Microsoft Warns of Unpatched Office Vulnerability Leading to Data Exposure
Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors.
The vulnerability, tracked as CVE-2024-38200 (CVSS score: 7.5), has been described as a spoofing flaw that affects the following versions of Office -
Microsoft Office 2016 for 32-bit edition and 64-bit editions
Microsoft Office LTSC 2021 for 32-bit and 64-bit editions
Microsoft 365 Apps for Enterprise for 32-bit and 64-bit Systems
Microsoft Office 2019 for 32-bit and 64-bit editions
https://thehackernews.com/2024/08/microsoft-warns-of-unpatched-office.html?utm_source=dlvr.it&utm_medium=twitter&m=1
Microsoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors.
The vulnerability, tracked as CVE-2024-38200 (CVSS score: 7.5), has been described as a spoofing flaw that affects the following versions of Office -
Microsoft Office 2016 for 32-bit edition and 64-bit editions
Microsoft Office LTSC 2021 for 32-bit and 64-bit editions
Microsoft 365 Apps for Enterprise for 32-bit and 64-bit Systems
Microsoft Office 2019 for 32-bit and 64-bit editions
https://thehackernews.com/2024/08/microsoft-warns-of-unpatched-office.html?utm_source=dlvr.it&utm_medium=twitter&m=1
Vulnerability: Adobe Products
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.
Vulnerability Details:
• Adobe Premiere Pro:
o CVE-2024-34123:Untrusted Search Path which could allow for arbitrary code execution.
• Adobe InDesign:
o CVE-2024-20781, CVE-2024-20783, CVE-2024-20785:Heap-based Buffer Overflow which could allow for arbitrary code execution.
o CVE-2024-20782:Out-of-bounds Write which could allow for arbitrary code execution.
• Adobe Bridge:
o CVE-2024-34139:Integer Overflow or Wraparound which could allow for arbitrary code execution.
o CVE-2024-34140:Out-of-bounds Read which could allow for a memory leak.
Affected Versions:
• Adobe Premiere Pro 24.4.1 and earlier versions for Windows and macOS.
• Adobe Premiere Pro 23.6.5 and earlier versions for Windows and macOS.
• Adobe InDesign ID19.3 and earlier version for Windows and macOS.
• Adobe InDesign ID18.5.2 and earlier version for Windows and macOS.
• Adobe Bridge 13.0.7 and earlier versions for Windows and macOS.
• Adobe Bridge 14.1 and earlier versions for Windows and macOS.
RECOMMEND ATIONS:
Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing
Reference: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2024-079
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.
Vulnerability Details:
• Adobe Premiere Pro:
o CVE-2024-34123:Untrusted Search Path which could allow for arbitrary code execution.
• Adobe InDesign:
o CVE-2024-20781, CVE-2024-20783, CVE-2024-20785:Heap-based Buffer Overflow which could allow for arbitrary code execution.
o CVE-2024-20782:Out-of-bounds Write which could allow for arbitrary code execution.
• Adobe Bridge:
o CVE-2024-34139:Integer Overflow or Wraparound which could allow for arbitrary code execution.
o CVE-2024-34140:Out-of-bounds Read which could allow for a memory leak.
Affected Versions:
• Adobe Premiere Pro 24.4.1 and earlier versions for Windows and macOS.
• Adobe Premiere Pro 23.6.5 and earlier versions for Windows and macOS.
• Adobe InDesign ID19.3 and earlier version for Windows and macOS.
• Adobe InDesign ID18.5.2 and earlier version for Windows and macOS.
• Adobe Bridge 13.0.7 and earlier versions for Windows and macOS.
• Adobe Bridge 14.1 and earlier versions for Windows and macOS.
RECOMMEND ATIONS:
Apply the stable channel update provided by Adobe to vulnerable systems immediately after appropriate testing
Reference: https://www.cisecurity.org/advisory/multiple-vulnerabilities-in-adobe-products-could-allow-for-arbitrary-code-execution_2024-079
CIS
Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution
<p>Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution.</p>
<ul>
<li>Adobe Premiere Pro is a timeline-based and non-linear video editing software application.</li>
<li>Adobe InDesign…
<ul>
<li>Adobe Premiere Pro is a timeline-based and non-linear video editing software application.</li>
<li>Adobe InDesign…
Vulnerability: Firewall pfsense
A popular open-source firewall software pfSense vulnerability has been identified, allowing for remote code execution (RCE) attacks.
Vulnerability Details:
• CVE-2022-31814- The vulnerability, tracked as CVE-2022-31814, highlights potential risks in pfSense installations, particularly those using the pfBlockerNG package.
The updated exploit, now available on GitHub, employs multiple payloads to account for variations in Python and PHP versions, ensuring a higher success rate across diverse environments. For pfSense users, staying updated on security patches and community advisories is crucial. Regular audits and a thorough understanding of the installed packages can mitigate potential vulnerabilities.
Reference: https://cybersecuritynews.com/open-source-firewall-pfsense-vulnerable/
A popular open-source firewall software pfSense vulnerability has been identified, allowing for remote code execution (RCE) attacks.
Vulnerability Details:
• CVE-2022-31814- The vulnerability, tracked as CVE-2022-31814, highlights potential risks in pfSense installations, particularly those using the pfBlockerNG package.
The updated exploit, now available on GitHub, employs multiple payloads to account for variations in Python and PHP versions, ensuring a higher success rate across diverse environments. For pfSense users, staying updated on security patches and community advisories is crucial. Regular audits and a thorough understanding of the installed packages can mitigate potential vulnerabilities.
