for the bugs were made available on GitHub on August 11, to ensure that partners who depend on OMI had enough time to implement the fix before details were made public.
Cisco Patches High-Severity Security Flaws in IOS XR
Cisco this week released patches for multiple high-severity vulnerabilities in the IOS XR software and warned that attackers could exploit these bugs to reboot devices, elevate privileges, or overwrite and read arbitrary files.
The most severe of these issues is CVE-2021-34720 (CVSS score 8.6), a bug that could be exploited remotely without authentication to exhaust device packet memory, leading to a denial of service (DoS) condition.
The issue was identified in the IP Service Level Agreements (IP SLA) responder and Two-Way Active Measurement Protocol (TWAMP) features of IOS XR and exists because socket creation failures are not handled correctly during the IP SLA and TWAMP processes.
By sending specific IP SLA or TWAMP packets, an attacker could trigger the vulnerability to exhaust the packet memory. This could result in the crash of the IP SLA process or could affect other processes, such as routing protocols.
Cisco also patched a separate issue (CVE-2021-34718, CVSS 8.1) in the SSH Server process of IOS XR that could be exploited by a remote attacker to overwrite and read arbitrary files. Exploitation of this bug requires authentication.
The issue exists because arguments that the user supplies for a specific file transfer method aren’t sufficiently validated. Thus, a low-privileged attacker could specify Secure Copy Protocol (SCP) parameters at authentication, which could allow them to elevate privileges and retrieve and upload files on a device.
Two other high severity privilege escalation bugs (CVE-2021-34719 and CVE-2021-34728) were also addressed in IOS XR, along with a denial of service flaw (CVE-2021-34713) affecting ASR 9000 series aggregation services routers that could lead to line card reboots.
Software updates were released to address all of these vulnerabilities and Cisco says it is not aware of any public exploits or malicious attacks targeting them.
Seven other security bugs were addressed in IOS XR software this week, all rated medium severity. Cisco included all of these vulnerabilities in its September 2021 semi-annual bundle of IOS XR Software security advisories.
In a separate advisory on Thursday, the U.S. government’s Cybersecurity and Infrastructure Security Agency (CISA) urged organizations to apply the Cisco patches as soon as possible.
“An attacker could exploit some of these vulnerabilities to take control of an affected system. […]CISA encourages users and administrators to review the […] Cisco advisories and apply the necessary updates,” CISA said.