ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-5128
objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without

objects.cc in Google V8 before 5.2.361.27, as used in Google Chrome before 52.0.2743.82, does not prevent API interceptors from modifying a store target without setting a property, which allows remote attackers to bypass the Same Origin Policy via a crafted web site.

NVD description · AI analysis pending
8.81%
  • google chrome
  • google v8
CVE-2021-1732
Out-of-Bounds Write Local Privilege Escalation in Microsoft Win32k (CVE-2021-1732)

CVE-2021-1732 is a local elevation-of-privilege vulnerability (CWE-787, out-of-bounds write) in Microsoft's Win32k kernel driver, publicly characterized as an "offset confusion" in the Win32k ConsoleControl routine. It is triggered locally: a process with only low privileges can invoke the vulnerable Win32k functionality without any user interaction, causing a user-supplied offset/pointer to be mishandled in kernel mode and memory to be written out of bounds. An attacker who successfully exploits the flaw can execute code in the kernel and elevate to SYSTEM, gaining full control of the host — which makes it a valuable second-stage link in malware and ransomware chains. Any system running the affected Windows 10 releases (1803, 1809, 1909, 2004, 20H2) or Windows Server 2019/1909/2004/20H2 is exposed, though exploitation requires the attacker to already run code locally on the target. The flaw was fixed in Microsoft's February 2021 Patch Tuesday updates, was added to CISA's KEV catalog on 2021-11-03 with known ransomware use, and carries a very high EPSS score (78.4%, 100th percentile), indicating sustained exploitation pressure.

Do: Apply Microsoft's February 2021 (or later) Windows cumulative security updates to all affected Windows 10 and Windows Server systems, per vendor instructions — CISA's KEV listing requires federal agencies to patch. Prioritize hosts exposed to untrusted local users or already compromised by malware (e.g., ransomware or Raspberry Robin activity, which has used chained Windows LPEs), and hunt on unpatched hosts for signs of post-exploitation privilege escalation to SYSTEM.

7.878% KEV ransomware PoC ×2
  • Microsoft Windows 10 1803
  • Microsoft Windows 10 1809
  • Microsoft Windows 10 1909
  • +6 more
mass≈1 billion+ Windows devices (the listed builds spanned the mainstream Windows 10/Server install base)
CVE-2021-21195
Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Use after free in V8 in Google Chrome prior to 89.0.4389.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

NVD description · AI analysis pending
8.81%
  • google chrome
  • google fedora
CVE-2021-26084
Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability

CVE-2021-26084 is an OGNL injection vulnerability (CWE-917) in Atlassian Confluence Server and Data Center that may allow an unauthenticated attacker to execute arbitrary code. Any organization running Confluence Server or Data Center is potentially affected. It is significant because it is listed in CISA's Known Exploited Vulnerabilities catalog with known ransomware use, and EPSS assigns a 100.0% probability of exploitation within 30 days (100th percentile).

Do: Apply updates to Confluence Server and Data Center per Atlassian's instructions, which is the required action in the CISA KEV listing. Prioritize remediation given confirmed in-the-wild exploitation and known ransomware use.

9.8100% KEV ransomware PoC
  • Atlassian Confluence Server and Data Center
CVE-2021-30551
V8 Type Confusion Zero-Day in Google Chrome (CVE-2021-30551), Exploited in the Wild

CVE-2021-30551 is a type confusion flaw (CWE-843) in the V8 JavaScript engine used by Google Chrome and Chromium, which can lead to heap corruption. An attacker triggers it by persuading a user to open a specially crafted HTML page — the browser bug requires user interaction but no privileges or authentication. Successful exploitation could allow a remote attacker to execute code or otherwise corrupt the browser process, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8). Anyone running Google Chrome prior to 91.0.4472.101, including Chromium-based packages such as Fedora's chromium, is affected. The flaw was exploited as a zero-day before the fix was released, with Google attributing recent Chrome zero-day attacks including this issue to campaigns against Armenian targets linked to a commercial spyware vendor, and it is listed in CISA's Known Exploited Vulnerabilities catalog.

