ZeroHour
The Recordpublished ()ingested

Google Chrome, D-Link bugs among twelve added to CISA’s list of known exploited vulnerabilities

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-3075CVE-2018-2628CVE-2020-9934

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-2628
Unauthenticated Java Deserialization RCE in Oracle WebLogic Server via T3

CVE-2018-2628 is a deserialization flaw (CWE-502) in the WLS Core Components of Oracle WebLogic Server that can be triggered by an unauthenticated attacker simply by sending malicious data over the T3 protocol to a reachable server. Because exploitation requires no credentials or user interaction and is easy to execute, a successful attack allows complete takeover of the WebLogic server, giving the attacker full confidentiality, integrity, and availability impact (CVSS 9.8). Any WebLogic Server installation running affected versions 10.3.6.0, 12.1.3.0, 12.2.1.2, or 12.2.1.3 is vulnerable, with internet-facing T3 endpoints at highest risk. Exploitation is well established: it is in CISA's Known Exploited Vulnerabilities catalog (added 2022-09-08), carries a 99.4% EPSS probability of exploitation, has three public exploits on Exploit-DB, and attackers have actively scanned for vulnerable WebLogic servers — including after Oracle's initial patch proved incomplete and reopened patched servers to attack.

Do: Apply the Oracle Critical Patch Update fixes for WebLogic Server on all affected versions (10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3), and re-verify patching against the most recent Oracle CPU since the initial fix was incomplete and left updated servers exposed. Restrict access to the T3 protocol (default port 7001) so it is reachable only from trusted hosts, and prioritize patching any T3 endpoints exposed to the internet. Search logs for suspicious T3 traffic and confirm remediation with a public exploit check.

9.899% KEV PoC ×3
  • Oracle WebLogic Server (WLS Core Components) 10.3.6.0, 12.1.3.0, 12.2.1.2, 12.2.1.3
large≈10,000–30,000 internet-exposed WebLogic servers, with a far larger internal enterprise install base
CVE-2020-9934
Environment Variable Handling Information Disclosure in Apple iOS, iPadOS, and macOS

CVE-2020-9934 is an input validation flaw in the way Apple operating systems handled environment variables, which could allow a local user to view sensitive user information. It is triggered by a local attacker or user with limited privileges running code or commands on a vulnerable device, where the mishandled environment variables leak data. Successful exploitation results in disclosure of confidential information only, with no impact on data integrity or availability per the CVSS scoring. It affects devices running iOS or iPadOS versions before 13.6 and macOS Catalina versions before 10.15.6. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-08, confirming exploitation in the wild, though no public proof-of-concept is known.

Do: Upgrade affected devices to iOS 13.6 / iPadOS 13.6 or later, and macOS Catalina systems to 10.15.6 or later, as required by CISA's KEV listing. Because exploitation requires local access, restrict local user accounts on shared Macs and iOS devices and review who can execute code on them. Use MDM or endpoint inventory to confirm fleet-wide patch levels against these minimum versions.

5.53% KEV
  • Apple iPhone OS (iOS) versions prior to iOS 13.6
  • Apple iPadOS versions prior to iPadOS 13.6
  • Apple macOS (macOS Catalina) macOS Catalina versions prior to 10.15.6
masshundreds of millions of devices (Apple's active iOS/macOS install base exceeds 1 billion, and all devices on pre-fix builds at disclosure were affected)
CVE-2022-3075
Actively Exploited Sandbox Escape via Insufficient Mojo Validation in Google Chrome

CVE-2022-3075 is an insufficient data validation flaw (CWE-20) in Mojo, the inter-process communication layer of the Chromium browser engine, affecting Google Chrome versions prior to 105.0.5195.102. An attacker triggers it via a crafted HTML page after first compromising the browser's renderer process; the bug then allows code to escape the Chrome sandbox. Successful exploitation yields execution outside the renderer sandbox, potentially giving the attacker broader access to the host, which the 9.6 CVSS score reflects via network attack vector, user interaction, and high impact across the changed scope. All users of Google Chrome prior to 105.0.5195.102 are exposed, and Fedora, which ships Chromium-based browser packages, is also listed as affected. The flaw was confirmed as a zero-day exploited in the wild — Google's ninth actively exploited Chrome zero-day of 2022 — was added to CISA's KEV catalog on 2022-09-08, and carries a 5.8% EPSS probability of exploitation within 30 days.

Do: Update Google Chrome to 105.0.5195.102 or later on all desktop platforms and restart the browser; verify the running version via chrome://version. Fedora users should immediately apply system updates to receive rebuilt Chromium packages. Because this flaw is in CISA's Known Exploited Vulnerabilities catalog, KEV-bound organizations (including federal agencies) must apply the vendor updates by the required deadline.

