ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Week in review: Microsoft, Apple patch exploited zero-days, tips for getting hired in cybersecurity

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20032
On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed:

On Feb 15, 2023, the following vulnerability in the ClamAV scanning library was disclosed: A vulnerability in the HFS+ partition file parser of ClamAV versions 1.0.0 and earlier, 0.105.1 and earlier, and 0.103.7 and earlier could allow an unauthenticated, remote attacker to execute arbitrary code. This vulnerability is due to a missing buffer size check that may result in a heap buffer overflow write. An attacker could exploit this vulnerability by submitting a crafted HFS+ partition file to be scanned by ClamAV on an affected device. A successful exploit could allow the attacker to execute arbitrary code with the privileges of the ClamAV scanning process, or else crash the process, resulting in a denial of service (DoS) condition. For a description of this vulnerability, see the ClamAV blog ["https://blog.clamav.net/"].

NVD description · AI analysis pending
9.829%
  • cisco secure endpoint
  • cisco secure endpoint private cloud
  • cisco web security appliance
  • +1 more
CVE-2023-21715
Actively Exploited Security Feature Bypass in Microsoft Office Publisher

Microsoft Office Publisher contains a security feature bypass (CWE-863, incorrect authorization) in which a specially crafted Publisher document can circumvent an Office security mechanism, widely reported as a bypass of the Mark-of-the-Web/Protected View protections applied to files from untrusted sources. The flaw is triggered locally when a user opens the malicious document, consistent with the CVSS vector (local attack, low privileges, user interaction required). Successful bypassing yields high impact on the victim system, with high ratings for confidentiality, integrity, and availability. Anyone running Microsoft 365 Apps or Microsoft Office editions that include Publisher is affected, and no specific affected version numbers are published in this data beyond the requirement to apply the February 2023 fixes. The vulnerability is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-02-14 and was patched as one of three exploited zero-days in Microsoft's February 2023 Patch Tuesday.

Do: Apply Microsoft's February 2023 Patch Tuesday security updates to Microsoft 365 Apps and any Office edition that includes Publisher, per vendor instructions as required by the CISA KEV entry; because affected builds differ by update channel, confirm the installed build after updating rather than relying on the date alone. Until patched, exercise caution with Publisher documents from untrusted sources. No public PoC or workaround is documented, so patching is the primary mitigation.

7.312% KEV
  • Microsoft 365 Apps
  • Microsoft Office (Publisher)
mass≈hundreds of millions of Office/365 installations worldwide
CVE-2023-23376
+1 in the same advisory: …21823
Out-of-Bounds Write Privilege Escalation in Microsoft Windows CLFS Driver

CVE-2023-23376 is a heap-based buffer overflow (out-of-bounds write, CWE-122/CWE-787) in the Windows Common Log File System (CLFS) kernel driver. A local attacker with low privileges can trigger the flaw when the driver mishandles CLFS log-file data, with no user interaction required. Successful exploitation elevates the attacker from a low-privileged user to SYSTEM/kernel-level privileges, which is why ransomware operators chain it with other bugs after gaining an initial foothold. All supported Windows 10 (1507, 1607, 1809, 20H2, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2008, 2012, 2016, and 2019 releases as of February 2023 are affected. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on February 14, 2023 with known ransomware use, Microsoft shipped the fix in the February 2023 Patch Tuesday release, and EPSS estimates roughly an 11% probability of exploitation within the next 30 days (96th percentile).

Do: Apply the Microsoft security updates released on February 14, 2023 (February Patch Tuesday) to every Windows 10, Windows 11, and Windows Server system in the affected version list, prioritizing servers and endpoints exposed to ransomware-prone environments. Verify patch status via update history or vulnerability scanning, since exploitation requires only local low-privileged access and there is no substitution for patching. Given confirmed ransomware chaining, also hunt for signs of post-compromise privilege escalation on hosts that were unpatched before mid-February 2023.