Do: Update Google Chrome to 91.0.4472.101 or later (via chrome://settings/help) and update Fedora's chromium package to the patched build, then verify the version in chrome://version. Fedora/Chromium administrators should apply vendor updates per CISA KEV guidance. Until patched, treat web browsing as a risk vector and avoid opening untrusted links, since exploitation requires loading a crafted web page.

8.865% KEV PoC
  • google chrome Google Chrome prior to 91.0.4472.101 (all platforms)
  • google chromium (V8 engine) Chromium builds with the vulnerable V8 engine, prior to the fix shipped in Chrome 91.0.4472.101
  • fedoraproject fedora (chromium package) Fedora chromium builds prior to the 91.0.4472.101-equivalent update
masshundreds of millions to billions of Chrome/Chromium installs worldwide (Chrome is the world's dominant browser)
CVE-2021-30983
Kernel Buffer Overflow in Apple iOS and iPadOS Enables Arbitrary Code Execution

CVE-2021-30983 is a buffer overflow (CWE-120) in Apple iOS and iPadOS, caused by improper memory handling, that was corrected in iOS 15.2 and iPadOS 15.2. It is triggered locally by an application running on the device (CVSS local attack vector with user interaction), so a user must run a malicious or compromised app for the flaw to be reached. Successful exploitation allows that application to execute arbitrary code with kernel privileges, giving the attacker near-complete control of the affected iPhone or iPad. Anyone using an iPhone or iPad running a version earlier than iOS/iPadOS 15.2 is affected. The vulnerability is confirmed exploited in the wild, having been added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-27, with EPSS estimating a 2.9% probability of exploitation within 30 days; no public proof-of-concept is known.

Do: Upgrade all iPhones and iPads to iOS 15.2 or iPadOS 15.2 or later per Apple's instructions, as this is the required action in CISA's KEV catalog. Use MDM or device inventory to identify any devices still below 15.2 and prioritize them for patching; until updated, limit app installation from untrusted sources, since exploitation requires running an application on the device.

7.83% KEV
  • Apple iOS (iPhone OS) All versions prior to iOS 15.2
  • Apple iPadOS All versions prior to iPadOS 15.2
masshundreds of millions of iPhone/iPad devices (Apple's active installed base exceeds 1 billion; every device not yet updated to iOS/iPadOS 15.2 is affected)
CVE-2021-36942
Unauthenticated LSA Spoofing (PetitPotam NTLM Relay) in Microsoft Windows

CVE-2021-36942 is a spoofing flaw in the Windows Local Security Authority (LSA), widely known as "PetitPotam," that lets an unauthenticated network attacker trick a Windows host into authenticating with NTLM to a machine the attacker controls. It is triggered remotely with no privileges and no user interaction (CVSS 3.1 AV:N/AC:L/PR:N/UI:N) by sending crafted requests that coerce the target system to authenticate. By relaying that coerced authentication to other services, an attacker can impersonate the machine — most critically a domain controller — and escalate toward domain-administrator access, producing a high confidentiality impact. All listed Windows Server releases are affected, with domain controllers and certificate-services servers as the highest-value targets. The flaw is actively exploited in the wild: it was added to CISA's KEV on 2021-11-03 with known ransomware use (LockFile and Babuk campaigns chained it with Exchange flaws), and Microsoft has released Windows updates to address it.

Do: Apply Microsoft's Windows updates per vendor instructions, prioritizing domain controllers and servers running Active Directory Certificate Services. As interim hardening, require SMB signing and restrict NTLM authentication per Microsoft guidance, and review authentication logs for unexpected NTLM connections from domain controllers to certificate-services endpoints.