Reference: https://cybersecuritynews.com/open-source-firewall-pfsense-vulnerable/
Cyber Security News
Open Source Firewall pfsense Vulnerable to Remote Code Execution Attacks
A vulnerability in the popular open-source firewall software pfSense has been identified, allowing for remote code execution (RCE) attacks.
End of support: Microsoft Exchange 2016
Microsoft reminded today that Exchange 2016 will reach the end of extended support next year on October 14 and shared guidance for admins who need to decommission outdated servers.
Exchange 2016 reached its mainstream end date in October 2020, while Exchange Server 2013 (the previous version) reached its extended end-of-support (EOS) date on April 11, 2023.The company recommends putting Exchange 2016 servers into maintenance mode for one week after migrating to a newer version of Exchange Server to identify any unforeseen issues.In January, Microsoft also announced the end of mainstream support for the Exchange Server 2019 on-premises mail server software, which will also reach its end of extended support on October 14, 2025.
RECOMMEND ATIONS:
Switch to Exchange 2019 to keep receiving security updates—CU15 or Migrate to Microsoft's hosted Exchange Online
Reference: https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-reaches-extended-end-of-support-in-october/
Microsoft reminded today that Exchange 2016 will reach the end of extended support next year on October 14 and shared guidance for admins who need to decommission outdated servers.
Exchange 2016 reached its mainstream end date in October 2020, while Exchange Server 2013 (the previous version) reached its extended end-of-support (EOS) date on April 11, 2023.The company recommends putting Exchange 2016 servers into maintenance mode for one week after migrating to a newer version of Exchange Server to identify any unforeseen issues.In January, Microsoft also announced the end of mainstream support for the Exchange Server 2019 on-premises mail server software, which will also reach its end of extended support on October 14, 2025.
RECOMMEND ATIONS:
Switch to Exchange 2019 to keep receiving security updates—CU15 or Migrate to Microsoft's hosted Exchange Online
Reference: https://www.bleepingcomputer.com/news/microsoft/microsoft-exchange-2016-reaches-extended-end-of-support-in-october/
BleepingComputer
Microsoft: Exchange 2016 reaches extended end of support in October
Microsoft reminded today that Exchange 2016 will reach the end of extended support next year on October 14 and shared guidance for admins who need to decommission outdated servers.
Vulnerability: OpenVPN
Microsoft disclosed four medium-severity security flaws in the open-source OpenVPN software that could be chained to achieve remote code execution (RCE) and local privilege escalation (LPE).
Vulnerability Details:
• CVE-2024-27459 - A stack overflow vulnerability leading to a Denial-of-service (DoS) and LPE in Windows
• CVE-2024-24974 - Unauthorized access to the "\\openvpn\\service" named pipe in Windows, allowing an attacker to remotely interact with it and launch operations on it
• CVE-2024-27903 - A vulnerability in the plugin mechanism leading to RCE in Windows, and LPE and data manipulation in Android, iOS, macOS, and BSD
• CVE-2024-1305 - A memory overflow vulnerability leading to DoS in Windows
The first three of the four flaws are rooted in a component named openvpnserv, while the last one resides in the Windows Terminal Access Point (TAP) driver.
Affected Versions:
• OpenVPN versions < 2.6.10
Reference: https://thehackernews.com/2024/08/microsoft-reveals-four-openvpn-flaws.html?m=1
Microsoft disclosed four medium-severity security flaws in the open-source OpenVPN software that could be chained to achieve remote code execution (RCE) and local privilege escalation (LPE).
Vulnerability Details:
• CVE-2024-27459 - A stack overflow vulnerability leading to a Denial-of-service (DoS) and LPE in Windows
• CVE-2024-24974 - Unauthorized access to the "\\openvpn\\service" named pipe in Windows, allowing an attacker to remotely interact with it and launch operations on it
• CVE-2024-27903 - A vulnerability in the plugin mechanism leading to RCE in Windows, and LPE and data manipulation in Android, iOS, macOS, and BSD
• CVE-2024-1305 - A memory overflow vulnerability leading to DoS in Windows
The first three of the four flaws are rooted in a component named openvpnserv, while the last one resides in the Windows Terminal Access Point (TAP) driver.
Affected Versions:
• OpenVPN versions < 2.6.10
Reference: https://thehackernews.com/2024/08/microsoft-reveals-four-openvpn-flaws.html?m=1
هکرها ۲۰ بانک ایرانی را هک کردند و برای منتشر نکردن اطلاعات مشتریان بانکها، سه میلیون دلار باج گرفتند!
پولتیکو به نقل از منابع مطلع گزارش داده که حمله سایبری ماه گذشته که تهدیدی برای ثبات سیستم بانکداری ایران بود موجب شد که شرکت تامین کننده خدمات الکترونیکی برای بانکهای ایران (شرکت توسن) به هکرها میلیونها دلار باج پرداخت کند.
براساس این گزارش، این شرکت ایرانی تحت فشار دولت دستکم سه میلیون دلار به عنوان باج پرداخت کرد تا از انتشار دادههای ۲۰ بانک ایران و اطلاعات حساب میلیونها ایرانی جلوگیری کند.
به گزارش پولتیکو، این بدترین حمله سایبری به بانکهای ایران بهشمار میرود و گروهی تحت عنوان «آیآرلیکس» (IRLeaks) که سابقه هک بانکهای ایران را دارد، احتمالا پشت این حمله قرار دارد. این گروه هکری در ماه دسامبر نیز اطلاعات بیش از ۲۰ شرکت بیمه و اسنپ فوود را هک کرده بود.
