Security Affairs newsletter Round 413 by Pierluigi Paganini
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-22809 | In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and ED In Sudo before 1.9.12p2, the sudoedit (aka -e) feature mishandles extra arguments passed in the user-provided environment variables (SUDO_EDITOR, VISUAL, and EDITOR), allowing a local attacker to append arbitrary entries to the list of files to process. This can lead to privilege escalation. Affected versions are 1.8.0 through 1.9.12.p1. The problem exists because a user-specified editor may contain a "--" argument that defeats a protection mechanism, e.g., an EDITOR='vim -- /path/to/extra/file' value. NVD description · AI analysis pending | 7.8 | 55% | PoC ×3 |
| — | |
| CVE-2023-23383 | Service Fabric Explorer Spoofing Vulnerability Service Fabric Explorer Spoofing Vulnerability NVD description · AI analysis pending | 4.7 | 12% |
| — | ||
| CVE-2023-23397 | Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak) CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates. Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook. | 9.8 | 97% | KEV |
| masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite) | |
| CVE-2023-23529 | WebKit Type Confusion RCE in Apple iOS, iPadOS, macOS, and Safari CVE-2023-23529 is a type confusion flaw (CWE-843) in Apple's WebKit engine, which renders web content in Safari and in the system web components of iOS, iPadOS, and macOS. It is triggered when a device processes maliciously crafted web content, typically when a user is lured into viewing an attacker-controlled web page or other web-rendered content. Successful exploitation can lead to arbitrary code execution with the privileges of the affected application (CVSS 3.1: 8.8, network vector, requiring user interaction). Affected users are those running iOS/iPadOS versions before the February 2023 fixes, macOS Ventura before 13.2.1, or Safari before 16.3. Apple reported the issue may have been actively exploited before patching, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-14; no public proof-of-concept is known. Do: Apply the vendor updates immediately per CISA's KEV required action: iOS/iPadOS 16.3.1 (or 15.7.4 for devices remaining on the iOS 15 branch), macOS Ventura 13.2.1, and Safari 16.3. Inventory managed iPhones, iPads, and Macs to verify updated versions, prioritizing devices used to browse untrusted web content. As an interim mitigation, treat untrusted links and web content with caution until all endpoints are patched. | 8.8 | 10% | KEV |
| massorder of 1 billion+ devices/users (Apple's active installed base of iOS, iPadOS, and macOS devices and Safari's user base exceed a billion; nearly all ran… |
Full article717 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
April 02, 2023

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free for you in your email box.
If you want to also receive for free the newsletter with the international press subscribe here.
International Press
The criminal use of ChatGPT – a cautionary tale about large language models
Casino Giant Crown Resorts Investigating Ransomware Group’s Data Theft Claims
Hacking
Spyware vendors use 0-days and n-days against popular platforms
Sudoedit bypass in Sudo <= 1.9.12p1 CVE-2023-22809
#SmoothOperator | Ongoing Campaign Trojanizes #3CXDesktopApp in Supply Chain Attack
Critical Elementor Pro Vulnerability Exploited
Malicious Actors Use Unicode Support in Python to Evade Detection
Updates from the MaaS: new threats delivered through NullMixer
MacStealer: New macOS-based Stealer Malware Identified
Copy-paste heist or clipboard-injector attacks on cryptousers
Mélofée: a new alien malware in the Panda’s toolset targeting Linux hosts
Ironing out (the macOS details) of a Smooth Operator
Dissecting AlienFox | The Cloud Spammer’s Swiss Army Knife
Intelligence and Information Warfare
Guidance for investigating attacks using CVE-2023-23397
Pack it Secretly: Earth Preta’s Updated Stealthy Strategies
Phishing Campaign Targets Chinese Nuclear Energy Industry
Cybersecurity
Lloyd’s of London says its controversial cyberwar exclusions could hit profits
Wearable Brain Devices Will Challenge Our Mental Privacy
President Biden Signs Executive Order Restricting Use of Commercial Spyware
UK Introduces Mass Surveillance With Online Safety Bill
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections:
- The Teacher – Most Educational Blog
- The Entertainer – Most Entertaining Blog
- The Tech Whizz – Best Technical Blog
- Best Social Media Account to Follow (@securityaffairs)
Please nominate Security Affairs as your favorite blog.
Nominate here: https://docs.google.com/forms/d/e/1FAIpQLSfaFMkrMlrLhOBsRPKdv56Y4HgC88Bcji4V7OCxCm_OmyPoLw/viewform
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, newsletter)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/144366/breaking-news/security-affairs-newsletter-round-413-by-pierluigi-paganini.html