7.566% KEV ransomware PoC
  • Microsoft Windows (per CISA affected listing) as listed by CISA
  • Microsoft Windows Server 2004 as listed in CISA/CPE data
  • Microsoft Windows Server 2008 as listed in CISA/CPE data
  • +4 more
massmillions of Windows Server deployments; hundreds of thousands of SMB-exposed hosts in public internet scans
CVE-2021-39793
Out-of-Bounds Write in Google Pixel Kernel Driver Enables Local Privilege Escalation

CVE-2021-39793 is an out-of-bounds write (CWE-787) in the kbase_jd_user_buf_pin_pages function of mali_kbase_mem.c — the Mali GPU kernel driver used in Google Pixel devices — caused by a logic error in the code. A local application or process can trigger the flaw via the GPU driver's user-buffer pinning routine without needing any additional execution privileges or user interaction. Successful exploitation lets the attacker write out of bounds in kernel memory and achieve local escalation of privilege, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). All Google Pixel devices running affected Android kernel builds are affected; the CISA record lists Google/Android as the vendor/product and designates Google Pixel as the affected product. The bug is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-04-11, no public proof-of-concept is known, and EPSS estimates a 0.7% probability of exploitation within 30 days.

Do: Apply Google's Android security updates on every Pixel device, per CISA's required action to apply updates per vendor instructions; patches were available as of the April 2022 KEV addition, so ensure devices are on an April 2022 or later security patch level (verify in Settings > About phone > Android security update). There is no known workaround, and because exploitation requires local code execution, review apps installed on unpatched devices and prioritize fleet-wide patching for enterprise-managed Pixel fleets.

7.8<1% KEV
  • Google Android (kernel; Mali GPU driver, mali_kbase_mem.c) on Google Pixel devices Android kernel builds on Pixel devices; the source data does not specify affected version ranges — fixed via Google/Android security updates
masson the order of tens of millions of Google Pixel devices (install base; only unpatched units are exploitable, and exploitation requires local code execution)
CVE-2021-40444
Remote Code Execution via MSHTML Rendering Engine in Microsoft Windows/Office (CVE-2021-40444)

CVE-2021-40444 is a remote code execution vulnerability in the Microsoft MSHTML browser rendering engine, which Microsoft Office documents can load on Windows systems. It is triggered when a user is convinced to open a specially crafted Office document containing a malicious ActiveX control hosted by the MSHTML engine (tracked as a path-traversal-class issue, CWE-22). A successful attacker gains the ability to run arbitrary code in the context of the logged-on user, with greater impact when that user has administrative rights. Any Windows system that can open Office documents is exposed, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H1) and Windows Server 2004/2008. Exploitation is confirmed in the wild: Microsoft observed targeted attacks at disclosure, the flaw is in CISA's KEV with known ransomware use, and Microsoft released security updates on September 14, 2021.

Do: Apply Microsoft's security updates released September 14, 2021 for your Windows version immediately; this is a CISA KEV item with known ransomware use, so patching is treated as mandatory. As interim protection, keep Microsoft Defender Antivirus/Defender for Endpoint signatures current (enterprise detection build 1.349.22.0 or newer, with alerts appearing as 'Suspicious Cpl File Execution') and avoid opening untrusted Office documents, since exploitation requires user interaction with a crafted file.

8.897% KEV ransomware PoC ×2
  • microsoft MSHTML as shipped in the affected Windows releases
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all versions covered by Microsoft's September 2021 security updates
  • +4 more
masshundreds of millions of Windows PCs and servers (nearly all Windows desktop/laptop installs on affected versions at disclosure)
CVE-2022-1096
Actively Exploited Type Confusion in Chromium V8 Engine (Chrome, Edge, Opera)

Google Chromium's V8 JavaScript engine contains a type confusion flaw (CWE-843) that a remote attacker can trigger by getting a user to open a crafted HTML page, causing heap corruption and potentially enabling code execution in the browser renderer. Because V8 underpins all Chromium-based browsers, Google Chrome, Microsoft Edge, Opera, and any other Chromium-derived browser built before the late-March 2022 fixes are affected. A successful exploit yields heap corruption in the renderer, which attackers typically use to run code in the browser process and often chain with sandbox escapes for broader system compromise. The vulnerability is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-28 with a required action of applying vendor updates — and EPSS assigns a 24.4% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known. CVSS scoring was not yet available at the time of this data.

Do: Update Chromium-based browsers immediately — Google Chrome to 99.0.4844.84 or later, Microsoft Edge to 99.0.1150.55 or later, and Opera to its equivalent Chromium 99 build — and verify versions via chrome://version or edge://version. There is no server-side mitigation because exploitation occurs when a user loads attacker-crafted HTML, so prioritize endpoint browser patching and rebuild any applications that embed Chromium (e.g., Electron apps) on patched V8.

