ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Chrome, Redis bugs to Known Exploited Vulnerabilities Catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-0543
Lua Sandbox Escape in Debian-packaged Redis Enables Unauthenticated RCE

CVE-2022-0543 is a Debian-specific Lua sandbox escape in the Redis key-value database, caused by a packaging issue in how the Debian-distributed redis-server build ships its embedded Lua interpreter (tracked as CWE-862). A remote, unauthenticated attacker can send a crafted Lua script through Redis' scripting interface (EVAL) to escape the Lua sandbox that normally limits scripts to safe operations. Successful exploitation yields remote code execution on the server in the context of the Redis process, giving the attacker control over stored data and the ability to run arbitrary system commands. Only Redis servers installed from Debian's (and derivative distributions') packages are affected; upstream Redis builds are not impacted. The flaw is actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-28, EPSS puts the 30-day exploitation probability at 99.4% (100th percentile), and botnet/worm activity against exposed Redis servers has been widely reported.

Do: Apply the updated redis-server packages published through Debian security updates (and equivalent updates in derivative distributions) per vendor instructions, restarting the Redis service after patching. As interim mitigation, restrict Redis exposure by binding to trusted interfaces only, enabling authentication, and firewalling port 6379 from untrusted networks. Check affected hosts for signs of compromise, such as unexpected Lua EVAL activity, unfamiliar child processes, or connections consistent with botnet/worm traffic.

10.099% KEV PoC
  • Debian (redis package; derived distributions affected via packaging) Redis persistent key-value database (Debian-specific builds)
masson the order of 100,000+ internet-exposed Redis servers, with Debian/Ubuntu-packaged installs a significant and plausibly large subset
CVE-2022-1096
Actively Exploited Type Confusion in Chromium V8 Engine (Chrome, Edge, Opera)

Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that a remote attacker can trigger by getting a user to open a crafted HTML page, causing heap corruption and potentially enabling code execution in the browser renderer. Because V8 underpins all Chromium-based browsers, Google Chrome, Microsoft Edge, Opera, and any other Chromium-derived browser built before the late-March 2022 fixes are affected. A successful exploit yields heap corruption in the renderer, which attackers typically use to run code in the browser process and often chain with sandbox escapes for broader system compromise. The vulnerability is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-28 with a required action of applying vendor updates — and EPSS assigns a 24.4% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. CVSS scoring was not yet available at the time of this data.

Do: Update Chromium-based browsers immediately — Google Chrome to 99.0.4844.84 or later, Microsoft Edge to 99.0.1150.55 or later, and Opera to its equivalent Chromium 99 build — and verify versions via chrome://version or edge://version. There is no server-side mitigation because exploitation occurs when a user loads attacker-crafted HTML, so prioritize endpoint browser patching and rebuild any applications that embed Chromium (e.g., Electron apps) on patched V8.

8.824% KEV
  • Google Chromium V8 JavaScript engine
  • Google Chrome (Chromium-based) desktop stable prior to 99.0.4844.84
  • Microsoft Edge (Chromium-based) Chromium 99-based builds prior to the late-March 2022 update (Edge 99.0.1150.55 equivalent)
  • +1 more
mass≈3+ billion users (effectively all Chromium-based browser installs worldwide)
CVE-2022-21999
Local Privilege Escalation in Microsoft Windows Print Spooler (CISA KEV)

CVE-2022-21999 is a privilege elevation vulnerability in the Windows Print Spooler service, caused by improper encapsulation of resources (CWE-40), which lets a local, limited-privilege user manipulate spooler resource handling and execute code with elevated rights. An attacker gains SYSTEM-level privileges on the affected Windows host after already obtaining some foothold locally, making it a common post-compromise escalation step rather than a remote entry point. Any Windows system with the Print Spooler service enabled — the default on most Windows desktop and server installations — is affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-25 with known ransomware use, and EPSS assigns a 41.7% chance of exploitation within 30 days (99th percentile), while the source data records no public proof-of-concept. Required action per CISA is to apply Microsoft updates per vendor instructions.

Do: Apply the vendor security updates per Microsoft's instructions, as required by CISA's KEV listing; since the source data does not specify fixed versions, verify your current Windows build against Microsoft's advisory. As an interim mitigation, disable the Print Spooler service on hosts where local or shared printing is not required. Because the flaw is exploited in the wild and linked to ransomware, check spooler-related privilege escalation activity in logs and prioritize patching servers and workstations accessible to low-privileged users.

