ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Microsoft Updates September 2014

criticalExploit / PoCimportance 60CVE-2013-7331

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2013-7331
Information Disclosure in Microsoft Internet Explorer Lets Pages Detect Anti-Malware

CVE-2013-7331 is an information disclosure flaw (CWE-200) in Microsoft Internet Explorer in which resources loaded into memory can be queried by web content. An attacker triggers it by luring a user to a malicious or compromised webpage whose crafted script probes memory-resident resources, requiring no authentication and no interaction beyond ordinary browsing. What the attacker gains is knowledge of which anti-malware applications are installed on the victim, information commonly used for victim fingerprinting; related coverage of the Nuclear exploit kit reflects how exploit kits leveraged this kind of security-product detection to tailor or withhold follow-on exploits. Any Microsoft Internet Explorer deployment is affected; the provided data does not specify exact version ranges, and the flaw was addressed in Microsoft's significant September 2014 Internet Explorer security bulletin. Exploitation is confirmed in the wild: the flaw was added to the CISA KEV catalog on 2022-05-25 with a high EPSS of 58% (99th percentile), though ransomware association is listed as unknown and no public proof-of-concept is known.

Do: Apply Microsoft's September 2014 Internet Explorer security updates (or any later cumulative IE updates) per vendor instructions, as required by the CISA KEV catalog, and audit for Windows systems still running unpatched IE builds. Prioritize general-purpose browsing and internet-facing endpoints since the flaw is used to fingerprint victims, and migrate any remaining legacy Internet Explorer usage to a supported browser such as Microsoft Edge (with IE mode for legacy dependencies).

58% KEV
  • Microsoft Internet Explorer
masshundreds of millions of Windows devices with Internet Explorer installed
Full article446 words · extracted from securelist.com · click to collapse

Software

Software

11 Sep 2014

minute read

APT Loses a Trick, Reminiscing Stuxnet EoP

Microsoft released four security bulletins this month addressing a total of 42 vulnerabilities in Internet Explorer (MS14-052), .NET (MS14-053), the Windows task scheduler (MS14-054), and several issues in Windows Lync Server (MS14-055). I counted a total of 37 cve set aside for Internet Explorer, with the other five for the three remaining software.

Most interesting is the XMLDOM vulnerability (cve-2013-7331), a vulnerability that has been publicly discussed since at least April 25, 2013. The PoC was re-purposed and abused in the VFW watering hole attack by APT otherwise known as Aurora Panda or “the DeputyDog actor”. The crew is highly advanced and effective in technique and operation, over time deploying multiple 0day to meet their heavy offensive needs. Their xmldom trick likely helped to delay discovery of their IE 0day and presence on the compromised VFW server. “The attacker can easily diagnose whether the machine is running EMET by loading an XML string. If the parsed return code fails, it means EMET is not present and the attacker can proceed with the exploit”. Microsoft rated this vulnerability patch “important” across OS versions, while the other privately disclosed IE vulnerabilities are rated “critical”.

The other 36 Internet Explorer memory corruption vulnerabilities are all over the board as far as exploitability per platform, but they all enable remote code execution. It’s most interesting that the patches for Internet Explorer v10 and v11 on supported Windows 8.1 are rated Critical RCE.

Also this month is a task scheduler escalation of privilege vulnerability reminiscent of one of the Stuxnet 0day that Kaspersky Lab researchers reported back in 2010, and was later deployed by the Tdss gang. And an update to an advisory went out to deal with post-exploitation lateral movement. This time the patched issue is not related to older pass-the-hash issues, but Kerberos ticket grant delay related. The logon credential cleanup package can be downloaded here.

More can be read about September 2014 Microsoft Security Bulletins here.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/microsoft-updates-september-2014-apt-loses-a-trick-reminiscing-stuxnet-eop/66474/