8.824% KEV
  • Google Chromium V8 JavaScript engine
  • Google Chrome (Chromium-based) desktop stable prior to 99.0.4844.84
  • Microsoft Edge (Chromium-based) Chromium 99-based builds prior to the late-March 2022 update (Edge 99.0.1150.55 equivalent)
  • +1 more
mass≈3+ billion users (effectively all Chromium-based browser installs worldwide)
CVE-2022-1232
Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Type confusion in V8 in Google Chrome prior to 100.0.4896.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

NVD description · AI analysis pending
8.817% PoC
  • google chrome
CVE-2022-1364
Actively Exploited V8 Turbofan Type Confusion in Google Chrome (CVE-2022-1364)

CVE-2022-1364 is a type confusion flaw (CWE-843) in the Turbofan JIT compiler of the V8 JavaScript engine, as shipped in Google Chrome. A remote attacker can trigger it by persuading a user to open a crafted HTML page, and successful exploitation can lead to heap corruption in the browser renderer. Per the CVSS vector, no privileges are required but user interaction is needed, with high potential impact on confidentiality, integrity, and availability. Anyone running Google Chrome prior to 100.0.4896.127 — and, per CISA's designation, the affected Google Chromium V8 component — is exposed until patched. The bug was exploited as a zero-day in the wild (reported as the ninth actively exploited Chrome zero-day of 2022), was added to CISA's KEV catalog on 2022-04-15, and carries a 13.7% probability of exploitation in the next 30 days (96th EPSS percentile).

Do: Update Google Chrome immediately to 100.0.4896.127 or later on all platforms, as required by the vendor and by CISA's KEV required action. Organizations using Chromium-based browsers (Edge, Brave, Opera, Vivaldi, etc.) should verify their vendors have shipped the corresponding V8 fix rather than waiting on version numbers. Given exploitation via crafted web pages, scan endpoint inventories for Chrome versions below 100.0.4896.127 and prioritize user-facing fleets.

8.814% KEV PoC
  • Google Chrome prior to 100.0.4896.127
  • Google Chromium V8 (Turbofan component, per CISA) as bundled in Chrome builds prior to 100.0.4896.127
massbillions of user installations (Chrome held roughly 65% of desktop browser share in 2022)
CVE-2022-21882
Out-of-Bounds Write LPE in Microsoft Win32k on Windows 10/11 and Windows Server

CVE-2022-21882 is a Win32k elevation-of-privilege vulnerability caused by an out-of-bounds write (CWE-787) in the Windows kernel's Win32k component, affecting Windows 10 versions 1809 through 21H2, Windows 11 21H2, and Windows Server 2019, 2022, and version 20H2. A local attacker who can already execute code with a low-privileged account can trigger the flaw via Win32k system calls with no user interaction, corrupting kernel memory and escalating to SYSTEM-level privileges. Successful exploitation gives the attacker full control of the compromised host (high confidentiality, integrity, and availability impact), and it is commonly chained after an initial foothold to deploy ransomware or other payloads. Anyone running the affected Windows 10, Windows 11, or Windows Server builds is exposed, because the vulnerable Win32k code ships by default with those operating systems. The flaw is actively exploited in the wild: it is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-04) with known ransomware use, and public proof-of-concept code was released by researchers after disclosure.

Do: Apply Microsoft's cumulative security updates for Windows 10 (1809–21H2), Windows 11 21H2, and Windows Server 2019/2022/20H2 immediately — the fix shipped in Microsoft's January 2022 Patch Tuesday and is included in all later cumulative updates; per CISA's required action, apply updates per vendor instructions. Prioritize multi-user hosts (RDS/VDI, terminal and jump servers) where local privilege escalation is most damaging, and hunt for post-compromise indicators such as unexpected SYSTEM-level processes, since ransomware operators are known to use this bug after gaining an initial foothold. If patching is delayed, limit local code execution on affected systems and watch EDR telemetry for kernel-level privilege-escalation behavior.

