CrowdStrike releases Root Cause Analysis (RCA) report for the bad Falcon update.
https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf
https://www.crowdstrike.com/wp-content/uploads/2024/08/Channel-File-291-Incident-Root-Cause-Analysis-08.06.2024.pdf
Microsoft Warns of Unpatched Office Vulnerability Leading to Data Exposure
Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors.
The vulnerability, tracked as CVE-2024-38200 (CVSS score: 7.5), has been described as a spoofing flaw that affects the following versions of Office -
Microsoft Office 2016 for 32-bit edition and 64-bit editions
Microsoft Office LTSC 2021 for 32-bit and 64-bit editions
Microsoft 365 Apps for Enterprise for 32-bit and 64-bit Systems
Microsoft Office 2019 for 32-bit and 64-bit editions
https://thehackernews.com/2024/08/microsoft-warns-of-unpatched-office.html?utm_source=dlvr.it&utm_medium=twitter&m=1
Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors.
The vulnerability, tracked as CVE-2024-38200 (CVSS score: 7.5), has been described as a spoofing flaw that affects the following versions of Office -
Microsoft Office 2016 for 32-bit edition and 64-bit editions
Microsoft Office LTSC 2021 for 32-bit and 64-bit editions
Microsoft 365 Apps for Enterprise for 32-bit and 64-bit Systems
Microsoft Office 2019 for 32-bit and 64-bit editions
https://thehackernews.com/2024/08/microsoft-warns-of-unpatched-office.html?utm_source=dlvr.it&utm_medium=twitter&m=1
Vulnerability: Adobe Products
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.
Vulnerability Details:
• Adobe Premiere Pro:
o CVE-2024-34123:Untrusted Search Path which could allow for arbitrary code execution.
• Adobe InDesign:
o CVE-2024-20781, CVE-2024-20783, CVE-2024-20785:Heap-based Buffer Overflow which could allow for arbitrary code execution.
o CVE-2024-20782:Out-of-bounds Write which could allow for arbitrary code execution.
• Adobe Bridge:
o CVE-2024-34139:Integer Overflow or Wraparound which could allow for arbitrary code execution.
o CVE-2024-34140:Out-of-bounds Read which could allow for a memory leak.
Affected Versions:
• Adobe Premiere Pro 24.4.1 and earlier versions for Windows and macOS.
• Adobe Premiere Pro 23.6.5 and earlier versions for Windows and macOS.
• Adobe InDesign ID19.3 and earlier version for Windows and macOS.
• Adobe InDesign ID18.5.2 and earlier version for Windows and macOS.
• Adobe Bridge 13.0.7 and earlier versions for Windows and macOS.
• Adobe Bridge 14.1 and earlier versions for Windows and macOS.
RECOMMEND ATIONS:
Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing
Reference: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2024-079
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.
Vulnerability Details:
• Adobe Premiere Pro:
o CVE-2024-34123:Untrusted Search Path which could allow for arbitrary code execution.
• Adobe InDesign:
o CVE-2024-20781, CVE-2024-20783, CVE-2024-20785:Heap-based Buffer Overflow which could allow for arbitrary code execution.
o CVE-2024-20782:Out-of-bounds Write which could allow for arbitrary code execution.
• Adobe Bridge:
o CVE-2024-34139:Integer Overflow or Wraparound which could allow for arbitrary code execution.
o CVE-2024-34140:Out-of-bounds Read which could allow for a memory leak.
Affected Versions:
• Adobe Premiere Pro 24.4.1 and earlier versions for Windows and macOS.
• Adobe Premiere Pro 23.6.5 and earlier versions for Windows and macOS.
• Adobe InDesign ID19.3 and earlier version for Windows and macOS.
• Adobe InDesign ID18.5.2 and earlier version for Windows and macOS.
• Adobe Bridge 13.0.7 and earlier versions for Windows and macOS.
• Adobe Bridge 14.1 and earlier versions for Windows and macOS.
RECOMMEND ATIONS:
Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing
Reference: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2024-079
CIS
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
<p>Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.</p>
<ul>
<li>Adobe Premiere Pro is a timeline-based and non-linear video editing software application.</li>
<li>Adobe InDesign…
<ul>
<li>Adobe Premiere Pro is a timeline-based and non-linear video editing software application.</li>
<li>Adobe InDesign…
Vulnerability: Firewall pfsense
A popular open-source firewall software pfSense vulnerability has been identified, allowing for remote code execution (RCE) attacks.
Vulnerability Details:
• CVE-2022-31814- The vulnerability, tracked as CVE-2022-31814, highlights potential risks in pfSense installations, particularly those using the pfBlockerNG package.