پولتیکو به نقل از منابع مطلع گزارش داده که حمله سایبری ماه گذشته که تهدیدی برای ثبات سیستم بانکداری ایران بود موجب شد که شرکت تامین کننده خدمات الکترونیکی برای بانکهای ایران (شرکت توسن) به هکرها میلیونها دلار باج پرداخت کند.
براساس این گزارش، این شرکت ایرانی تحت فشار دولت دستکم سه میلیون دلار به عنوان باج پرداخت کرد تا از انتشار دادههای ۲۰ بانک ایران و اطلاعات حساب میلیونها ایرانی جلوگیری کند.
به گزارش پولتیکو، این بدترین حمله سایبری به بانکهای ایران بهشمار میرود و گروهی تحت عنوان «آیآرلیکس» (IRLeaks) که سابقه هک بانکهای ایران را دارد، احتمالا پشت این حمله قرار دارد. این گروه هکری در ماه دسامبر نیز اطلاعات بیش از ۲۰ شرکت بیمه و اسنپ فوود را هک کرده بود.
Security Updates
Critical Vulnerabilities in VMware Products
VMware has released a security advisory (VMSA-2024-0019) addressing critical vulnerabilities in VMware vCenter Server and VMware Cloud Foundation, posing significant risks, including potential remote code execution and privilege escalation.
Vulnerability Details:
CVE:
CVE-2024-38812:
A heap-overflow vulnerability in the DCERPC protocol implementation allows remote attackers with network access to execute arbitrary code by sending specially crafted packets.
CVSS Score: 9.8 (Critical)
CVE-2024-38813:
A privilege escalation vulnerability that enables attackers with network access to escalate their privileges to root on the vCenter Server Appliance via crafted packets.
CVSS Score: 7.5 (High)
Affected Versions: • vCenter Server 8: Versions prior to 8.0 U3b are affected by CVE-2024-38812 and CVE-2024-38813.
• vCenter Server 7: Versions prior to 7.0 U3s are affected by CVE-2024-38812 and CVE-2024-38813.
• VMware Cloud Foundation 5.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 8.0 U3b.
• VMware Cloud Foundation 4.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 7.0 U3s.
Fixed Versions: • vCenter Server 8: Update to version 8.0 U3b.
• vCenter Server 7: Update to version 7.0 U3s.
• VMware Cloud Foundation 5.x: Apply the async patch to version 8.0 U3b.
• VMware Cloud Foundation 4.x: Apply the async patch to version 7.0 U3s
References
• https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
Critical Vulnerabilities in VMware Products
VMware has released a security advisory (VMSA-2024-0019) addressing critical vulnerabilities in VMware vCenter Server and VMware Cloud Foundation, posing significant risks, including potential remote code execution and privilege escalation.
Vulnerability Details:
CVE:
CVE-2024-38812:
A heap-overflow vulnerability in the DCERPC protocol implementation allows remote attackers with network access to execute arbitrary code by sending specially crafted packets.
CVSS Score: 9.8 (Critical)
CVE-2024-38813:
A privilege escalation vulnerability that enables attackers with network access to escalate their privileges to root on the vCenter Server Appliance via crafted packets.
CVSS Score: 7.5 (High)
Affected Versions: • vCenter Server 8: Versions prior to 8.0 U3b are affected by CVE-2024-38812 and CVE-2024-38813.
• vCenter Server 7: Versions prior to 7.0 U3s are affected by CVE-2024-38812 and CVE-2024-38813.
• VMware Cloud Foundation 5.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 8.0 U3b.
• VMware Cloud Foundation 4.x: Versions are affected by CVE-2024-38812 and CVE-2024-38813, with fixes available in the async patch for 7.0 U3s.
Fixed Versions: • vCenter Server 8: Update to version 8.0 U3b.
• vCenter Server 7: Update to version 7.0 U3s.
• VMware Cloud Foundation 5.x: Apply the async patch to version 8.0 U3b.
• VMware Cloud Foundation 4.x: Apply the async patch to version 7.0 U3s
References
• https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/24968
Security Updates
Critical Vulnerability in GitLab
GitLab has released a security advisory addressing a critical vulnerability affecting its Community Edition (CE) and Enterprise Edition (EE) products. The vulnerability allows unauthorized attackers to log in as arbitrary users within the vulnerable system, posing a significant security risk.
Vulnerability Details:
CVE: CVE-2024-45409
CVSS Score: 10.0 (Critical)
Impact: An unauthenticated attacker with access to any signed SAML document (by the IdP) can forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as any user within the vulnerable system.
Affected Versions: GitLab Community Edition (CE) and Enterprise Edition (EE) are affected in the following versions:
• Versions prior to 17.3.3
• Versions prior to 17.2.7
• Versions prior to 17.1.8
• Versions prior to 17.0.8
• Versions prior to 16.11.10
Fixed Versions: GitLab CE and EE: Update to versions 17.3.3, 17.2.7, 17.1.8, 17.0.8, or 16.11.10 to mitigate this vulnerability.
References
• https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/
Critical Vulnerability in GitLab
GitLab has released a security advisory addressing a critical vulnerability affecting its Community Edition (CE) and Enterprise Edition (EE) products. The vulnerability allows unauthorized attackers to log in as arbitrary users within the vulnerable system, posing a significant security risk.
Vulnerability Details:
CVE: CVE-2024-45409
CVSS Score: 10.0 (Critical)
Impact: An unauthenticated attacker with access to any signed SAML document (by the IdP) can forge a SAML Response/Assertion with arbitrary contents. This would allow the attacker to log in as any user within the vulnerable system.
