Hackers Exploiting Recently Reported Windows Print Spooler Vulnerability in the Wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-6882 | Cross-Site Scripting (XSS) in Synacor Zimbra Collaboration Suite Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting flaw (CWE-79) that allows remote attackers to inject arbitrary web script or HTML through the ZCS web interface. An attacker who successfully injects script can execute it in the browser context of a logged-in Zimbra user, enabling actions such as stealing session cookies or credentials, defacing webmail content, or chaining into further compromise; the specific injection vector is not detailed in the available data. Any organization running Zimbra Collaboration Suite, particularly deployments exposing the ZCS webmail interface to the internet, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-19 with known ransomware use, and EPSS estimates a 25.3% probability of exploitation within 30 days (98th percentile), although no public proof-of-concept is known. Do: Apply the latest Zimbra Collaboration Suite patches per Synacor's vendor instructions, as required by CISA's KEV listing, prioritizing internet-facing webmail servers given confirmed in-the-wild exploitation and known ransomware use. Because the affected version range is not specified in this data, check your current ZCS release against Synacor's advisory and upgrade to any patched release it designates. In the interim, restrict exposure of the ZCS web interface and monitor for unexpected injected script or HTML in webmail content. | 6.1 | 25% | KEV ransomware PoC |
| mass≈ millions of users across tens of thousands of internet-exposed ZCS servers (estimate; public internet-wide scans of Zimbra deployments) | |
| CVE-2019-3568 | Buffer Overflow RCE in WhatsApp VoIP Stack via Crafted RTCP Packets A buffer overflow (CWE-122) in the VoIP telephony stack of WhatsApp allowed a remote attacker to achieve remote code execution on a target device by sending a specially crafted series of RTCP packets to the victim's phone number. Because the flaw resided in the call-handling stack of the core app, an attacker who could reach the target's phone number over the network could gain arbitrary code execution on the device. All WhatsApp users at the time of disclosure were potentially exposed, since the vulnerable component shipped in the mainstream Meta Platforms (then Facebook) product rather than an optional add-on. The vulnerability was added to CISA's Known Exploited Vulnerability catalog on 2022-04-19, indicating confirmed real-world exploitation, and its EPSS score of 39.2% (99th percentile) signals a high likelihood of continued exploitation; no public proof-of-concept is known. It was remediated in vendor updates issued in 2019 and is widely associated with targeted espionage use (notably Pegasus spyware deployments). Do: Update WhatsApp on all mobile devices to the latest vendor release, per the CISA KEV required action; inventory your mobile fleet for outdated 2019-era builds and verify current app versions. Prioritize high-value targets (executives, journalists, government personnel) given the vulnerability's confirmed in-the-wild exploitation in espionage campaigns. No public PoC is known, but the flaw is remotely exploitable via network packets to a phone number, so treat patching as urgent. | 9.8 | 30% | KEV |
| mass≈1.5–2 billion users (effectively the entire global WhatsApp user base at the time of disclosure) | |
| CVE-2022-22718 | Local Privilege Escalation in Microsoft Windows Print Spooler CVE-2022-22718 is an elevation of privilege vulnerability in the Microsoft Windows Print Spooler service, the component that manages printing and print queues on Windows systems. A local attacker who can already execute low-privileged code on a vulnerable machine can exploit the flaw with no user interaction required. Successful exploitation grants elevated (SYSTEM-level) privileges, giving the attacker full control of the compromised host. The affected range spans essentially the entire supported Windows installed base at the time of disclosure, including Windows 7 through Windows 11 21H2 and Windows Server 2008. The flaw is known to be exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-19 and carries an 18.5% EPSS probability of exploitation within 30 days (97th percentile), though no public proof-of-concept is catalogued and ransomware use is listed as unknown. Do: Apply Microsoft's security updates (released with the February 2022 Patch Tuesday and later cumulative updates) to every affected Windows system, per CISA's required action to update per vendor instructions; Windows 7 and 8.1 may require extended-security-update coverage. Prioritize multi-user and high-value hosts such as domain controllers, Remote Desktop Session Hosts, and print servers, where a local privilege escalation to SYSTEM is most impactful. As an interim mitigation where patching is delayed, consider disabling the Print Spooler service on systems that do not need printing. | 7.8 | 18% | KEV |
| masshundreds of millions to 1B+ Windows devices (Windows 10 alone was reported running on over 1 billion active devices) |
Full article351 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 20, 2022
A security flaw in the Windows Print Spooler component that was patched by Microsoft in February is being actively exploited in the wild, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned.
To that end, the agency has added the shortcoming to its Known Exploited Vulnerabilities Catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to address the issues by May 10, 2022.
Tracked as CVE-2022-22718 (CVSS score: 7.8), the security vulnerability is one among the four privilege escalation flaws in the Print Spooler that Microsoft resolved as part of its Patch Tuesday updates on February 8, 2022.
It's worth noting that the Redmond-based tech giant has remediated a number of Print Spooler flaws since the critical PrintNightmare remote code execution vulnerability came to light last year, including 15 elevation of privilege vulnerabilities in April 2022.
Specifics about the nature of the attacks and the identity of the threat actors that may be exploiting the Print Spooler defect remain unknown, partly in an attempt to prevent further exploitation by hacking crews. Microsoft, for its part, assigned it an "exploitation more likely" tag back when the fixes were rolled out two months ago.
Also added to the catalog are two other security flaws based on "evidence of active exploitation" -
- CVE-2018-6882 (CVSS score: 6.1) - Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability
- CVE-2019-3568 (CVSS score: 9.8) - WhatsApp VOIP Stack Buffer Overflow Vulnerability
The addition of CVE-2018-6882 comes close on the heels of an advisory released by the Computer Emergency Response Team of Ukraine (CERT-UA) last week, cautioning of phishing attacks targeting government entities with the goal of forwarding victims' emails to a third-party email address by leveraging the Zimbra vulnerability.
CERT-UA attributed the targeted intrusions to a threat cluster tracked as UAC-0097.
In light of real world attacks weaponizing the vulnerabilities, organizations are recommended to reduce their exposure by "prioritizing timely remediation of [...] as part of their vulnerability management practice."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/04/hackers-exploiting-recently-reported.html