The updated exploit, now available on GitHub, employs multiple payloads to account for variations in Python and PHP versions, ensuring a higher success rate across diverse environments. For pfSense users, staying updated on security patches and community advisories is crucial. Regular audits and a thorough understanding of the installed packages can mitigate potential vulnerabilities.
Reference: https://cybersecuritynews.com/open-source-firewall-pfsense-vulnerable/
A popular open-source firewall software pfSense vulnerability has been identified, allowing for remote code execution (RCE) attacks.
Vulnerability Details:
• CVE-2022-31814- The vulnerability, tracked as CVE-2022-31814, highlights potential risks in pfSense installations, particularly those using the pfBlockerNG package.
The updated exploit, now available on GitHub, employs multiple payloads to account for variations in Python and PHP versions, ensuring a higher success rate across diverse environments. For pfSense users, staying updated on security patches and community advisories is crucial. Regular audits and a thorough understanding of the installed packages can mitigate potential vulnerabilities.
Reference: https://cybersecuritynews.com/open-source-firewall-pfsense-vulnerable/
Cyber Security News
Open Source Firewall pfsense Vulnerable to Remote Code Execution Attacks
A vulnerability in the popular open-source firewall software pfSense has been identified, allowing for remote code execution (RCE) attacks.
End of support: Microsoft Exchange 2016
Microsoft reminded today that Exchange 2016 will reach the end of extended support next year on October 14 and shared guidance for admins who need to decommission outdated servers.
Exchange 2016 reached its mainstream end date in October 2020, while Exchange Server 2013 (the previous version) reached its extended end-of-support (EOS) date on April 11, 2023.The company recommends putting Exchange 2016 servers into maintenance mode for one week after migrating to a newer version of Exchange Server to identify any unforeseen issues.In January, Microsoft also announced the end of mainstream support for the Exchange Server 2019 on-premises mail server software, which will also reach its end of extended support on October 14, 2025.
RECOMMEND ATIONS:
Switch to Exchange 2019 to keep receiving security updates—CU15 or Migrate to Microsoft's hosted Exchange Online
Reference: https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-reaches-extended-end-of-support-in-october/
Microsoft reminded today that Exchange 2016 will reach the end of extended support next year on October 14 and shared guidance for admins who need to decommission outdated servers.
Exchange 2016 reached its mainstream end date in October 2020, while Exchange Server 2013 (the previous version) reached its extended end-of-support (EOS) date on April 11, 2023.The company recommends putting Exchange 2016 servers into maintenance mode for one week after migrating to a newer version of Exchange Server to identify any unforeseen issues.In January, Microsoft also announced the end of mainstream support for the Exchange Server 2019 on-premises mail server software, which will also reach its end of extended support on October 14, 2025.
RECOMMEND ATIONS:
Switch to Exchange 2019 to keep receiving security updates—CU15 or Migrate to Microsoft's hosted Exchange Online
Reference: https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-reaches-extended-end-of-support-in-october/
BleepingComputer
Microsoft: Exchange 2016 reaches extended end of support in October
Microsoft reminded today that Exchange 2016 will reach the end of extended support next year on October 14 and shared guidance for admins who need to decommission outdated servers.
Vulnerability: OpenVPN
Microsoft disclosed four medium-severity security flaws in the open-source OpenVPN software that could be chained to achieve remote code execution (RCE) and local privilege escalation (LPE).
Vulnerability Details:
• CVE-2024-27459 - A stack overflow vulnerability leading to a Denial-of-service (DoS) and LPE in Windows
• CVE-2024-24974 - Unauthorized access to the "\\openvpn\\service" named pipe in Windows, allowing an attacker to remotely interact with it and launch operations on it
• CVE-2024-27903 - A vulnerability in the plugin mechanism leading to RCE in Windows, and LPE and data manipulation in Android, iOS, macOS, and BSD
• CVE-2024-1305 - A memory overflow vulnerability leading to DoS in Windows
The first three of the four flaws are rooted in a component named openvpnserv, while the last one resides in the Windows Terminal Access Point (TAP) driver.
Affected Versions:
• OpenVPN versions < 2.6.10
Reference: https://thehackernews.com/2024/08/microsoft-reveals-four-openvpn-flaws.html?m=1
Microsoft disclosed four medium-severity security flaws in the open-source OpenVPN software that could be chained to achieve remote code execution (RCE) and local privilege escalation (LPE).