Affected Versions: GitLab Community Edition (CE) and Enterprise Edition (EE) are affected in the following versions:
• Versions prior to 17.3.3
• Versions prior to 17.2.7
• Versions prior to 17.1.8
• Versions prior to 17.0.8
• Versions prior to 16.11.10
Fixed Versions: GitLab CE and EE: Update to versions 17.3.3, 17.2.7, 17.1.8, 17.0.8, or 16.11.10 to mitigate this vulnerability.
References
• https://about.gitlab.com/releases/2024/09/17/patch-release-gitlab-17-3-3-released/
GitLab
GitLab Critical Patch Release: 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10
Learn more about GitLab Critical Patch Release: 17.3.3, 17.2.7, 17.1.8, 17.0.8, 16.11.10 for GitLab Community Edition (CE) and Enterprise Edition (EE).
Security Updates
Information Disclosure Vulnerability in Multiple Zoom Products
A medium-severity vulnerability has been identified in the Zoom Workplace Apps, which may allow unauthenticated users to disclose sensitive information through network access. The vulnerability, cataloged as CVE-2024-45424, affects multiple platforms and could potentially expose users to data breaches if not addressed promptly.
Vulnerability Details:
CVE: CVE-2024-45424
CVSS Score: 5.3 (Medium)
Affected Versions: • Zoom Workplace Desktop App for Windows (before version 6.1.0)
• Zoom Workplace Desktop App for macOS (before version 6.1.0)
• Zoom Workplace Desktop App for Linux (before version 6.1.0)
• Zoom Workplace VDI Client for Windows (before version 6.1.0, except versions 5.17.15 and 6.0.12)
• Zoom Workplace App for iOS (before version 6.1.0)
• Zoom Workplace App for Android (before version 6.1.0)
• Zoom Meeting SDK for Windows (before version 6.1.0)
• Zoom Meeting SDK for iOS (before version 6.1.0)
• Zoom Meeting SDK for Android (before version 6.1.0)
• Zoom Meeting SDK for macOS (before version 6.1.0)
• Zoom Meeting SDK for Linux (before version 6.1.0)
• Zoom Rooms App for Windows (before version 6.1.0)
• Zoom Rooms App for macOS (before version 6.1.0)
• Zoom Rooms App for iPad (before version 6.1.0)
• Zoom Rooms Controller for Windows (before version 6.1.0)
• Zoom Rooms Controller for macOS (before version 6.1.0)
• Zoom Rooms Controller for Linux (before version 6.1.0)
• Zoom Rooms Controller for Android (before version 6.1.0)
Fixed Versions: Upgrade to the latest version of the affected Zoom products as soon as possible to mitigate the vulnerability.
References
• https://www.zoom.com/en/trust/security-bulletin/zsb-24036/
Information Disclosure Vulnerability in Multiple Zoom Products
A medium-severity vulnerability has been identified in the Zoom Workplace Apps, which may allow unauthenticated users to disclose sensitive information through network access. The vulnerability, cataloged as CVE-2024-45424, affects multiple platforms and could potentially expose users to data breaches if not addressed promptly.
Vulnerability Details:
CVE: CVE-2024-45424
CVSS Score: 5.3 (Medium)
Affected Versions: • Zoom Workplace Desktop App for Windows (before version 6.1.0)
• Zoom Workplace Desktop App for macOS (before version 6.1.0)
• Zoom Workplace Desktop App for Linux (before version 6.1.0)
• Zoom Workplace VDI Client for Windows (before version 6.1.0, except versions 5.17.15 and 6.0.12)
• Zoom Workplace App for iOS (before version 6.1.0)
• Zoom Workplace App for Android (before version 6.1.0)
• Zoom Meeting SDK for Windows (before version 6.1.0)
• Zoom Meeting SDK for iOS (before version 6.1.0)
• Zoom Meeting SDK for Android (before version 6.1.0)
• Zoom Meeting SDK for macOS (before version 6.1.0)
• Zoom Meeting SDK for Linux (before version 6.1.0)
• Zoom Rooms App for Windows (before version 6.1.0)
• Zoom Rooms App for macOS (before version 6.1.0)
• Zoom Rooms App for iPad (before version 6.1.0)
• Zoom Rooms Controller for Windows (before version 6.1.0)
• Zoom Rooms Controller for macOS (before version 6.1.0)
• Zoom Rooms Controller for Linux (before version 6.1.0)
• Zoom Rooms Controller for Android (before version 6.1.0)
Fixed Versions: Upgrade to the latest version of the affected Zoom products as soon as possible to mitigate the vulnerability.
References
• https://www.zoom.com/en/trust/security-bulletin/zsb-24036/
Zoom
ZSB-24036
Security Updates
RCE Vulnerabilities in Docker Desktop
Docker has released a security update to address multiple remote code execution (RCE) vulnerabilities in its desktop application. These critical vulnerabilities could allow attackers to execute arbitrary code on affected systems, posing serious risks.
Vulnerability Details:
CVE:
CVE-2024-8695
CVSS Base Score: 9.0 (Critical)
A vulnerability in Docker Desktop's handling of extension descriptions and changelogs could allow attackers to execute arbitrary code.
CVE-2024-8696
CVSS Base Score: 8.9 (High)
A vulnerability in Docker Desktop's handling of publisher-url/additional-urls could allow attackers to execute arbitrary code.
Impact: Successful exploitation of these vulnerabilities could lead to unauthorized access, data theft, and other malicious activities.