7.859% KEV ransomware
  • Microsoft Windows 10 1809
  • Microsoft Windows 10 1909
  • Microsoft Windows 10 20H2
  • +6 more
mass≈1 billion Windows 10/11 devices plus millions of Windows Server instances (installed-base estimate)
CVE-2022-22587
Memory Corruption in Apple iOS, iPadOS, and macOS Allows Kernel-Privilege Code Execution

CVE-2022-22587 is a memory corruption flaw (CWE-787, out-of-bounds write) in Apple's operating systems that Apple addressed with improved input validation. It is triggered by a malicious application already running on a vulnerable device, which can exploit the corruption to execute arbitrary code with kernel privileges — the highest privilege level of the OS. All iPhones and iPads running iOS/iPadOS versions earlier than 15.3 and Macs running macOS Monterey earlier than 12.2 or Big Sur earlier than 11.6.3 are affected. Apple reported the issue as actively exploited, and CISA added it to the Known Exploited Vulnerabilities catalog on 2022-01-28; EPSS rates it at 11.6% probability of exploitation in the next 30 days (96th percentile). It was one of two actively exploited Apple zero-days patched in Apple's January 2022 emergency updates.

Do: Update iPhones and iPads to iOS/iPadOS 15.3 and Macs to macOS Monterey 12.2 or Big Sur 11.6.3 (or later). Inventory managed fleets for devices below these versions, since the flaw is exploited in the wild and CISA KEV requires applying vendor updates. Until devices are patched, limit exposure by avoiding installation of untrusted applications on vulnerable iPhones, iPads, and Macs.

9.812% KEV
  • Apple iPhone OS (iOS) iOS versions earlier than 15.3 (fixed in iOS 15.3)
  • Apple iPadOS iPadOS versions earlier than 15.3 (fixed in iPadOS 15.3)
  • Apple macOS Monterey macOS Monterey versions earlier than 12.2 (fixed in 12.2)
  • +1 more
mass>1 billion active Apple devices (all iPhones, iPads, and Macs below the fixed versions)
CVE-2022-22620
WebKit Use-After-Free (CVE-2022-22620) Enables RCE on iOS, iPadOS, and macOS

CVE-2022-22620 is a use-after-free (CWE-416) in Apple's WebKit browser engine, the component that renders web content on iPhones, iPads, Macs, and Safari. An attacker triggers it by getting a victim to process maliciously crafted web content, such as visiting an attacker-controlled webpage, requiring no privileges and only user interaction with the content. Successful exploitation may lead to arbitrary code execution in the context of the browser, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 8.8 High). All devices running iOS or iPadOS before 15.3.1, macOS Monterey before 12.2.1, or Safari before 15.3 are affected, which effectively means the broad Apple user base at the time of disclosure. Apple reported the issue may have been actively exploited in the wild; it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-02-11 and carries a 16.2% EPSS probability of exploitation in the next 30 days (97th percentile).

Do: Update iPhones and iPads to iOS/iPadOS 15.3.1, Macs to macOS Monterey 12.2.1, and Safari to version 15.3 (builds 16612.4.9.1.8 or 15612.4.9.1.8), per Apple's vendor instructions. Inventory for devices still on pre-patch versions, prioritizing user workstations and mobile devices that browse web or HTML email content, since WebKit loads content automatically. Note the vulnerability is listed in CISA's KEV catalog with 'apply updates per vendor instructions' as the required action, so patching is the only reliable mitigation.

8.816% KEV
  • Apple iOS (iPhone OS) prior to iOS 15.3.1
  • Apple iPadOS prior to iPadOS 15.3.1
  • Apple macOS (Monterey) prior to macOS Monterey 12.2.1
  • +1 more
mass≈1 billion+ Apple devices (WebKit is the system web engine on every iPhone, iPad, and Mac)
CVE-2022-26134
Unauthenticated OGNL Injection RCE in Atlassian Confluence Server/Data Center

Atlassian Confluence Server and Data Center contain an unauthenticated remote code execution flaw caused by improper neutralization of expression-language (OGNL) input (CWE-917): an attacker with network access to the application can submit a crafted request that is evaluated as an expression and executed by the server. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code with the privileges of the Confluence process, without any credentials. All organizations running self-managed Confluence Server or Data Center are affected, particularly instances exposed to the internet; Confluence Cloud is not listed among the affected products. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-02 with ransomware use marked as known, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile). CVSS has not yet been scored in this data, but the KEV listing and known ransomware use make unpatched, internet-facing instances a top-priority patching target.