Vulnerability Details:
• CVE-2024-27459 - A stack overflow vulnerability leading to a Denial-of-service (DoS) and LPE in Windows
• CVE-2024-24974 - Unauthorized access to the "\\openvpn\\service" named pipe in Windows, allowing an attacker to remotely interact with it and launch operations on it
• CVE-2024-27903 - A vulnerability in the plugin mechanism leading to RCE in Windows, and LPE and data manipulation in Android, iOS, macOS, and BSD
• CVE-2024-1305 - A memory overflow vulnerability leading to DoS in Windows
The first three of the four flaws are rooted in a component named openvpnserv, while the last one resides in the Windows Terminal Access Point (TAP) driver.
Affected Versions:
• OpenVPN versions < 2.6.10
Reference: https://thehackernews.com/2024/08/microsoft-reveals-four-openvpn-flaws.html?m=1
هکرها ۲۰ بانک ایرانی را هک کردند و برای منتشر نکردن اطلاعات مشتریان بانکها، سه میلیون دلار باج گرفتند!
پولتیکو به نقل از منابع مطلع گزارش داده که حمله سایبری ماه گذشته که تهدیدی برای ثبات سیستم بانکداری ایران بود موجب شد که شرکت تامین کننده خدمات الکترونیکی برای بانکهای ایران (شرکت توسن) به هکرها میلیونها دلار باج پرداخت کند.
براساس این گزارش، این شرکت ایرانی تحت فشار دولت دستکم سه میلیون دلار به عنوان باج پرداخت کرد تا از انتشار دادههای ۲۰ بانک ایران و اطلاعات حساب میلیونها ایرانی جلوگیری کند.
به گزارش پولتیکو، این بدترین حمله سایبری به بانکهای ایران بهشمار میرود و گروهی تحت عنوان «آیآرلیکس» (IRLeaks) که سابقه هک بانکهای ایران را دارد، احتمالا پشت این حمله قرار دارد. این گروه هکری در ماه دسامبر نیز اطلاعات بیش از ۲۰ شرکت بیمه و اسنپ فوود را هک کرده بود.
پولتیکو به نقل از منابع مطلع گزارش داده که حمله سایبری ماه گذشته که تهدیدی برای ثبات سیستم بانکداری ایران بود موجب شد که شرکت تامین کننده خدمات الکترونیکی برای بانکهای ایران (شرکت توسن) به هکرها میلیونها دلار باج پرداخت کند.
براساس این گزارش، این شرکت ایرانی تحت فشار دولت دستکم سه میلیون دلار به عنوان باج پرداخت کرد تا از انتشار دادههای ۲۰ بانک ایران و اطلاعات حساب میلیونها ایرانی جلوگیری کند.
به گزارش پولتیکو، این بدترین حمله سایبری به بانکهای ایران بهشمار میرود و گروهی تحت عنوان «آیآرلیکس» (IRLeaks) که سابقه هک بانکهای ایران را دارد، احتمالا پشت این حمله قرار دارد. این گروه هکری در ماه دسامبر نیز اطلاعات بیش از ۲۰ شرکت بیمه و اسنپ فوود را هک کرده بود.
Security Updates
Critical Vulnerabilities in VMware Products
VMware has released a security advisory (VMSA-2024-0019) addressing critical vulnerabilities in VMware vCenter Server and VMware Cloud Foundation, posing significant risks, including potential remote code execution and privilege escalation.
Vulnerability Details:
CVE:
CVE-2024-38812:
A heap-overflow vulnerability in the DCERPC protocol implementation allows remote attackers with network access to execute arbitrary code by sending specially crafted packets.
CVSS Score: 9.8 (Critical)
CVE-2024-38813:
A privilege escalation vulnerability that enables attackers with network access to escalate their privileges to root on the vCenter Server Appliance via crafted packets.
CVSS Score: 7.5 (High)
Affected Versions: • vCenter Server 8: Versions prior to 8.0 U3b are affected by CVE-2024-38812 and CVE-2024-38813.
• vCenter Server 7: Versions prior to 7.0 U3s are affected by CVE-2024-38812 and CVE-2024-38813.
• VMware Cloud Foundation 5.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 8.0 U3b.
• VMware Cloud Foundation 4.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 7.0 U3s.
Fixed Versions: • vCenter Server 8: Update to version 8.0 U3b.
• vCenter Server 7: Update to version 7.0 U3s.
• VMware Cloud Foundation 5.x: Apply the async patch to version 8.0 U3b.
• VMware Cloud Foundation 4.x: Apply the async patch to version 7.0 U3s
References
• https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
Critical Vulnerabilities in VMware Products
VMware has released a security advisory (VMSA-2024-0019) addressing critical vulnerabilities in VMware vCenter Server and VMware Cloud Foundation, posing significant risks, including potential remote code execution and privilege escalation.