Affected Versions: Docker Desktop versions prior to 4.34.2.
Fixed Versions: Docker Desktop 4.34.2 or later.
References
• https://docs.docker.com/desktop/release-notes/#4342
RCE Vulnerabilities in Docker Desktop
Docker has released a security update to address multiple remote code execution (RCE) vulnerabilities in its desktop application. These critical vulnerabilities could allow attackers to execute arbitrary code on affected systems, posing serious risks.
Vulnerability Details:
CVE:
CVE-2024-8695
CVSS Base Score: 9.0 (Critical)
A vulnerability in Docker Desktop's handling of extension descriptions and changelogs could allow attackers to execute arbitrary code.
CVE-2024-8696
CVSS Base Score: 8.9 (High)
A vulnerability in Docker Desktop's handling of publisher-url/additional-urls could allow attackers to execute arbitrary code.
Impact: Successful exploitation of these vulnerabilities could lead to unauthorized access, data theft, and other malicious activities.
Affected Versions: Docker Desktop versions prior to 4.34.2.
Fixed Versions: Docker Desktop 4.34.2 or later.
References
• https://docs.docker.com/desktop/release-notes/#4342
Docker Documentation
Docker Desktop release notes
Find the Docker Desktop release notes for Mac, Linux, and Windows.
Security Updates
Tropic Trooper APT Group Targeting Middle East Government Entities
Security researchers have detected a sophisticated cyber espionage campaign targeting a government entity in the Middle East, attributed to the Chinese-speaking APT group known as Tropic Trooper.
Details:
Threat Overview: Tropic Trooper, active since 2011, has typically targeted sectors such as government, healthcare, transportation, and high-tech industries, particularly in regions like Taiwan, the Philippines, and Hong Kong. In 2024, the group shifted its focus toward Middle Eastern government entities involved in human rights studies.
In June 2024, telemetry alerts identified a new variant of the China Chopper web shell on a compromised public server running Umbraco CMS. This web shell was used to execute commands remotely and drop additional malware components.
Malware Clusters Identified: Successful exploitation of these vulnerabilities could lead to unauthorized access, data theft, and other malicious activities.
Attack Vector: The attackers exploited known vulnerabilities in Microsoft Exchange and Adobe ColdFusion to deploy their payloads. Unpatched software greatly increased the risk of successful exploitation.
Indicators of Compromise (IOCs): Umbraco Web Shells (MD5 Hashes):
• 3F15C4431AD4573344AD56E8384EBD62
• 78B47DDA664545542ED3ABE17400C354
• 3B7721715B2842CDFF0AB72BD605A0CE
• 868B8A5012E0EB9A48D2DAF7CB7A5D87
Post-Exploitation Tools (MD5 Hashes):
• 149A9E24DBE347C4AF2DE8D135AA4B76
• 103E4C2E4EE558D130C8B59BFD66B4FB
• E0D9215F64805E0BFF03F4DC796FE52E
• 27C558BD42744CDDC9EDB3FA597D0510
• 4F950683F333F5ED779D70EB38CDADCF
Tropic Trooper Loaders (MD5 Hashes):
• FD8382EFB0A16225896D584DA56C182C
• 1DD03936BAF0FE95B7E5B54A9DD4A577
• 8A900F742D0E3CD3898F37DBC3D6E054
• A213873EB55DC092DDF3ADBEB242BD44
• DD7593E9BA80502505C958B9BBBF2838
• 2C7EBD103514018BAD223F25026D4DB3
• 0B9AE998423A207F021F8E61B93BC849
• E845563BA35E8D227152165B0C3E769F
Domains and IPs:
• 51.195.37[.]155
• 162.19.135[.]182
• techmersion[.]com
SHA256 Hashes:
• 8df9fa495892fc3d183917162746ef8fd9e438ff0d639264236db553b09629dc
• ea2f8884fee1b5a10a0286c5acfb283a60b97b0a3325508b38900b16255e5589
• 3dd2a588b9e269b780bd7648db581d0e64c92a05588fe72a836c4e48641a826f
• 9ba6c63e29b26174e52a519c1afe7a4401e65485fd6ce6a2d574d910dd1d8d22
• efc0d2c1e05e106c5c36160e17619a494676deb136fb877c6d26f3adf75a5777
• 9dff4c8f403338875d009508c64a0e4d4a5eeac191d7654a7793c823fb8e3018
• 98af7888655b8bcac49b76c074fc08877807ac074fb4e81a6cacfd1566d52f12
• https://securelist.com/new-tropic-trooper-web-shell-infection/113737/?reseller=gl_regular-sm_acq_ona_smm__onl_b2b_twi_lnk_sm-team_______f914262e964e2827&utm_source=twitter&utm_medium=social&utm_campaign=g
Tropic Trooper APT Group Targeting Middle East Government Entities
Security researchers have detected a sophisticated cyber espionage campaign targeting a government entity in the Middle East, attributed to the Chinese-speaking APT group known as Tropic Trooper.
Details:
Threat Overview: Tropic Trooper, active since 2011, has typically targeted sectors such as government, healthcare, transportation, and high-tech industries, particularly in regions like Taiwan, the Philippines, and Hong Kong. In 2024, the group shifted its focus toward Middle Eastern government entities involved in human rights studies.
In June 2024, telemetry alerts identified a new variant of the China Chopper web shell on a compromised public server running Umbraco CMS. This web shell was used to execute commands remotely and drop additional malware components.
Malware Clusters Identified: Successful exploitation of these vulnerabilities could lead to unauthorized access, data theft, and other malicious activities.
