امنیت سایبری SOC
327 subscribers
160 photos
10 videos
169 files
212 links
Information about soc , cyber security defence and cyber security news
Download Telegram
❤1
🔥2👍1
Channel name was changed to «Cyber Security Blue Red»
CrowdStrike releases Root Cause Analysis (RCA) report for the bad Falcon update.
https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf
Microsoft Warns of Unpatched Office Vulnerability Leading to Data Exposure
Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors.

The vulnerability, tracked as CVE-2024-38200 (CVSS score: 7.5), has been described as a spoofing flaw that affects the following versions of Office -

Microsoft Office 2016 for 32-bit edition and 64-bit editions
Microsoft Office LTSC 2021 for 32-bit and 64-bit editions
Microsoft 365 Apps for Enterprise for 32-bit and 64-bit Systems
Microsoft Office 2019 for 32-bit and 64-bit editions

https://thehackernews.com/2024/08/microsoft-warns-of-unpatched-office.html?utm_source=dlvr.it&utm_medium=twitter&m=1
Vulnerability: Adobe Products
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.

Vulnerability Details:
• Adobe Premiere Pro:
o CVE-2024-34123:Untrusted Search Path which could allow for arbitrary code execution.

• Adobe InDesign:
o CVE-2024-20781, CVE-2024-20783, CVE-2024-20785:Heap-based Buffer Overflow which could allow for arbitrary code execution.
o CVE-2024-20782:Out-of-bounds Write which could allow for arbitrary code execution.

• Adobe Bridge:
o CVE-2024-34139:Integer Overflow or Wraparound which could allow for arbitrary code execution.
o CVE-2024-34140:Out-of-bounds Read which could allow for a memory leak.

Affected Versions:
• Adobe Premiere Pro 24.4.1 and earlier versions for Windows and macOS.
• Adobe Premiere Pro 23.6.5 and earlier versions for Windows and macOS.
• Adobe InDesign ID19.3 and earlier version for Windows and macOS.
• Adobe InDesign ID18.5.2 and earlier version for Windows and macOS.
• Adobe Bridge 13.0.7 and earlier versions for Windows and macOS.
• Adobe Bridge 14.1 and earlier versions for Windows and macOS.

RECOMMEND ATIONS:
Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing

Reference: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2024-079
Vulnerability: Firewall pfsense
A popular open-source firewall software pfSense vulnerability has been identified, allowing for remote code execution (RCE) attacks.

Vulnerability Details:
• CVE-2022-31814- The vulnerability, tracked as CVE-2022-31814, highlights potential risks in pfSense installations, particularly those using the pfBlockerNG package.

The updated exploit, now available on GitHub, employs multiple payloads to account for variations in Python and PHP versions, ensuring a higher success rate across diverse environments. For pfSense users, staying updated on security patches and community advisories is crucial. Regular audits and a thorough understanding of the installed packages can mitigate potential vulnerabilities.

Reference: https://cybersecuritynews.com/open-source-firewall-pfsense-vulnerable/
End of support: Microsoft Exchange 2016
Microsoft reminded today that Exchange 2016 will reach the end of extended support next year on October 14 and shared guidance for admins who need to decommission outdated servers.
Exchange 2016 reached its mainstream end date in October 2020, while Exchange Server 2013 (the previous version) reached its extended end-of-support (EOS) date on April 11, 2023.The company recommends putting Exchange 2016 servers into maintenance mode for one week after migrating to a newer version of Exchange Server to identify any unforeseen issues.In January, Microsoft also announced the end of mainstream support for the Exchange Server 2019 on-premises mail server software, which will also reach its end of extended support on October 14, 2025.

RECOMMEND ATIONS:
Switch to Exchange 2019 to keep receiving security updates—CU15 or Migrate to Microsoft's hosted Exchange Online

Reference: https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-reaches-extended-end-of-support-in-october/
Vulnerability: OpenVPN
Microsoft disclosed four medium-severity security flaws in the open-source OpenVPN software that could be chained to achieve remote code execution (RCE) and local privilege escalation (LPE).

Vulnerability Details:
• CVE-2024-27459 - A stack overflow vulnerability leading to a Denial-of-service (DoS) and LPE in Windows
• CVE-2024-24974 - Unauthorized access to the "\\openvpn\\service" named pipe in Windows, allowing an attacker to remotely interact with it and launch operations on it
• CVE-2024-27903 - A vulnerability in the plugin mechanism leading to RCE in Windows, and LPE and data manipulation in Android, iOS, macOS, and BSD
• CVE-2024-1305 - A memory overflow vulnerability leading to DoS in Windows

The first three of the four flaws are rooted in a component named openvpnserv, while the last one resides in the Windows Terminal Access Point (TAP) driver.

Affected Versions:
• OpenVPN versions < 2.6.10
Reference: https://thehackernews.com/2024/08/microsoft-reveals-four-openvpn-flaws.html?m=1
هکرها ۲۰ بانک ایرانی را هک کردند و برای منتشر نکردن اطلاعات مشتریان بانک‌ها، سه میلیون دلار باج گرفتند!

پولتیکو به نقل از منابع مطلع گزارش داده که حمله سایبری ماه گذشته که تهدیدی برای ثبات سیستم بانکداری ایران بود موجب شد که شرکت تامین کننده خدمات الکترونیکی برای بانک‌های ایران (شرکت توسن) به هکرها میلیون‌ها دلار باج پرداخت کند.