7.811% KEV ransomware
  • Microsoft Windows 10 1507 (all builds prior to the February 2023 security updates)
  • Microsoft Windows 10 1607 (all builds prior to the February 2023 security updates)
  • Microsoft Windows 10 1809 (all builds prior to the February 2023 security updates)
  • +9 more
mass~1 billion+ Windows devices (the CLFS driver ships in every listed Windows 10/11 client and Windows Server 2008-2019 release)
CVE-2023-23529
WebKit Type Confusion RCE in Apple iOS, iPadOS, macOS, and Safari

CVE-2023-23529 is a type confusion flaw (CWE-843) in Apple's WebKit engine, which renders web content in Safari and in the system web components of iOS, iPadOS, and macOS. It is triggered when a device processes maliciously crafted web content, typically when a user is lured into viewing an attacker-controlled web page or other web-rendered content. Successful exploitation can lead to arbitrary code execution with the privileges of the affected application (CVSS 3.1: 8.8, network vector, requiring user interaction). Affected users are those running iOS/iPadOS versions before the February 2023 fixes, macOS Ventura before 13.2.1, or Safari before 16.3. Apple reported the issue may have been actively exploited before patching, and CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-14; no public proof-of-concept is known.

Do: Apply the vendor updates immediately per CISA's KEV required action: iOS/iPadOS 16.3.1 (or 15.7.4 for devices remaining on the iOS 15 branch), macOS Ventura 13.2.1, and Safari 16.3. Inventory managed iPhones, iPads, and Macs to verify updated versions, prioritizing devices used to browse untrusted web content. As an interim mitigation, treat untrusted links and web content with caution until all endpoints are patched.

8.810% KEV
  • Apple iPhone OS (iOS) iOS versions prior to the fixed releases; fixed in iOS 16.3.1 and in iOS 15.7.4 on the legacy branch
  • Apple iPadOS iPadOS versions prior to the fixed releases; fixed in iPadOS 16.3.1 and in iPadOS 15.7.4 on the legacy branch
  • Apple macOS (Ventura) macOS Ventura versions prior to 13.2.1
  • +1 more
massorder of 1 billion+ devices/users (Apple's active installed base of iOS, iPadOS, and macOS devices and Safari's user base exceed a billion; nearly all ran…
Full article1,025 words · extracted from helpnetsecurity.com · click to collapse

Cybersecurity week in review

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Combining identity and security strategies to mitigate risks
The Identity Defined Security Alliance (IDSA), a nonprofit that provides vendor-neutral resources to help organizations reduce the risk of a breach by combining identity and security strategies, announced Jeff Reich as the organization’s new Executive Director.

Can we predict cyber attacks? Bfore.AI says they can
In this Help Net Security interview, Luigi Lenguito, CEO at Bfore.AI, talks about threat prevention challenges and how his company can predict cyber attacks before they begin.

Microsoft patches three exploited zero-days (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823)
The February 2023 Patch Tuesday is upon us, with Microsoft releasing patches for 75 CVE-numbered vulnerabilities, including three actively exploited zero-day flaws (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823).

Helping users and organizations build an instinctive data privacy habit
Many organizations around the world engage in efforts to raise awareness about the importance of online privacy during that week, including the National Cybersecurity Alliance (NCA) – a non-profit whose goal is to demystify complex security topics to help consumers and businesses better understand the simple steps they can take to protect themselves.

Get hired in cybersecurity: Expert tips for job seekers
In this Help Net Security interview, Joseph Cooper, Cybersecurity Recruiter at Aspiron Search, offers practical advice for job seekers and talks about how the cybersecurity profession continues to expand.

Admins, patch your Cisco enterprise security solutions! (CVE-2023-20032)
Cisco has released security updates for several of its enterprise security and networking products.

DHL, MetaMask phishing emails target Namecheap customers
A surge of phishing emails impersonating DHL and MetaMask have started hitting inboxes of Namecheap customers last week, attempting to trick recipients into sharing personal information or sharing their crypto wallet’s secret recovery phrase.