9.66% KEV
  • Google Chrome all versions prior to 105.0.5195.102
  • Fedora Project Fedora (Chromium-based browser packages) Chromium code prior to 105.0.5195.102; exact Fedora package versions not specified in the data
mass≈3 billion+ users (order of magnitude: billions, based on Chrome's dominant market share)
Full article821 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) added twelve vulnerabilities to its catalog of known exploited bugs this week, highlighting several issues found in Google Chrome as well as tools from QNAP, D-Link, Apple, Oracle and more.

Federal civilian agencies have until September 29 to patch the vulnerabilities and as with all additions to the list, CISA said there is evidence of active exploitation.

“These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise,” CISA said in its notice. 

Several experts pointed to CVE-2022-3075 – a high-severity bug affecting web browsers that utilize Chromium like Google Chrome and Microsoft Edge – as the most serious of the additions due to its ubiquity. 

CISA explained that Google Chromium Mojo “contains an insufficient data validation vulnerability” but noted that the impacts from exploitation “are not yet known.” 

Despite how widespread it might be, several experts said Google makes it relatively easy to update Chrome, reducing the likelihood of rampant abuse. 

Qualys security engineer Saeed Abbasi told The Record that attention will focus around the Chrome bug because it is of extremely high severity and because it is known to be actively exploited in the wild.

“With over 65% of internet users browsing via Chrome, the scope and scale of risk that a vulnerability like this presents is massive,” Abbasi said. 

“While users are grateful for the urgent patch released by Google, it came to fruition just before the Labor Day weekend holiday, when many IT and cybersecurity staffers were on vacation and unable to respond in a timely manner.” 

Abbasi added that the rate at which Google has disclosed vulnerabilities — a reflection of the speed at which they are weaponized — is overwhelming security teams. This is the sixth zero-day Google has released in 2022.

“Paired with the severe talent shortage, these pain points could be detrimental to businesses,” Abbasi said. 

Ryan Cribelar, vulnerability research engineer at Nucleus Security, agreed that CVE-2022-3075 has the widest potential reach in this round of additions to CISA’s list. 

“Not only did this vulnerability affect a fresh version of Chrome right off of a large security update, but it was also given its own emergency update cycle and pushed out with a warning from Google to get on version 105.0.5195.102,” he said. Cribelar also spotlighted several other additions to the list that concerned him, including CVE-2018-2628 — a bug targeting the often-compromised Oracle WebLogic.  

Cribelar said it was the only observed vulnerability by security researcher company GreyNoise to be actively scanned opportunistically on the internet.

“The Oracle WebLogic CVE-2018-2628 RCE is also a widespread and reoccurring issue in that WebLogic servers are ripe in opportunity for attackers to install things such as cryptominers,” he explained. “It is often that WebLogic servers are capable of consuming a ton of resources in an environment. This is what makes it a great target candidate for such activity.”

Vulcan Cyber’s Mike Parkin said that the Apple vulnerability — CVE-2020-9934 — was also an issue because of the widespread use of Apple iOS, iPadOS, and macOS. 

Like Google, however, Apple offers paths to automatically update vulnerable versions, Parkin noted.

One of the listed vulnerabilities affects QNAP’s Photo Station tool and was warned about last week by the company, which told users not to connect the product directly to the internet.

QNAP released the warning following the most recent spate of Deadbolt ransomware attacks over the Labor Day long weekend. Deadbolt ransomware actors have repeatedly targeted QNAP network-attached storage devices connected to the internet. 

“The lesson from this one is to look from time to time at your scans of Internet-facing devices, ignoring the vulnerabilities, and just looking at the devices themselves. Look for something that shouldn't be there,” Cribelar said. 

“And if you find something that shouldn't be there, get it out of there before you end up with a bigger problem.”

End-of-life software

One of the other major trends Cribelar referenced was the prevalence of end-of-life software. The latest additions to CISA’s list include multiple vulnerabilities affecting D-Link routers that were end-of-life, meaning the company would no longer be servicing them. In April, CISA added several bugs found in such routers.

Cribelar lauded the agency for adding the bugs, knowing that end-of-life products are often still utilized in many environments. 

“Those who have been in this situation often understand when some end-of-life devices/software are still in use in an environment, but it has to be clear that the plan to move away from this must continue to stay in motion,” he said. 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/google-chrome-d-link-bugs-among-twelve-added-to-cisas-list-of-known-exploited-vulnerabilities