ZeroHour
The Recordpublished ()ingested

If you bought an iPhone after 2017, update it now, CISA says

criticalRansomware exploited in the wildimportance 60CVE-2023-21715CVE-2023-21823CVE-2023-23376

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-21715
Actively Exploited Security Feature Bypass in Microsoft Office Publisher

Microsoft Office Publisher contains a security feature bypass (CWE-863, incorrect authorization) in which a specially crafted Publisher document can circumvent an Office security mechanism, widely reported as a bypass of the Mark-of-the-Web/Protected View protections applied to files from untrusted sources. The flaw is triggered locally when a user opens the malicious document, consistent with the CVSS vector (local attack, low privileges, user interaction required). Successful bypassing yields high impact on the victim system, with high ratings for confidentiality, integrity, and availability. Anyone running Microsoft 365 Apps or Microsoft Office editions that include Publisher is affected, and no specific affected version numbers are published in this data beyond the requirement to apply the February 2023 fixes. The vulnerability is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-02-14 and was patched as one of three exploited zero-days in Microsoft's February 2023 Patch Tuesday.

Do: Apply Microsoft's February 2023 Patch Tuesday security updates to Microsoft 365 Apps and any Office edition that includes Publisher, per vendor instructions as required by the CISA KEV entry; because affected builds differ by update channel, confirm the installed build after updating rather than relying on the date alone. Until patched, exercise caution with Publisher documents from untrusted sources. No public PoC or workaround is documented, so patching is the primary mitigation.

7.312% KEV
  • Microsoft 365 Apps
  • Microsoft Office (Publisher)
mass≈hundreds of millions of Office/365 installations worldwide
CVE-2023-23376
+1 in the same advisory: …21823
Out-of-Bounds Write Privilege Escalation in Microsoft Windows CLFS Driver

CVE-2023-23376 is a heap-based buffer overflow (out-of-bounds write, CWE-122/CWE-787) in the Windows Common Log File System (CLFS) kernel driver. A local attacker with low privileges can trigger the flaw when the driver mishandles CLFS log-file data, with no user interaction required. Successful exploitation elevates the attacker from a low-privileged user to SYSTEM/kernel-level privileges, which is why ransomware operators chain it with other bugs after gaining an initial foothold. All supported Windows 10 (1507, 1607, 1809, 20H2, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2008, 2012, 2016, and 2019 releases as of February 2023 are affected. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on February 14, 2023 with known ransomware use, Microsoft shipped the fix in the February 2023 Patch Tuesday release, and EPSS estimates roughly an 11% probability of exploitation within the next 30 days (96th percentile).

Do: Apply the Microsoft security updates released on February 14, 2023 (February Patch Tuesday) to every Windows 10, Windows 11, and Windows Server system in the affected version list, prioritizing servers and endpoints exposed to ransomware-prone environments. Verify patch status via update history or vulnerability scanning, since exploitation requires only local low-privileged access and there is no substitution for patching. Given confirmed ransomware chaining, also hunt for signs of post-compromise privilege escalation on hosts that were unpatched before mid-February 2023.

7.811% KEV ransomware
  • Microsoft Windows 10 1507 (all builds prior to the February 2023 security updates)
  • Microsoft Windows 10 1607 (all builds prior to the February 2023 security updates)
  • Microsoft Windows 10 1809 (all builds prior to the February 2023 security updates)
  • +9 more
mass~1 billion+ Windows devices (the CLFS driver ships in every listed Windows 10/11 client and Windows Server 2008-2019 release)
Full article652 words · extracted from therecord.media · click to collapse

If the iPhone in your pocket is any newer than an iPhone 8 (circa 2017), or you own an iPad Pro or third generation iPad Air, you need to update the software. The Cybersecurity and Infrastructure Security Agency (CISA) added four new bugs in Apple and Microsoft products to its list of known exploited vulnerabilities this week.

The list is a catalogue of bugs that have become frequent targets of attack for malicious cyber actors. CISA has given nonmilitary federal agencies until March 7 to patch the vulnerabilities — which include zero days for not just for a roster of Apple products but for Microsoft Office software as well.

The Apple zero day – designated CVE 2023-23529 – was patched in the company’s latest operating system update. The company said on Monday that the vulnerability affects all smartphone models after iPhone 8, as well as all iPad Pro models; iPad Air 3rd generation and later; and regular and mini iPads 5th generation and later. Apple said it was aware of reports that the issue “may have been actively exploited.”

A zero day is a previously unknown vulnerability in software. The term “zero-day” refers to the fact that the vendor or developer didn’t know about the flaw before it was exploited – which means they have “zero days” to fix it before a hacker takes advantage.

According to researchers from Nucleus Security, a Florida-based vulnerability management company, an attacker would need to convince a user to load up malware on a vulnerable Apple device, which isn’t as hard as it sounds. The vulnerability “can be easily delivered by mobile phishing attacks via SMS, messenger apps or fake QR codes,” JT Keating, a senior vice president at Zimperium, a mobile device security company, added. He said that after gaining access, an attacker could then take control and execute commands on the infected device.

Microsoft zero days

Microsoft provided patches for the zero-day vulnerabilities as part of its most recent Patch Tuesday, a monthly offering of updates to fix bugs in the company’s software. The most recent release involved the disclosure of 75 fixed bugs. The three cited by CISA are CVE-2023-21715, CVE-2023-21823 and CVE-2023-23376.

The most critical of the bunch, according to Peter Pflaster, a product manager at the IT operations company Automox, is CVE-2023-21715 because hackers have been actively exploiting it to bypass a number of Microsoft Office’s security features. “Attackers could lcoerce an authenticated end user to download and open a specially crafted file that enables a local attack on the device,” he said. 

Mike Walters, vice president of vulnerability and threat research at Action1, said the CVE-2023-23376 zero day is dangerous too. It targets the Windows Common Log File System Driver, which basically logs the activity on a system. The vulnerability could allow a user to escalate their privileges on a network and, Walters said, the vulnerability is relatively simple to exploit and requires low levels of access and no user interaction. 

Windows operating systems from Windows 7 onwards carry a high vulnerability score of 7.8. He added that Microsoft has confirmed that the vulnerability is currently being exploited in the wild.

Researchers at Nucleus Security also warned that the bug could be used alongside another code execution vulnerability in a ransomware campaign. 

The last bug, CVE-2023-21823, affects the Windows Graphics system and according to Walters is also relatively simple to exploit while requiring low levels of access.  

In addition to offerings from Microsoft and Apple, February’s Patch Tuesday included security updates for products from Adobe, SAP, VMWare, Android, and OpenSSL

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/if-you-bought-an-iphone-after-2017-update-it-now-cisa-says