Week in review: PoC for Windows Print Spooler flaw leaked, conquering synthetic identity fraud
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-3580 | Cross-Site Scripting in Cisco ASA and FTD Web Services Interface CVE-2020-3580 is a cross-site scripting (XSS) flaw caused by insufficient validation of user-supplied input in the web services interface of Cisco ASA and Firepower Threat Defense (FTD) software. An unauthenticated, remote attacker can exploit it by persuading a user of the web interface to click a crafted link, which then executes arbitrary script code in the context of the interface or exposes sensitive browser-based information such as session data. Only devices running specific AnyConnect and WebVPN configurations are affected, so not every ASA/FTD deployment is vulnerable. The flaw is under active exploitation: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, a public PoC exploit has driven scanning, and groups such as Akira and LockBit are actively searching for vulnerable Cisco ASA devices. Do: Apply updates per the vendor's instructions (Cisco's advisory lists the fixed ASA/FTD releases), prioritizing internet-facing devices since ransomware operators (Akira, LockBit) are actively scanning. Check whether the web services interface (AnyConnect/WebVPN) is enabled, as only those configurations are vulnerable, and restrict internet access to the device's management/web interface where possible. Treat as urgent given its KEV listing and known ransomware use. | 6.1 | 86% | KEV ransomware |
| mass≈100,000–1,000,000 internet-exposed ASA/FTD appliances (Cisco ASA is among the most commonly exposed edge firewall/VPN platforms in public internet scans) | |
| CVE-2021-1675 | Remote Code Execution in Microsoft Windows Print Spooler (PrintNightmare) CVE-2021-1675 is a code execution flaw in the Windows Print Spooler service affecting the listed Windows 10, 7, 8.1, RT 8.1 and Windows Server editions. It is triggered through print operations processed by the spooler, notably print driver handling; the public PoC demonstrates DLL injection into the spooler, allowing an attacker to run arbitrary code with the privileges of the spooler service, typically SYSTEM. Successful exploitation yields full system compromise: installing programs, viewing or deleting data, creating accounts, and lateral movement into domains, which is why it has been widely used as a ransomware entry vector. Any Windows system with the Print Spooler service enabled is exposed, and the service runs by default on servers, domain controllers, and most workstations. Exploitation is confirmed in the wild: a public PoC is available, the flaw was weaponized by the Magniber and Vice Society ransomware groups, it was added to CISA KEV on 2021-11-03 with known ransomware use, and Microsoft issued out-of-band fixes after it was being exploited in the wild. Do: Apply Microsoft's out-of-band security updates immediately on all affected Windows client and server systems (per CISA KEV required action), prioritizing domain controllers and print/file servers. As an interim mitigation, disable the Print Spooler service on hosts that do not need printing (e.g., domain controllers) and restrict RPC/network access to the spooler on systems that must keep it running. Check for compromise by looking for unexpected DLL or driver files loaded by the spooler, spoolsv.exe spawning unusual child processes, and ransomware indicators given documented Magniber and Vice Society abuse. | 7.8 | 86% | KEV ransomware PoC |
| masshundreds of millions of Windows endpoints and servers (Print Spooler runs by default across the 1B+ device Windows installed base) | |
| CVE-2021-34527 | PrintNightmare: Remote Code Execution in Microsoft Windows Print Spooler CVE-2021-34527, widely known as 'PrintNightmare', is a remote code execution flaw in the Microsoft Windows Print Spooler service, which improperly performs privileged file operations such as loading printer driver DLLs. An attacker with low-level access who can reach a machine's spooler, for example a domain user able to add a printer connection via Point and Print, can induce the SYSTEM-privileged service to load an attacker-controlled DLL with no user interaction required (CVSS:3.1 vector AV:N/AC:L/PR:L/UI:N). Successful exploitation yields arbitrary code execution as SYSTEM, letting the attacker install programs, view, change or delete data, and create new accounts with full user rights, effectively achieving complete host compromise. The flaw affects all supported Windows client and server releases in the CISA data, Windows 10 from 1507 through 22H2, Windows 11, Windows RT 8.1, and Windows Server 2008, 2012 and 2016, wherever the Print Spooler service is running. Exploitation is confirmed in the wild: the bug was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, the FBI and CISA have warned of Russian actors exploiting it, and EPSS places the 30-day exploitation probability at 99.8%. Do: Install the July 2021 security updates immediately, released July 6, 2021 with additional updates on July 7 for Windows Server 2012, Windows Server 2016 and Windows 10 version 1607, and review KB5005010 for restricting installation of new printer drivers after applying the July 6 updates. Where patching is delayed, disable the Print Spooler service on hosts that do not need printing or restrict Point and Print, and verify that NoWarningNoElevationOnInstall and UpdatePromptSettings under HKLM\SOFTWARE\Policies\Microsoft\Windows NT\Printers\PointAndPrint are set to 0 or not defined (these keys do not exist by default, which is the secure state; NoWarningNoElevationOnInstall = 1 makes the system vulnerable by design). Prioritize domain controllers and servers with exposed spoolers, and hunt… | 8.8 | 100% | KEV ransomware PoC ×3 |
| masshundreds of millions of Windows systems (order of magnitude 10^8) |
Full article878 words · extracted from helpnetsecurity.com · click to collapse
Here’s an overview of some of last week’s most interesting news and articles:
PoC for critical Windows Print Spooler flaw leaked
Microsoft has confirmed that the so-called PrintNightmare vulnerability (CVE-2021-34527) is not the same flaw as the previously patched CVE-2021-1675, and that the leaked PoC exploits can be used to exploit this RCE zero-day.