Do: Immediately upgrade to the patched Confluence release specified in Atlassian's 2022-06-02 security advisory, and until patched follow the CISA required action to block all internet traffic to and from affected instances. Because in-the-wild exploitation and ransomware use are confirmed, also hunt for compromise indicators on both patched and unpatched hosts, such as webshells, unexpected child processes of the Confluence service, and unusual outbound connections.

9.8100% KEV ransomware PoC ×2
  • Atlassian Confluence Server
  • Atlassian Confluence Data Center
largetens of thousands of internet-exposed instances (public scan counts of roughly 60,000-90,000 Confluence Server/Data Center hosts around the June 2022…
CVE-2022-26925
Spoofing Flaw in Windows LSA (CVE-2022-26925) Exploited Against Domain Controllers

CVE-2022-26925 is a spoofing vulnerability in the Windows Local Security Authority (LSA) that lets an unauthenticated network attacker make a spoofed call to LSA on a remote Windows host. It is triggered over the network with no user interaction, typically by coercing a Windows system—most critically a domain controller—into authenticating via NTLM to an attacker-controlled machine, in the manner of the PetitPotam forced-authentication attacks referenced in CISA's catalog update. By spoofing the client when LSA processes that authentication, the attacker undermines NTLM's authentication guarantees and, when chained with relay techniques, can authenticate to a domain controller with elevated privileges, which is reflected in the CVSS high-integrity impact. Any organization running affected Windows clients or Windows Server versions is exposed, with domain controllers the highest-value targets. The flaw was exploited as a zero-day before Microsoft's June 2022 Patch Tuesday fixes and is now listed in CISA's Known Exploited Vulnerabilities catalog, with CISA ordering federal agencies to patch.

Do: Apply Microsoft's June 2022 Patch Tuesday updates (per CISA's guidance for the June Microsoft patch, https://www.cisa.gov/guidance-applying-june-microsoft-patch) across all affected Windows versions, prioritizing domain controllers; systems that cannot yet patch should be protected with NTLM-related mitigations (e.g., enforced SMB signing, LDAP signing/channel binding, and restricting or auditing NTLM use) per CISA/Microsoft remediation guidance. Check whether domain controllers are internet-exposed or reachable from untrusted networks, and hunt for signs of forced-authentication/relay activity. Note that a related PetitPotam KEV entry was superseded, so ensure this newer LSA fix—not just the older PetitPotam patch—is deployed.

5.911% KEV
  • microsoft windows 10 1507, 1607, 1809, 1909, 20H2, 21H1, 21H2
  • microsoft windows 11 21H2
  • microsoft windows 7
  • +3 more
mass≈1 billion+ Windows installations worldwide (essentially every Windows environment, and domain controllers at virtually every Windows-running organization)
CVE-2022-30190
MSDT URL Protocol Remote Code Execution in Microsoft Windows (Follina)

CVE-2022-30190 (Follina) is a remote code execution flaw in the Microsoft Windows Support Diagnostic Tool (MSDT) when MSDT is invoked through its ms-msdt URL protocol by a calling application such as Microsoft Word. Attackers trigger it by luring a user into opening a malicious document — typically a Word/RTF file whose link or remotely linked template launches the ms-msdt: URI with attacker-supplied commands — and CVSS 3.1 rates it 7.8 with a local attack vector and required user interaction. A successful exploit runs arbitrary code with the privileges of the calling application, allowing the attacker to install programs, view, change or delete data, or create new accounts in the user's context. Per the CISA data, affected platforms are Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 and 2012 — essentially any Windows installation that ships MSDT, with Office/Word as the common delivery vector. Exploitation is confirmed in the wild: Microsoft acknowledged it as an exploited zero-day, CISA added it to the KEV on 2022-06-14 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.2% (99th percentile), and contemporaneous reporting also tied its use to espionage actors including APT28.