Attack Vector: The attackers exploited known vulnerabilities in Microsoft Exchange and Adobe ColdFusion to deploy their payloads. Unpatched software greatly increased the risk of successful exploitation.
Indicators of Compromise (IOCs): Umbraco Web Shells (MD5 Hashes):
• 3F15C4431AD4573344AD56E8384EBD62
• 78B47DDA664545542ED3ABE17400C354
• 3B7721715B2842CDFF0AB72BD605A0CE
• 868B8A5012E0EB9A48D2DAF7CB7A5D87
Post-Exploitation Tools (MD5 Hashes):
• 149A9E24DBE347C4AF2DE8D135AA4B76
• 103E4C2E4EE558D130C8B59BFD66B4FB
• E0D9215F64805E0BFF03F4DC796FE52E
• 27C558BD42744CDDC9EDB3FA597D0510
• 4F950683F333F5ED779D70EB38CDADCF
Tropic Trooper Loaders (MD5 Hashes):
• FD8382EFB0A16225896D584DA56C182C
• 1DD03936BAF0FE95B7E5B54A9DD4A577
• 8A900F742D0E3CD3898F37DBC3D6E054
• A213873EB55DC092DDF3ADBEB242BD44
• DD7593E9BA80502505C958B9BBBF2838
• 2C7EBD103514018BAD223F25026D4DB3
• 0B9AE998423A207F021F8E61B93BC849
• E845563BA35E8D227152165B0C3E769F
Domains and IPs:
• 51.195.37[.]155
• 162.19.135[.]182
• techmersion[.]com
SHA256 Hashes:
• 8df9fa495892fc3d183917162746ef8fd9e438ff0d639264236db553b09629dc
• ea2f8884fee1b5a10a0286c5acfb283a60b97b0a3325508b38900b16255e5589
• 3dd2a588b9e269b780bd7648db581d0e64c92a05588fe72a836c4e48641a826f
• 9ba6c63e29b26174e52a519c1afe7a4401e65485fd6ce6a2d574d910dd1d8d22
• efc0d2c1e05e106c5c36160e17619a494676deb136fb877c6d26f3adf75a5777
• 9dff4c8f403338875d009508c64a0e4d4a5eeac191d7654a7793c823fb8e3018
• 98af7888655b8bcac49b76c074fc08877807ac074fb4e81a6cacfd1566d52f12
• https://securelist.com/new-tropic-trooper-web-shell-infection/113737/?reseller=gl_regular-sm_acq_ona_smm__onl_b2b_twi_lnk_sm-team_______f914262e964e2827&utm_source=twitter&utm_medium=social&utm_campaign=g
Securelist
New malicious web shell from the Tropic Trooper group is found in the Middle East
Kaspersky experts found a new variant of the China Chopper web shell from the Tropic Trooper group that imitates an Umbraco CMS module and targets a government entity in the Middle East.
Security Updates
Critical Vulnerabilities in Google Chrome
Google has released security updates to address multiple vulnerabilities in the Chrome browser, which could allow attackers to execute malicious code or compromise user data.
Vulnerability Details:
CVE: • CVE-2024-8904: Type Confusion in V8 (High Severity)
• CVE-2024-8905: Inappropriate implementation in V8 (Medium Severity)
• CVE-2024-8906: Incorrect security UI in Downloads (Medium Severity)
• CVE-2024-8907: Insufficient data validation in Omnibox (Medium Severity)
• CVE-2024-8908: Inappropriate implementation in Autofill (Low Severity)
• CVE-2024-8909: Inappropriate implementation in UI (Low Severity)
Fixed Versions: • Chrome 129.0.6668.58/.59 for Windows, Mac, and Linux
• Chrome 129.0.6668.54 for Android
• Chrome 128.0.6613.162 for Windows and Mac (Extended Stable Channel)
References
• https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html
• https://chromereleases.googleblog.com/
Critical Vulnerabilities in Google Chrome
Google has released security updates to address multiple vulnerabilities in the Chrome browser, which could allow attackers to execute malicious code or compromise user data.
Vulnerability Details:
CVE: • CVE-2024-8904: Type Confusion in V8 (High Severity)
• CVE-2024-8905: Inappropriate implementation in V8 (Medium Severity)
• CVE-2024-8906: Incorrect security UI in Downloads (Medium Severity)
• CVE-2024-8907: Insufficient data validation in Omnibox (Medium Severity)
• CVE-2024-8908: Inappropriate implementation in Autofill (Low Severity)
• CVE-2024-8909: Inappropriate implementation in UI (Low Severity)
Fixed Versions: • Chrome 129.0.6668.58/.59 for Windows, Mac, and Linux
• Chrome 129.0.6668.54 for Android
• Chrome 128.0.6613.162 for Windows and Mac (Extended Stable Channel)
References
• https://chromereleases.googleblog.com/2024/09/stable-channel-update-for-desktop_17.html
• https://chromereleases.googleblog.com/
Chrome Releases
Stable Channel Update for Desktop
The Chrome team is delighted to announce the promotion of Chrome 129 to the stable channel for Windows, Mac and Linux. This will roll out ...
Security Updates
Critical Flaws in Red Hat OpenShift
Red Hat OpenShift, a widely used hybrid cloud platform, has been identified with two severe vulnerabilities that could allow attackers to execute arbitrary commands and escalate privileges on affected nodes.
Vulnerability Details:
CVE: • CVE-2024-45496:
• CVSS Score: 9.9 (Critical)
• Description: This vulnerability arises from the misuse of elevated privileges during the build initialization process. The git-clone container runs with a privileged security context, enabling attackers with developer-level access to inject malicious code via a crafted .gitconfig file, leading to arbitrary command execution on the worker node.