براساس این گزارش، این شرکت ایرانی تحت فشار دولت دست‌کم سه میلیون دلار به عنوان باج پرداخت کرد تا از انتشار داده‌های ۲۰ بانک ایران و اطلاعات حساب میلیون‌ها ایرانی جلوگیری کند.
به گزارش پولتیکو، این بدترین حمله سایبری به بانک‌های ایران به‌شمار می‌رود و گروهی تحت عنوان «آی‌آر‌لیکس» (IRLeaks) که سابقه هک بانک‌های ایران را دارد، احتمالا پشت این حمله قرار دارد. این گروه هکری در ماه دسامبر نیز اطلاعات بیش از ۲۰ شرکت بیمه و اسنپ فوود را هک کرده بود.
Security Updates
Critical Vulnerabilities in VMware Products

VMware has released a security advisory (VMSA-2024-0019) addressing critical vulnerabilities in VMware vCenter Server and VMware Cloud Foundation, posing significant risks, including potential remote code execution and privilege escalation.
Vulnerability Details:
CVE:
CVE-2024-38812:
A heap-overflow vulnerability in the DCERPC protocol implementation allows remote attackers with network access to execute arbitrary code by sending specially crafted packets.
CVSS Score: 9.8 (Critical)

CVE-2024-38813:
A privilege escalation vulnerability that enables attackers with network access to escalate their privileges to root on the vCenter Server Appliance via crafted packets.
CVSS Score: 7.5 (High)
Affected Versions: • vCenter Server 8: Versions prior to 8.0 U3b are affected by CVE-2024-38812 and CVE-2024-38813.
• vCenter Server 7: Versions prior to 7.0 U3s are affected by CVE-2024-38812 and CVE-2024-38813.
• VMware Cloud Foundation 5.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 8.0 U3b.
• VMware Cloud Foundation 4.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 7.0 U3s.
Fixed Versions: • vCenter Server 8: Update to version 8.0 U3b.
• vCenter Server 7: Update to version 7.0 U3s.
• VMware Cloud Foundation 5.x: Apply the async patch to version 8.0 U3b.
• VMware Cloud Foundation 4.x: Apply the async patch to version 7.0 U3s
References
• https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
Security Updates
Critical Vulnerability in GitLab

GitLab has released a security advisory addressing a critical vulnerability affecting its Community Edition (CE) and Enterprise Edition (EE) products. The vulnerability allows unauthorized attackers to log in as arbitrary users within the vulnerable system, posing a significant security risk.
Vulnerability Details:
CVE: CVE-2024-45409
CVSS Score: 10.0 (Critical)
Impact: An unauthenticated attacker with access to any signed SAML document (by the IdP) can forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as any user within the vulnerable system.
Affected Versions: GitLab Community Edition (CE) and Enterprise Edition (EE) are affected in the following versions:
• Versions prior to 17.3.3
• Versions prior to 17.2.7
• Versions prior to 17.1.8
• Versions prior to 17.0.8
• Versions prior to 16.11.10
Fixed Versions: GitLab CE and EE: Update to versions 17.3.3, 17.2.7, 17.1.8, 17.0.8, or 16.11.10 to mitigate this vulnerability.
References
• https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/
Security Updates
Information Disclosure Vulnerability in Multiple Zoom Products

A medium-severity vulnerability has been identified in the Zoom Workplace Apps, which may allow unauthenticated users to disclose sensitive information through network access. The vulnerability, cataloged as CVE-2024-45424, affects multiple platforms and could potentially expose users to data breaches if not addressed promptly.
Vulnerability Details:
CVE: CVE-2024-45424
CVSS Score: 5.3 (Medium)
Affected Versions: • Zoom Workplace Desktop App for Windows (before version 6.1.0)
• Zoom Workplace Desktop App for macOS (before version 6.1.0)
• Zoom Workplace Desktop App for Linux (before version 6.1.0)
• Zoom Workplace VDI Client for Windows (before version 6.1.0, except versions 5.17.15 and 6.0.12)
• Zoom Workplace App for iOS (before version 6.1.0)
• Zoom Workplace App for Android (before version 6.1.0)
• Zoom Meeting SDK for Windows (before version 6.1.0)
• Zoom Meeting SDK for iOS (before version 6.1.0)
• Zoom Meeting SDK for Android (before version 6.1.0)
• Zoom Meeting SDK for macOS (before version 6.1.0)
• Zoom Meeting SDK for Linux (before version 6.1.0)
• Zoom Rooms App for Windows (before version 6.1.0)
• Zoom Rooms App for macOS (before version 6.1.0)
• Zoom Rooms App for iPad (before version 6.1.0)
• Zoom Rooms Controller for Windows (before version 6.1.0)
• Zoom Rooms Controller for macOS (before version 6.1.0)
• Zoom Rooms Controller for Linux (before version 6.1.0)
• Zoom Rooms Controller for Android (before version 6.1.0)
Fixed Versions: Upgrade to the latest version of the affected Zoom products as soon as possible to mitigate the vulnerability.
References
• https://www.zoom.com/en/trust/security-bulletin/zsb-24036/
Security Updates
RCE Vulnerabilities in Docker Desktop

Docker has released a security update to address multiple remote code execution (RCE) vulnerabilities in its desktop application. These critical vulnerabilities could allow attackers to execute arbitrary code on affected systems, posing serious risks.
Vulnerability Details:
CVE:
CVE-2024-8695
CVSS Base Score: 9.0 (Critical)
A vulnerability in Docker Desktop's handling of extension descriptions and changelogs could allow attackers to execute arbitrary code.

CVE-2024-8696
CVSS Base Score: 8.9 (High)
A vulnerability in Docker Desktop's handling of publisher-url/additional-urls could allow attackers to execute arbitrary code.
Impact: Successful exploitation of these vulnerabilities could lead to unauthorized access, data theft, and other malicious activities.
Affected Versions: Docker Desktop versions prior to 4.34.2.
Fixed Versions: Docker Desktop 4.34.2 or later.
References
• https://docs.docker.com/desktop/release-notes/#4342