ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Severe Android and Novi Survey Vulnerabilities Under Active Exploitation

criticalVulnerability exploited in the wildimportance 60CVE-2023-20963CVE-2023-29492

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20963
Local Privilege Escalation in Android Framework (WorkSource Parcel Mismatch)

CVE-2023-20963 is a local privilege escalation vulnerability in the Android Framework's WorkSource component, caused by a parcel mismatch (improperly handled parcel data) on devices running Android 11, 12, 12L, and 13. A malicious or compromised app already on the device can trigger the mismatch with no additional execution privileges and no user interaction, making it a low-friction vector once an attacker has any local foothold. Successful exploitation escalates privileges beyond the normal app sandbox - the CVSS 7.8 vector scores high confidentiality, integrity, and availability impact while requiring only low local privileges, indicating substantial system-level access. Any Android device on versions 11 through 13 that has not received the vendor's security patch is potentially affected, which spans a large share of the global smartphone and tablet fleet. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-13 (EPSS currently estimates a 1.5% probability of exploitation in the next 30 days), and related news coverage - including Google's suspension of the Chinese e-commerce app Pinduoduo over malware - links the exploited bug to a broader malware campaign.

Do: Apply the latest Android security updates from your device vendor or OEM as soon as they are issued, prioritizing all devices on Android 11, 12, 12L, or 13 - this is the required action CISA lists for this KEV entry. Until patched, avoid installing apps from untrusted sources, since exploitation requires the attacker to already run code locally on the device. Administrators should inventory Android 11-13 endpoints via MDM/EMM and track the fix by Android bug ID A-220302519.

7.81% KEV
  • google android Android 11, Android 12, Android 12L, and Android 13 (Android Framework component; Android bug ID A-220302519)
mass~1-3+ billion devices (Android 11-13 cover the majority of Google's 3+ billion active Android installs)
CVE-2023-29492
Unauthenticated Deserialization RCE in 3rd Mill Novi Survey

Novi Survey, a survey platform from 3rd Mill, fails to safely handle untrusted deserialization (CWE-94), letting unauthenticated remote attackers execute arbitrary code on the server. Because the flaw is network-reachable and requires no privileges or user interaction (CVSS 9.8), any exposed Novi Survey instance running a version before 8.9.43676 can be targeted directly over HTTP. A successful attacker gains code execution in the context of the service account running the application, though the flaw does not grant access to stored survey or response data. Organizations hosting Novi Survey themselves are affected; the bug was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-13 following reports of active exploitation, with an EPSS of about 2.7% (85th percentile). Ransomware association is currently unknown, and no public proof-of-concept is available.

Do: Upgrade Novi Survey to version 8.9.43676 or later per vendor instructions, prioritizing instances exposed to the internet. In the meantime, restrict network access to the survey application and review service account activity and process logs for signs of compromise, since successful exploitation runs code under that account. Because the flaw does not expose stored survey data, incident review should focus on service-level code execution rather than data access.

9.83% KEV
  • 3rd Mill Novi Survey all versions prior to 8.9.43676
nichelikely hundreds to low thousands of internet-exposed instances (unknown; no public install counts or scan data)
Full article470 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 14, 2023Mobile Security / Cyber Threat

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The two flaws are listed below -

  • CVE-2023-20963 (CVSS score: 7.8) - Android Framework Privilege Escalation Vulnerability
  • CVE-2023-29492 (CVSS score: TBD) - Novi Survey Insecure Deserialization Vulnerability

"Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed," CISA said in an advisory for CVE-2023-20963.

Google, in its monthly Android Security Bulletin for March 2023, acknowledged "there are indications that CVE-2023-20963 may be under limited, targeted exploitation."

The development comes as tech news site Ars Technica disclosed late last month that Android apps digitally signed by China's e-commerce company Pinduoduo weaponized the flaw as a zero-day to seize control of devices and steal sensitive data, quoting an analysis from mobile security firm Lookout.

Chief among the capabilities of the malware-laced app includes inflating the number of Pinduoduo daily active users and monthly active users, uninstalling rival apps, accessing notifications and location information, and preventing itself from being uninstalled.

CNN, in a follow-up report published at the start of the month, said an analysis of the 6.49.0 version of the app revealed code designed to achieve privilege escalation and even track user activity on other shopping apps.

The exploits allowed the malicious app to access users' contacts, calendars, and photo albums without their consent and requested a "large number of permissions beyond the normal functions of a shopping app," the news channel said.

It's worth pointing out that Google suspended Pinduoduo's official app from the Play Store in March, citing malware identified in "off-Play versions" of the software.

That said, it's still not clear how these APK files were signed with the same key used to sign the legitimate Pinduoduo app. This either points to a key leak, the work of a rogue insider, a compromise of Pinduoduo's build pipeline, or a deliberate attempt by the Chinese company to distribute malware.

The second vulnerability added to the KEV catalog relates to an insecure deserialization vulnerability in Novi Survey software that allows remote attackers to execute code on the server in the context of the service account.

The issue, which impacts Novi Survey versions prior to 8.9.43676, was addressed by the Boston-based provider earlier this week on April 10, 2023. It's currently not known how the flaw is being abused in real-world attacks.

To counter the risks posed by the vulnerabilities, Federal Civilian Executive Branch (FCEB) agencies in the U.S. are advised to apply necessary patches by May 4, 2023.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/04/severe-android-and-novi-survey.html