• Impact: Attackers can execute commands with elevated privileges on affected nodes.
• CVE-2024-7387:
• CVSS Score: 9.1 (Critical)
• Description: This flaw allows command injection via path traversal by exploiting the spec.source.secrets.secret.destinationDir attribute in the BuildConfig definition. Malicious users can override executable files within the privileged build container, leading to arbitrary command execution.
• Impact: Command execution on affected nodes.
Affected Products: • Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
• Red Hat OpenShift Container Platform 4.13 for RHEL 8 x86_64
• Red Hat OpenShift Container Platform for Power 4.13 for RHEL 9 ppc64le
• Red Hat OpenShift Container Platform for Power 4.13 for RHEL 8 ppc64le
• Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 9 s390x
• Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 8 s390x
• Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 9 aarch64
• Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 8 aarch64
Fixed Version: Red Hat OpenShift Container Platform 4.13.50
Recommendations: • Upgrade Immediately: Users of OpenShift Container Platform 4.13 should upgrade to version 4.13.50 as soon as it becomes available.
• Restrict Build Strategies: Until patches are applied, administrators should restrict the use of the affected build strategies ("Docker" and "Source") to trusted users to minimize exploitation risks.
References
• https://access.redhat.com/errata/RHSA-2024:6691
Critical Flaws in Red Hat OpenShift
Red Hat OpenShift, a widely used hybrid cloud platform, has been identified with two severe vulnerabilities that could allow attackers to execute arbitrary commands and escalate privileges on affected nodes.
Vulnerability Details:
CVE: • CVE-2024-45496:
• CVSS Score: 9.9 (Critical)
• Description: This vulnerability arises from the misuse of elevated privileges during the build initialization process. The git-clone container runs with a privileged security context, enabling attackers with developer-level access to inject malicious code via a crafted .gitconfig file, leading to arbitrary command execution on the worker node.
• Impact: Attackers can execute commands with elevated privileges on affected nodes.
• CVE-2024-7387:
• CVSS Score: 9.1 (Critical)
• Description: This flaw allows command injection via path traversal by exploiting the spec.source.secrets.secret.destinationDir attribute in the BuildConfig definition. Malicious users can override executable files within the privileged build container, leading to arbitrary command execution.
• Impact: Command execution on affected nodes.
Affected Products: • Red Hat OpenShift Container Platform 4.13 for RHEL 9 x86_64
• Red Hat OpenShift Container Platform 4.13 for RHEL 8 x86_64
• Red Hat OpenShift Container Platform for Power 4.13 for RHEL 9 ppc64le
• Red Hat OpenShift Container Platform for Power 4.13 for RHEL 8 ppc64le
• Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 9 s390x
• Red Hat OpenShift Container Platform for IBM Z and LinuxONE 4.13 for RHEL 8 s390x
• Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 9 aarch64
• Red Hat OpenShift Container Platform for ARM 64 4.13 for RHEL 8 aarch64
Fixed Version: Red Hat OpenShift Container Platform 4.13.50
Recommendations: • Upgrade Immediately: Users of OpenShift Container Platform 4.13 should upgrade to version 4.13.50 as soon as it becomes available.
• Restrict Build Strategies: Until patches are applied, administrators should restrict the use of the affected build strategies ("Docker" and "Source") to trusted users to minimize exploitation risks.
References
• https://access.redhat.com/errata/RHSA-2024:6691
Security Updates
Multiple Vulnerabilities in HPE Aruba Networking Products
Several vulnerabilities in HPE Aruba Mobility Conductors, Controllers, and WLAN/SD-WAN Gateways running AOS could allow authenticated attackers to execute arbitrary code on affected systems.
Vulnerability Details:
CVE: • CVE-2024-42501: Path traversal vulnerability in AOS (CVSS 7.2) allowing code execution.
• CVE-2024-42502: Remote command execution via AOS CLI (CVSS 7.2).
• CVE-2024-42503: Command injection in Lua package of AOS CLI (CVSS 7.2).
Affected Versions: • AOS-10.6.x.x (10.6.0.2 and below)
• AOS-8.12.x.x (8.12.0.1 and below)
• AOS-8.10.x.x (8.10.0.13 and below)
Fixed Versions: Update to AOS-10.7.x.x (10.7.0.0+), AOS-10.6.x.x (10.6.0.3+), AOS-8.12.x.x (8.12.0.2+), or AOS-8.10.x.x (8.10.0.14+).
References
• https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale
Multiple Vulnerabilities in HPE Aruba Networking Products
Several vulnerabilities in HPE Aruba Mobility Conductors, Controllers, and WLAN/SD-WAN Gateways running AOS could allow authenticated attackers to execute arbitrary code on affected systems.
Vulnerability Details:
CVE: • CVE-2024-42501: Path traversal vulnerability in AOS (CVSS 7.2) allowing code execution.
• CVE-2024-42502: Remote command execution via AOS CLI (CVSS 7.2).
• CVE-2024-42503: Command injection in Lua package of AOS CLI (CVSS 7.2).
Affected Versions: • AOS-10.6.x.x (10.6.0.2 and below)
• AOS-8.12.x.x (8.12.0.1 and below)
• AOS-8.10.x.x (8.10.0.13 and below)
Fixed Versions: Update to AOS-10.7.x.x (10.7.0.0+), AOS-10.6.x.x (10.6.0.3+), AOS-8.12.x.x (8.12.0.2+), or AOS-8.10.x.x (8.10.0.14+).