Vulnerability Details:
CVE:
CVE-2024-38812:
A heap-overflow vulnerability in the DCERPC protocol implementation allows remote attackers with network access to execute arbitrary code by sending specially crafted packets.
CVSS Score: 9.8 (Critical)
CVE-2024-38813:
A privilege escalation vulnerability that enables attackers with network access to escalate their privileges to root on the vCenter Server Appliance via crafted packets.
CVSS Score: 7.5 (High)
Affected Versions: • vCenter Server 8: Versions prior to 8.0 U3b are affected by CVE-2024-38812 and CVE-2024-38813.
• vCenter Server 7: Versions prior to 7.0 U3s are affected by CVE-2024-38812 and CVE-2024-38813.
• VMware Cloud Foundation 5.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 8.0 U3b.
• VMware Cloud Foundation 4.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 7.0 U3s.
Fixed Versions: • vCenter Server 8: Update to version 8.0 U3b.
• vCenter Server 7: Update to version 7.0 U3s.
• VMware Cloud Foundation 5.x: Apply the async patch to version 8.0 U3b.
• VMware Cloud Foundation 4.x: Apply the async patch to version 7.0 U3s
References
• https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
Security Updates
Critical Vulnerability in GitLab
GitLab has released a security advisory addressing a critical vulnerability affecting its Community Edition (CE) and Enterprise Edition (EE) products. The vulnerability allows unauthorized attackers to log in as arbitrary users within the vulnerable system, posing a significant security risk.
Vulnerability Details:
CVE: CVE-2024-45409
CVSS Score: 10.0 (Critical)
Impact: An unauthenticated attacker with access to any signed SAML document (by the IdP) can forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as any user within the vulnerable system.
Affected Versions: GitLab Community Edition (CE) and Enterprise Edition (EE) are affected in the following versions:
• Versions prior to 17.3.3
• Versions prior to 17.2.7
• Versions prior to 17.1.8
• Versions prior to 17.0.8
• Versions prior to 16.11.10
Fixed Versions: GitLab CE and EE: Update to versions 17.3.3, 17.2.7, 17.1.8, 17.0.8, or 16.11.10 to mitigate this vulnerability.
References
• https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/
Critical Vulnerability in GitLab
GitLab has released a security advisory addressing a critical vulnerability affecting its Community Edition (CE) and Enterprise Edition (EE) products. The vulnerability allows unauthorized attackers to log in as arbitrary users within the vulnerable system, posing a significant security risk.
Vulnerability Details:
CVE: CVE-2024-45409
CVSS Score: 10.0 (Critical)
Impact: An unauthenticated attacker with access to any signed SAML document (by the IdP) can forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as any user within the vulnerable system.
Affected Versions: GitLab Community Edition (CE) and Enterprise Edition (EE) are affected in the following versions:
• Versions prior to 17.3.3
• Versions prior to 17.2.7
• Versions prior to 17.1.8
• Versions prior to 17.0.8
• Versions prior to 16.11.10
Fixed Versions: GitLab CE and EE: Update to versions 17.3.3, 17.2.7, 17.1.8, 17.0.8, or 16.11.10 to mitigate this vulnerability.
References
• https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/
GitLab
GitLab Critical Patch Release: 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10
Learn more about GitLab Critical Patch Release: 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10 for GitLab Community Edition (CE) and Enterprise Edition (EE).
Security Updates
Information Disclosure Vulnerability in Multiple Zoom Products
A medium-severity vulnerability has been identified in the Zoom Workplace Apps, which may allow unauthenticated users to disclose sensitive information through network access. The vulnerability, cataloged as CVE-2024-45424, affects multiple platforms and could potentially expose users to data breaches if not addressed promptly.
Vulnerability Details:
CVE: CVE-2024-45424
CVSS Score: 5.3 (Medium)
Affected Versions: • Zoom Workplace Desktop App for Windows (before version 6.1.0)
• Zoom Workplace Desktop App for macOS (before version 6.1.0)
• Zoom Workplace Desktop App for Linux (before version 6.1.0)
• Zoom Workplace VDI Client for Windows (before version 6.1.0, except versions 5.17.15 and 6.0.12)
• Zoom Workplace App for iOS (before version 6.1.0)
• Zoom Workplace App for Android (before version 6.1.0)
• Zoom Meeting SDK for Windows (before version 6.1.0)
• Zoom Meeting SDK for iOS (before version 6.1.0)
• Zoom Meeting SDK for Android (before version 6.1.0)
• Zoom Meeting SDK for macOS (before version 6.1.0)
• Zoom Meeting SDK for Linux (before version 6.1.0)
• Zoom Rooms App for Windows (before version 6.1.0)
• Zoom Rooms App for macOS (before version 6.1.0)
• Zoom Rooms App for iPad (before version 6.1.0)
• Zoom Rooms Controller for Windows (before version 6.1.0)
• Zoom Rooms Controller for macOS (before version 6.1.0)
• Zoom Rooms Controller for Linux (before version 6.1.0)
• Zoom Rooms Controller for Android (before version 6.1.0)
Fixed Versions: Upgrade to the latest version of the affected Zoom products as soon as possible to mitigate the vulnerability.
