ZeroHour
The Recordpublished ()ingested

CISA adds printer bug, Chrome zero-day and ChatGPT issue to exploited vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-2136CVE-2023-28432

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2136
Skia Integer Overflow Sandbox Escape in Google Chrome

An integer overflow (CWE-190) in Skia, the 2D graphics library used by Chrome's renderer, can be triggered by a crafted HTML page whose content drives Skia processing past the limits of its integer math. A remote attacker who has already compromised the Chrome renderer process — for example through a separate renderer flaw or a malicious page — can leverage the overflow to escape Chrome's renderer sandbox and gain broader code execution on the host. All Google Chrome and Chromium users running versions prior to 112.0.5615.137 are affected, including Chromium packages shipped by Debian and Fedora. The flaw is rated Critical (CVSS 3.1: 9.6) and carries Chromium security severity High, with an EPSS probability of 5.7% (93rd percentile) of exploitation within 30 days. It was added to CISA's Known Exploited Vulnerability catalog on 2023-04-21, and news reports describe it as an actively exploited Chrome zero-day for which Google rushed out the 112.0.5615.137 patch.

Do: Update Google Chrome to 112.0.5615.137 or later on all platforms, and install the corresponding Chromium security updates on Debian and Fedora systems. Because exploitation requires user interaction with a crafted page plus a pre-existing renderer compromise, prompt patching is the primary mitigation; verify via CISA KEV required actions that all managed browsers are updated and confirm Chrome versions in endpoint inventory.

9.66% KEV
  • Google Chrome all versions prior to 112.0.5615.137
  • Google Chromium Chromium builds with Skia code prior to the fix delivered in 112.0.5615.137
  • Debian Linux (chromium package)
  • +1 more
masson the order of billions of Chrome/Chromium users worldwide (~3+ billion installations; ~65% browser market share)
CVE-2023-28432
Unauthenticated Information Disclosure in MinIO Object Storage Clusters

MinIO, a Multi-Cloud Object Storage framework, exposes its entire set of environment variables in distributed (cluster) deployments running RELEASE.2019-12-17T23-16-33Z or later but prior to RELEASE.2023-03-20T20-16-18Z: an unauthenticated POST request to the cluster bootstrap endpoint (/cluster?bootstrap) on the MinIO API port (default 9000) returns secrets including MINIO_SECRET_KEY and MINIO_ROOT_PASSWORD. An attacker with network access to that port needs no privileges or user interaction (CVSS 3.1: AV:N/AC:L/PR:N, 7.5 high), and with the retrieved root credentials gains full administrative control over the stored objects; the publicly shared 'Evil_MinIO' exploit demonstrates the disclosure can be chained into full server compromise. Only distributed/cluster deployments are affected; the flaw is classified as CWE-200 information disclosure. The bug is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-21, EPSS ranks it in the 100th percentile with an 84% probability of exploitation within 30 days, and attacks on MinIO servers using the Evil_MinIO exploit have been reported.

Do: Upgrade distributed MinIO clusters to RELEASE.2023-03-20T20-16-18Z or later per the vendor advisory and the CISA KEV required action, and restrict untrusted network access to the MinIO API port (default 9000). Because the flaw leaks the entire environment, rotate MINIO_ROOT_PASSWORD/MINIO_SECRET_KEY and any other credentials passed via environment variables, and review logs for suspicious POST /cluster?bootstrap requests or unexpected logins.

7.584% KEV PoC
  • MinIO (Multi-Cloud Object Storage) Distributed/cluster deployments from RELEASE.2019-12-17T23-16-33Z (inclusive) through RELEASE.2023-03-20T20-16-18Z (exclusive); fixed in RELEASE.2023-03-20T20-1
large≈10,000-20,000 internet-exposed instances (public scan data at disclosure time; many more in private deployments)
Full article516 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) added an issue affecting a popular print management software tool to its list of exploited vulnerabilities on Friday.

PaperCut is a software company that produces printing management software for Canon, Epson, Xerox, Brother and almost every other major printer brand. Their tools are widely used within governments agencies, universities, and large companies around the world.

But on Wednesday, the company published an urgent update to an advisory recommending companies install a patch for the vulnerability.

“We have evidence to suggest that unpatched servers are being exploited in the wild,” the company said. The first published an advisory about the issue on March 8.

“If you suspect that your server has been compromised, we recommend taking server backups, then wiping the Application Server, and rebuilding the Application Server and restoring the database from a ‘safe’ backup point prior to when you discovered any suspicious behavior.”

CVE-2023–27350 was the most severe of the two, with a CVSS score of 9.8 out of 10. That vulnerability – which CISA added to its Known Exploited Vulnerability catalog on Friday – allows an unauthenticated attacker to access victim systems remotely without the need to log in anywhere.

PaperCut released a fix for the vulnerability last month and CISA gave federal civilian agencies until May 12 to install the patch.

The PaperCut vulnerability was one of three bugs added to CISA’s list on Friday. A zero-day vulnerability affecting Google Chrome – CVE-2023-2136 – was also added to the list after Google released a security update for the issue on Wednesday.

Google said it “is aware that an exploit for CVE-2023-2136 exists in the wild.” The vulnerability affects Skia, a tool used by the browser to render graphics, text, shapes, images, and animations.

The other vulnerability added, CVE-2023-28432, affects a tool called MinIO which is used widely for machine learning, analytics and more.

Threat intelligence company GreyNoise explained that the issue affects OpenAI’s popular ChatGPT tool. Last month, OpenAI added a new feature to the headline-grabbing tool that allows it to pull information from other sources.

“There are some concerns about the security of the example code provided by OpenAI for developers who want to integrate their plugins with the new feature,” GreyNoise’s Matthew Remacle said.

“While we have no information suggesting that any specific actor is targeting ChatGPT example instances, we have observed this vulnerability being actively exploited in the wild. When attackers attempt mass-identification and mass-exploitation of vulnerable services, ‘everything’ is in scope, including any deployed ChatGPT plugins that utilize this outdated version of MinIO.”

Like the PaperCut issue, both the Google and MinIO vulnerabilities need to be patched by federal civilian agencies by May 12.

Clarification (4/24/2023): This story has been updated to include information about PaperCut's original advisory.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-printer-bug-and-chrome-zero-day-to-catalogue