References
• https://support.hpe.com/hpesc/public/docDisplay?docId=hpesbnw04709en_us&docLocale
Security Updates
Critical Vulnerability in Ivanti Cloud Appliance
Ivanti has issued a security advisory for a critical vulnerability (CVE-2024-8963) in its Cloud Services Appliance (CSA), version 4.6, which is being actively exploited. This path traversal vulnerability allows remote unauthenticated attackers to access restricted functionality and potentially execute arbitrary commands when combined with CVE-2024-8190.
Vulnerability Details:
CVE: CVE-2024-8963: Path traversal vulnerability in CSA 4.6 (CVSS 9.4 Critical). Exploitation could bypass admin authentication and lead to command execution.
Affected Products: CSA 4.6 (all versions before Patch 519)
Fixed Version: CSA 4.6 Patch 519 or CSA 5.0 (recommended)
Recommendations: Update to CSA 4.6 Patch 519 or upgrade to CSA 5.0 to mitigate this critical risk.
References
• https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US
Critical Vulnerability in Ivanti Cloud Appliance
Ivanti has issued a security advisory for a critical vulnerability (CVE-2024-8963) in its Cloud Services Appliance (CSA), version 4.6, which is being actively exploited. This path traversal vulnerability allows remote unauthenticated attackers to access restricted functionality and potentially execute arbitrary commands when combined with CVE-2024-8190.
Vulnerability Details:
CVE: CVE-2024-8963: Path traversal vulnerability in CSA 4.6 (CVSS 9.4 Critical). Exploitation could bypass admin authentication and lead to command execution.
Affected Products: CSA 4.6 (all versions before Patch 519)
Fixed Version: CSA 4.6 Patch 519 or CSA 5.0 (recommended)
Recommendations: Update to CSA 4.6 Patch 519 or upgrade to CSA 5.0 to mitigate this critical risk.
References
• https://forums.ivanti.com/s/article/Security-Advisory-Ivanti-CSA-4-6-Cloud-Services-Appliance-CVE-2024-8963?language=en_US
Security Updates
Earth Baxia Threat Campaign
Earth Baxia, a sophisticated threat actor group, has been targeting government organizations and critical sectors in the Asia-Pacific (APAC) region. The group employs spear-phishing and exploits the GeoServer vulnerability (CVE-2024-36401) to deploy customized malware, including a modified version of Cobalt Strike and a new backdoor named EAGLEDOOR.
Details:
Attack Details: • Spear-Phishing: Tailored phishing emails with malicious attachments to gain initial access.
• CVE-2024-36401: Exploits GeoServer to execute arbitrary commands, enabling malicious payload delivery.
Malware: • Cobalt Strike Modifications: Altered to evade detection through internal signature and configuration changes.
• EAGLEDOOR Backdoor: Uses DNS, HTTP, TCP, and Telegram for data exfiltration and command-and-control, with system information gathering and payload delivery capabilities.
Indicators of Compromise (IOCs): Earth Baxia Threat Campaign IOC.csv
Recommendations: • Patch systems, especially GeoServer, to prevent CVE-2024-36401 exploitation.
References
• https://www.trendmicro.com/en_us/research/24/i/earth-baxia-spear-phishing-and-geoserver-exploit.html
Earth Baxia Threat Campaign
Earth Baxia, a sophisticated threat actor group, has been targeting government organizations and critical sectors in the Asia-Pacific (APAC) region. The group employs spear-phishing and exploits the GeoServer vulnerability (CVE-2024-36401) to deploy customized malware, including a modified version of Cobalt Strike and a new backdoor named EAGLEDOOR.
Details:
Attack Details: • Spear-Phishing: Tailored phishing emails with malicious attachments to gain initial access.
• CVE-2024-36401: Exploits GeoServer to execute arbitrary commands, enabling malicious payload delivery.
Malware: • Cobalt Strike Modifications: Altered to evade detection through internal signature and configuration changes.
• EAGLEDOOR Backdoor: Uses DNS, HTTP, TCP, and Telegram for data exfiltration and command-and-control, with system information gathering and payload delivery capabilities.
Indicators of Compromise (IOCs): Earth Baxia Threat Campaign IOC.csv
Recommendations: • Patch systems, especially GeoServer, to prevent CVE-2024-36401 exploitation.
References
• https://www.trendmicro.com/en_us/research/24/i/earth-baxia-spear-phishing-and-geoserver-exploit.html
Trend Micro
Earth Baxia Uses Spear-Phishing and GeoServer Exploit to Target APAC
Security Updates
High Severity Vulnerability in Keycloak
A high-severity vulnerability (CVE-2024-8698) has been identified in Keycloak's SAML signature validation process, allowing attackers to bypass authentication and potentially escalate privileges.
Vulnerability Details:
CVE: CVE-2024-8698
CVSS Score: 7.7 (High)
Affected Version: Keycloak versions up to and including 25.0.5
Fixed Version: Keycloak version 25.0.6
References
• https://nvd.nist.gov/vuln/detail/CVE-2024-8698
High Severity Vulnerability in Keycloak
A high-severity vulnerability (CVE-2024-8698) has been identified in Keycloak's SAML signature validation process, allowing attackers to bypass authentication and potentially escalate privileges.
Vulnerability Details:
CVE: CVE-2024-8698
CVSS Score: 7.7 (High)
Affected Version: Keycloak versions up to and including 25.0.5
Fixed Version: Keycloak version 25.0.6
References
• https://nvd.nist.gov/vuln/detail/CVE-2024-8698