ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Microsoft Internet Explorer and Twilio Authy bugs to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2012-4792CVE-2024-39891

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2012-4792
Use-After-Free RCE in Microsoft Internet Explorer (CISA KEV)

Microsoft Internet Explorer contains a use-after-free vulnerability (CWE-416) in which an attacker can trigger access to an object that was either never properly allocated or has already been deleted, demonstrated in the flaw record by a CDwnBindInfo object. A remote attacker exploits it by enticing a user to a crafted web site, and successful exploitation yields arbitrary code execution in the context of the logged-on user. Potentially affected parties are users of Microsoft Internet Explorer, which CISA notes is an end-of-life product. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-23, carries a 78.7% EPSS probability of exploitation within 30 days (top percentile), and related reporting ('Miniduke: Web Based Infection Vector', 'Group 72') underscores web-based infection vectors for this class of IE flaw; no public PoC is known and ransomware use is unknown.

Do: Per CISA's required action, the impacted product is end-of-life: retire or disconnect any systems still relying on Internet Explorer and move users to a supported browser such as Microsoft Edge. Audit legacy Windows hosts, kiosks, and line-of-business web apps that still invoke IE, and where a supported platform allows it apply Microsoft's cumulative Internet Explorer security update addressing this CVE (MS13-002). On any remaining legacy systems, restrict web browsing to trusted sites until the software is retired.

79% KEV
  • Microsoft Internet Explorer
masshundreds of millions of users historically (IE shipped as the default Windows browser); current still-vulnerable install base unknown
CVE-2024-39891
Unauthenticated Phone-Number Enumeration in Twilio Authy API (Android/iOS)

An unauthenticated endpoint in the Twilio Authy API, reachable through Authy for Android before 25.1.0 and Authy for iOS before 26.1.0, disclosed whether arbitrary phone numbers were registered with the Authy service — an information-disclosure flaw tracked as CWE-203. An attacker could send a stream of phone-number queries to the endpoint over the network with no authentication, privileges, or user interaction, and the API responses revealed the registration status of each number. The attacker's gain was bulk enumeration of which phone numbers use Authy, which is valuable for targeting follow-on phishing, social engineering, or SIM-swap attacks; Authy accounts themselves were not compromised and no credentials or authentication data were exposed. Any user of the affected Android or iOS apps whose phone number could be queried was potentially affected, since the flaw lay in the API's access control rather than in the apps' token generation. The flaw was exploited in the wild in June 2024 and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-23 (EPSS currently estimates a 1.7% probability of exploitation in the next 30 days); no public PoC is known.

Do: Update the Authy Android app to version 25.1.0 or later and the Authy iOS app to version 26.1.0 or later per Twilio's guidance, which closes the unauthenticated endpoint's permissive responses. No account compromise was reported, but users and defenders should stay alert to targeted phishing or social engineering that could leverage knowledge of a phone number's Authy registration, and organizations tracking CISA KEV should apply vendor mitigations or discontinue use of the product if mitigations are unavailable.

5.32% KEV
  • twilio Authy for Android before 25.1.0
  • twilio Authy for iOS before 26.1.0
  • twilio Authy / Authy Authenticator (as listed in CPE)
mass≈ tens of millions of Authy app users (large consumer/enterprise 2FA install base)
Full article290 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Internet Explorer and Twilio Authy bugs to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2012-4792 Microsoft Internet Explorer Use-After-Free Vulnerability
  • CVE-2024-39891 Twilio Authy Information Disclosure Vulnerability

Below are the descriptions of the flaws added to the KEV catalog:

CVE-2012-4792 (CVSS score of 9.3) is a use-after-free issue in Microsoft Internet Explorer 6 through 8. Remote attackers can exploit the flaw to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object, and exploited in the wild in December 2012.

CVE-2024-39891 (CVSS score of 5.3) is a Twilio Authy information disclosure vulnerability. In the Twilio Authy API, accessed by Authy Android before 25.1.0 and Authy iOS before 26.1.0, an unauthenticated endpoint provided access to certain phone-number data, as exploited in the wild in June 2024. An endpoint was discovered that could receive phone numbers and return information indicating whether each number was registered with Authy. Importantly, while this endpoint confirmed the registration status, it did not compromise Authy accounts themselves.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by August 13, 2024.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/166126/breaking-news/u-s-cisa-adds-microsoft-internet-explorer-and-twilio-authy-bugs-known-exploited-vulnerabilities-catalog.html