Do: Apply Microsoft's security updates per vendor instructions (the fix shipped in the June 2022 Patch Tuesday releases for the affected Windows versions), as required by CISA's KEV. If patching must be delayed, follow Microsoft's documented mitigation to disable the MSDT URL protocol (remove or restrict the HKEY_CLASSES_ROOT\ms-msdt registry key) and enforce Office Protected View / block Word from fetching remote templates over the network. Hunt for exploitation by checking whether Office processes (WINWORD.exe) launch msdt.exe or sdiagnhost.exe, or whether ms-msdt: URIs are invoked unexpectedly.

7.899% KEV ransomware PoC
  • Microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7
  • +4 more
mass≈1 billion+ Windows devices (effectively the entire supported Windows installed base)
Full article548 words · extracted from securityaffairs.com · click to collapse

Google Project Zero states that in H1 2022 at least half of zero-day issues exploited in attacks were related to not properly fixed old flaws.

Google Project Zero researcher Maddie Stone published a blog post that resumes her speech at the FIRST conference in June 2022, the presentation is titled “0-day In-the-Wild Exploitation in 2022…so far“.

Stone revealed that nine out of 18 zero-day flaws detected and disclosed as exploited in-the-wild in 2022 are variants of previously patched vulnerabilities

“As of June 15, 2022, there have been 18 0-days detected and disclosed as exploited in-the-wild in 2022. When we analyzed those 0-days, we found that at least nine of the 0-days are variants of previously patched vulnerabilities. At least half of the 0-days we’ve seen in the first six months of 2022 could have been prevented with more comprehensive patching and regression tests.” wrote Stone. “On top of that, four of the 2022 0-days are variants of 2021 in-the-wild 0-days. Just 12 months from the original in-the-wild 0-day being patched, attackers came back with a variant of the original bug.”

This means that in many cases the attacks were not so sophisticated, instead threat actors that exploited the issue were able to come back and trigger the known vulnerability through a different path.

For example, the recently discovered Follina Windows vulnerability, tracked as CVE-2022-30190, is a variant of the CVE-2021-40444 MSHTML zero-day.

The following table includes the list of the zero-day and the associated variants:

Product2022 ITW 0-dayVariant
Windows win32kCVE-2022-21882CVE-2021-1732 (2021 itw)
iOS IOMobileFrameBufferCVE-2022-22587CVE-2021-30983 (2021 itw)
WindowsCVE-2022-30190 (“Follina”)CVE-2021-40444 (2021 itw)
Chromium property access interceptorsCVE-2022-1096CVE-2016-5128 CVE-2021-30551 (2021 itw) CVE-2022-1232 (Addresses incomplete CVE-2022-1096 fix)
Chromium v8CVE-2022-1364CVE-2021-21195
WebKitCVE-2022-22620 (“Zombie”)Bug was originally fixed in 2013, patch was regressed in 2016
Google PixelCVE-2021-39793** While this CVE says 2021, the bug was patched and disclosed in 2022Linux same bug in a different subsystem
Atlassian ConfluenceCVE-2022-26134CVE-2021-26084
WindowsCVE-2022-26925 (“PetitPotam”)CVE-2021-36942 (Patch regressed)

“When 0-day exploits are detected in-the-wild, it’s the failure case for an attacker. It’s a gift for us security defenders to learn as much as we can and take actions to ensure that that vector can’t be used again. The goal is to force attackers to start from scratch each time we detect one of their exploits: they’re forced to discover a whole new vulnerability, they have to invest the time in learning and analyzing a new attack surface, they must develop a brand new exploitation method.” continues Stone. “To do that effectively, we need correct and comprehensive fixes.”

To properly address zero-day vulnerabilities Google researchers recommend platform security teams and other independent security researchers to invest in root cause analysis, variant analysis, patch analysis, and exploit technique analysis.

“Transparently sharing these analyses helps the industry as a whole as well. We publish our analyses at this repository. We encourage vendors and others to publish theirs as well.” concludes Stone. “This allows developers and security professionals to better understand what the attackers already know about these bugs, which hopefully leads to even better solutions and security overall.”

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, zero-day)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/132813/security/h1-2022-zero-day-variants-previous-flaws.html