Apple fixes actively exploited WebKit zero-day in iOS, macOS (CVE-2023-23529)
Apple has released security updates that fix a WebKit zero-day vulnerability (CVE-2023-23529) that “may have been actively exploited.”

Vulnerabilities open Korenix JetWave industrial networking devices to attack
Three vulnerabilities found in a variety of Korenix JetWave industrial access points and LTE cellular gateways may allow attackers to either disrupt their operation or to use them as a foothold for further attacks, CyberDanube researchers have found.

Reimagining zero trust for modern SaaS
The concept of zero trust – as a way to improve the security of and access to an organization’s network, systems, and data – has gained traction in recent years.

Malware that can do anything and everything is on the rise
“Swiss Army knife” malware – multi-purpose malware that can perform malicious actions across the cyber-kill chain and evade detection by security controls – is on the rise, according to the results of Picus Security’s analysis.

Introducing the book – Threats: What Every Engineer Should Learn From Star Wars
Adam Shostack, the author of “Threat Modeling: Designing for Security”, and the co-author of “The New School of Information Security”, recently launched his new book – “Threats: What Every Engineer Should Learn From Star Wars”.

Steps CISA should take in 2023
The quality of content CISA releases is consistently top-notch, whether they are advisories, infographics, or videos. Its releases are educational, accessible, and timely — essential in a fast-moving field like cybersecurity.

Navigating the ever-changing landscape of digital security solutions
Recently, Entrust named Bhagwat Swaroop as President, Digital Security Solutions. In this role, Bhagwat will lead the evolution, growth, and expansion of the Entrust Digital Security portfolio, which includes solutions for data encryption, public and private certificate authorities, identity and access management, digital signing, and security policy management.

Cybercriminals exploit fear and urgency to trick consumers
Cybercriminals remained active in spying and information stealing, with lottery-themed adware campaigns used as a tactic to obtain people’s contact details, according to Avast.

As regulations skyrocket, is compliance even possible anymore?
In this Help Net Security video, Gianna Price, Solutions Architect at Telos Corporation, explores what organizations can do to streamline compliance and get ahead.

The risks and benefits of starting a vCISO practice
There is a definite trend of MSPs shifting into security. There are a number of very good reasons for this, including the fact that other services traditionally offered are becoming commoditized, as well as the increasing threat that SMEs and SMBs are facing when it comes to cyber attacks.

High-risk users may be few, but the threat they pose is huge
High-risk users represent approximately 10% of the worker population and are found in every department and function of the organization, according to Elevate Security research.

How to prevent DDoS attacks
In this Help Net Security video, Matthew Andriani, CEO at MazeBolt, discusses the growing threat and impact of DDoS attacks and how organizations can stay safe against them.

Attack surface management (ASM) is not limited to the surface
Attack surface management (ASM) is a make or break for organizations, but before we get to the usual list of best practices, we need to accept that attack surface management is not limited to the surface.

Actionable intelligence is the key to better security outcomes
Despite the widespread belief that understanding the cyber threat actors who could be targeting their organization is important, 79% of respondents stated that their organizations make the majority of cybersecurity decisions without insights into the threat actor targeting them.

Expected advancements in quantum cryptography
In this Help Net Security video, Vanesa Diaz, CEO at LuxQuanta, talks about how precautions must be taken ahead of this new quantum age, where cybersecurity solutions require significant attention and developments to ensure the protection and security of data.

Application and cloud security is a shared responsibility
Cloud environments and application connectivity have become a critical part of many organizations’ digital transformation initiatives.

How hackers can cause physical damage to bridges
In this Help Net Security video, Daniel Dos Santos, Head of Security Research at Forescout, talks about recent research, which has revealed how attackers can move laterally between vulnerable networks and devices found at the controller level of critical infrastructure.

New infosec products of the week: February 17, 2023
Here’s a look at the most interesting products from the past week, featuring releases from CyberSaint, DigiCert, Finite State, FireMon, and Veeam Software.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/02/19/week-in-review-microsoft-apple-patch-exploited-zero-days-tips-for-getting-hired-in-cybersecurity/