Cisco security devices targeted with CVE-2020-3580 PoC exploit
Attackers and bug hunters are leveraging an exploit for CVE-2020-3580 to compromise vulnerable security devices running Cisco ASA or FTD software.
Navigating the complexity of ransomware negotiations
Most ransomware attacks are opportunistic, and at the end of the day, cybercriminals do not discriminate. Nobody plans to fall victim, but the fact is any company with an internet presence, regardless of size, is at risk.
XDR: Security’s new frontier
Enabling enterprises to go above and beyond typical security functionality, extended detection and response (XDR) provides a much simpler, single pane of glass view that seamlessly integrates multiple security products into one system.
Unstructured data still overshared inside and outside organizations
The number of overshared files rose 450 percent compared to the same quarter in 2020, highlighting the significant impact of the pandemic and remote work on data security.
How IoT is keeping businesses connected in an expanding network
IoT is advancing the technical lives of millions, with the network of connected devices becoming more populated with each passing year. From toothbrushes to toasters, IoT has reached new heights in terms of consumer devices. Look past these however, and it is clear that IoT is indeed a serious proposition for enterprises and an essential ingredient for successful business transformation.
New security measures to keep Google Play safe
Google is announcing two new security measures aimed at minimizing the number of malicious / potentially unwanted apps available for download from the Google Play Store: additional Android developer identification requirements and 2-step verification.
USB threats could critically impact business operations
According to a report released by Honeywell, USB threats that can severely impact business operations increased significantly during a disruptive year when the usage of removable media and network connectivity also grew.
A closer look at Google Workspace privacy and data security
Google recently unveiled the next evolution of Google Workspace, including new security and privacy capabilities to help users take advantage of trusted, cloud-native collaboration.
Consumers neglecting mobile security despite growing number of threats
A new McAfee report reveals that 49% of U.S. consumers do not use mobile security software to protect their sensitive data, thus leaving them vulnerable to these increasingly advanced cyberattacks.
Zero day malware reached an all-time high of 74% in Q1 2021
74% of threats detected in Q1 2021 were zero day malware – or those for which a signature-based antivirus solution did not detect at the time of the malware release – capable of circumventing conventional antivirus solutions, according to WatchGuard.
Regula: Open source policy engine for IaC security
Fugue announced Regula 1.0, an open source policy engine for infrastructure as code (IaC) security. Available at GitHub, the tool includes support for common IaC tools such as Terraform and AWS CloudFormation, prebuilt libraries with hundreds of policies that validate AWS, Microsoft Azure, and Google Cloud resources, and new developer tooling to support custom rules development and testing with Open Policy Agent.
Major threats to cloud infrastructure security include a lack of visibility and inadequate IAM
98% of companies had experienced at least one cloud data breach in the past 18 months compared to 79% last year, according to an IDC survey. Meanwhile, 67% reported three or more such breaches, and 63% said they had sensitive data exposed.
Protecting your organizations against BEC and other email attacks
Business Email Compromise (BEC) attacks are skyrocketing as organizations rely on decades-old email protocols and standards, and bad actors perfect social engineering.
How do I select a big data solution for my business?
To select a suitable big data solution for your business, you need to think about a variety of factors. We’ve talked to several industry professionals to get their insight on the topic.
Technical certifications demand growing, most IT employees have at least one
Technical certifications are increasingly in demand with 87% of IT employees possessing at least one and 40% pursuing their next. According to Questionmark, certification bodies must ensure they can quickly deliver, and robustly assess, their programs to meet new levels of demand.
How to conquer synthetic identity fraud
Synthetic fraud is today’s fastest-growing type of financial crime. To make matters worse, up to 95% goes undetected by regular fraud models, as these actors behave, act and look like regular customers that neither the human eye nor highly complex computer vision methods would have detected.
Resilience by design: What security pros need to know about microlearning
Microlearning delivers digestible bits of information specifically designed for the learner to retain in a short period of time. Common microlearning content includes videos, simulations, quizzes and more. Sounds simple enough, right?
Threat modeling needs a reset
Organizations need to rethink their approach to threat modeling or risk losing its value as a key defense in their cybersecurity arsenals.
Download: The CISO’s Guide to Third-Party Security Management
In this comprehensive guide, we provide the direction you need to make your organization’s third-party security program efficient and scalable.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/07/04/week-in-review-poc-for-windows-print-spooler-flaw-leaked-conquering-synthetic-identity-fraud/