7.842% KEV ransomware
  • Microsoft Windows (Print Spooler service)
masshundreds of millions of Windows devices (Print Spooler enabled by default on most desktop/server installs)
CVE-2022-26318
Unauthenticated RCE in WatchGuard Firebox and XTM Fireware OS

CVE-2022-26318 (vendor tracker FBX-22786) is a critical (CVSS 9.8) unauthenticated arbitrary code execution vulnerability in Fireware OS running on WatchGuard Firebox and XTM security appliances. An unauthenticated remote attacker can trigger it by sending crafted requests to network-facing services on an affected appliance, requiring no credentials or user interaction. Successful exploitation allows execution of arbitrary code with high impact on confidentiality, integrity, and availability, typically yielding full control of the perimeter device and a foothold into the internal network behind it. Any organization running Fireware OS in the affected ranges — before 12.7.2_U2, 12.x before 12.1.3_U8, or 12.2.x through 12.5.x before 12.5.9_U2 — is exposed, a population dominated by SMB and mid-market perimeter firewall/VPN deployments. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-03-25, and press reporting of the period links Russian GRU (Sandworm) activity to exploitation of network edge devices of this kind.

Do: Apply the vendor's updates per branch guidance: upgrade Fireware OS to 12.7.2_U2, 12.1.3_U8, or 12.5.9_U2 (or later) as applicable to your release train. Because the flaw is on CISA's KEV list, check whether the appliance's management or other interfaces are internet-exposed, review logs and configuration for signs of compromise, and consider a factory reset or re-image for appliances showing evidence of intrusion, since patching alone may not remove attacker persistence. Organizations in energy and other targeted sectors should prioritize remediation given reported GRU activity against edge devices.

9.878% KEV
  • WatchGuard Fireware OS (Firebox and XTM appliances) All versions before 12.7.2_U2
  • WatchGuard Fireware OS (Firebox and XTM appliances) 12.x before 12.1.3_U8
  • WatchGuard Fireware OS (Firebox and XTM appliances) 12.2.x through 12.5.x before 12.5.9_U2
mass~100,000-300,000 internet-exposed Firebox/XTM appliances per public scan counts; vendor-reported install base of 1M+ appliances
Full article383 words · extracted from securityaffairs.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added Chrome and Redis flaws to its Known Exploited Vulnerabilities Catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added Google Chome zero-day (CVE-2022-1096) and a critical Redis vulnerability (CVE-2022-0543), along with other 30 vulnerabilities, to its Known Exploited Vulnerabilities Catalog.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

The new vulnerabilities added to the catalog have to be addressed by federal agencies by April 18, 2022.

Last week, Google fixed the actively exploited CVE-2022-1096 zero-day vulnerability with the release of Chrome 99.0.4844.84 for Windows, Mac, and Linux.

Google has released Chrome 99.0.4844.84 for Windows, Mac, and Linux users to address it.

The CVE-2022-1096 vulnerability is a Type Confusion in V8 JavaScript engine, the bug was reported by an anonymous on 2022-03-23.

The second issue added to the catalog, tracked as CVE-2022-0543, is a Lua sandbox escape flaw that impacts Debian and Debian-derived Linux distributions.

The vulnerability, which was rated 10 out of 10 for severity, could be exploited by a remote attacker with the ability to execute arbitrary Lua scripts to possibly escape the Lua sandbox and execute arbitrary code on the underlying machine.

Juniper Threat Labs researchers reported that the Muhstik botnet has been observed targeting Redis servers exploiting the CVE-2022-0543 vulnerability.

On March 27, the US Cybersecurity and Infrastructure Security Agency (CISA) added 66 new flaws to its Known Exploited Vulnerabilities Catalog.

One of the 66 flaws added to the catalog is the recently discovered Windows CVE-2022-21999 vulnerability, which is a Windows Print Spooler Elevation of Privilege bug. Microsoft addressed this bug with the release of the February 2022 Patch Tuesday updates.

Another issue added to the catalog, tracked as CVE-2022-26318, is an arbitrary code execution in WatchGuard Firebox and XTM Appliances.

The CISA Catalog has reached a total of 602 entries with the latest added vulnerabilities.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/129593/security/chrome-redis-known-exploited-vulnerabilities-catalog.html