References
• https://www.zoom.com/en/trust/security-bulletin/zsb-24036/
Information Disclosure Vulnerability in Multiple Zoom Products
A medium-severity vulnerability has been identified in the Zoom Workplace Apps, which may allow unauthenticated users to disclose sensitive information through network access. The vulnerability, cataloged as CVE-2024-45424, affects multiple platforms and could potentially expose users to data breaches if not addressed promptly.
Vulnerability Details:
CVE: CVE-2024-45424
CVSS Score: 5.3 (Medium)
Affected Versions: • Zoom Workplace Desktop App for Windows (before version 6.1.0)
• Zoom Workplace Desktop App for macOS (before version 6.1.0)
• Zoom Workplace Desktop App for Linux (before version 6.1.0)
• Zoom Workplace VDI Client for Windows (before version 6.1.0, except versions 5.17.15 and 6.0.12)
• Zoom Workplace App for iOS (before version 6.1.0)
• Zoom Workplace App for Android (before version 6.1.0)
• Zoom Meeting SDK for Windows (before version 6.1.0)
• Zoom Meeting SDK for iOS (before version 6.1.0)
• Zoom Meeting SDK for Android (before version 6.1.0)
• Zoom Meeting SDK for macOS (before version 6.1.0)
• Zoom Meeting SDK for Linux (before version 6.1.0)
• Zoom Rooms App for Windows (before version 6.1.0)
• Zoom Rooms App for macOS (before version 6.1.0)
• Zoom Rooms App for iPad (before version 6.1.0)
• Zoom Rooms Controller for Windows (before version 6.1.0)
• Zoom Rooms Controller for macOS (before version 6.1.0)
• Zoom Rooms Controller for Linux (before version 6.1.0)
• Zoom Rooms Controller for Android (before version 6.1.0)
Fixed Versions: Upgrade to the latest version of the affected Zoom products as soon as possible to mitigate the vulnerability.
References
• https://www.zoom.com/en/trust/security-bulletin/zsb-24036/
Zoom
ZSB-24036
Security Updates
RCE Vulnerabilities in Docker Desktop
Docker has released a security update to address multiple remote code execution (RCE) vulnerabilities in its desktop application. These critical vulnerabilities could allow attackers to execute arbitrary code on affected systems, posing serious risks.
Vulnerability Details:
CVE:
CVE-2024-8695
CVSS Base Score: 9.0 (Critical)
A vulnerability in Docker Desktop's handling of extension descriptions and changelogs could allow attackers to execute arbitrary code.
CVE-2024-8696
CVSS Base Score: 8.9 (High)
A vulnerability in Docker Desktop's handling of publisher-url/additional-urls could allow attackers to execute arbitrary code.
Impact: Successful exploitation of these vulnerabilities could lead to unauthorized access, data theft, and other malicious activities.
Affected Versions: Docker Desktop versions prior to 4.34.2.
Fixed Versions: Docker Desktop 4.34.2 or later.
References
• https://docs.docker.com/desktop/release-notes/#4342
RCE Vulnerabilities in Docker Desktop
Docker has released a security update to address multiple remote code execution (RCE) vulnerabilities in its desktop application. These critical vulnerabilities could allow attackers to execute arbitrary code on affected systems, posing serious risks.
Vulnerability Details:
CVE:
CVE-2024-8695
CVSS Base Score: 9.0 (Critical)
A vulnerability in Docker Desktop's handling of extension descriptions and changelogs could allow attackers to execute arbitrary code.
CVE-2024-8696
CVSS Base Score: 8.9 (High)
A vulnerability in Docker Desktop's handling of publisher-url/additional-urls could allow attackers to execute arbitrary code.
Impact: Successful exploitation of these vulnerabilities could lead to unauthorized access, data theft, and other malicious activities.
Affected Versions: Docker Desktop versions prior to 4.34.2.
Fixed Versions: Docker Desktop 4.34.2 or later.
References
• https://docs.docker.com/desktop/release-notes/#4342
Docker Documentation
Docker Desktop release notes
Find the Docker Desktop release notes for Mac, Linux, and Windows.