ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Warns of Active Attacks Exploiting Fortra MFT, TerraMaster NAS, and Intel Driver Flaws

criticalAdvisory exploited in the wildimportance 60CVE-2022-24990CVE-2015-2291CVE-2023-0669

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2015-2291
Input Validation DoS Flaw in Intel Ethernet Diagnostics Driver for Windows

CVE-2015-2291 is an input-validation flaw (CWE-20) in the Windows kernel-mode driver files IQVW32.sys and IQVW64.sys that ship with Intel's Ethernet diagnostics software for Windows. It is triggered when the driver mishandles malformed or unexpected input (such as a crafted request from code running on the host), causing the affected Windows system to crash. An attacker gains denial of service — a system-wide crash or blue-screen — on any Windows machine where the vulnerable diagnostics drivers are installed, a technique CISA notes has been used in ransomware operations. Any Windows workstation or server running the Intel Ethernet Diagnostics Driver is affected. Exploitation is in the wild: CISA added the flaw to the KEV catalog on 2023-02-10 with known ransomware use; EPSS estimates a 9.0% probability of exploitation in the next 30 days (95th percentile), and no public PoC is known.

Do: Inventory Windows hosts for the driver files IQVW32.sys and IQVW64.sys (including driver service entries) to determine exposure, then apply updated Intel Ethernet diagnostics/network drivers per Intel's instructions, as required by CISA's KEV listing. Given known ransomware use, prioritize high-value servers and endpoints where untrusted code or users run. Restricting local code execution to trusted users reduces exposure until updates are applied.

9% KEV ransomware
  • Intel Ethernet Diagnostics Driver for Windows
mass≈ millions of Windows endpoints plausibly carry these Intel diagnostics drivers; exact count unknown
CVE-2022-24990
Unauthenticated RCE via Admin Password Leak in TerraMaster TOS 4.2.29 and earlier

TerraMaster TOS (TerraMaster OS) versions 4.2.29 and earlier do not require authentication (CWE-306) on the mobile API endpoint module/api.php?mobile/webNasIPS, and a request presenting the User-Agent "TNAS" returns system information that includes the administrative account's password in the PWD field. An unauthenticated attacker with network access to the NAS web interface can send this request and read the response, obtaining full administrative credentials. With those credentials an attacker controls the NAS, and public proof-of-concept exploits chain this flaw with a PHP object-instantiation bug to achieve unauthenticated remote command execution. Any TerraMaster NAS running TOS 4.2.29 or earlier is affected, with internet-exposed devices at the greatest risk. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities Catalog (added 2023-02-10) with known ransomware use, carries an EPSS of roughly 84%, and CISA and press reports describe active attacks, including North Korean ransomware activity against healthcare and critical infrastructure.

Do: Upgrade TerraMaster TOS to a release newer than 4.2.29 per the vendor's instructions, as required by the CISA KEV entry. If patching must wait, restrict the TOS web interface to trusted networks so unauthenticated users cannot reach module/api.php?mobile/webNasIPS. Check device logs for requests to the webNasIPS endpoint with a TNAS User-Agent and look for signs of post-compromise activity, since ransomware use of this flaw is known.

7.584% KEV ransomware PoC ×3
  • TerraMaster OS (TOS) on TerraMaster NAS devices 4.2.29 and earlier
largeon the order of tens of thousands of internet-exposed TerraMaster NAS devices (estimate, not a verified count)
CVE-2023-0669
Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT

Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%.

Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use.

7.2100% KEV ransomware PoC ×3
  • Fortra GoAnywhere MFT
moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface)
Full article469 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 11, 2023Threat Response / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active abuse in the wild.

Included among the three is CVE-2022-24990, a bug affecting TerraMaster network-attached storage (TNAS) devices that could lead to unauthenticated remote code execution with the highest privileges.

Details about the flaw were disclosed by Ethiopian cyber security research firm Octagon Networks in March 2022.

The vulnerability, according to a joint advisory released by U.S. and South Korean government authorities, is said to have been weaponized by North Korean nation-state hackers to strike healthcare and critical infrastructure entities with ransomware.

The second shortcoming to be added to KEV catalog is CVE-2015-2291, an unspecified flaw in the Intel ethernet diagnostics driver for Windows (IQVW32.sys and IQVW64.sys) that could throw an affected device into a denial-of-service state.

The exploitation of CVE-2015-2291 in the wild was revealed by CrowdStrike last month, detailing a Scattered Spider (aka Roasted 0ktapus or UNC3944) attack that entailed an attempt to plant a legitimately signed but malicious version of the vulnerable driver using a tactic called Bring Your Own Vulnerable Driver (BYOVD).

The goal, the cybersecurity firm said, was to bypass endpoint security software installed on the compromised host. The attack was ultimately unsuccessful.

The development underscores the growing adoption of the technique by multiple threat actors, namely BlackByte, Earth Longzhi, Lazarus Group, and OldGremlin, to power their intrusions with elevated privileges.

Lastly, CISA has also added a remote code injection issue discovered in Fortra's GoAnywhere MFT managed file transfer application (CVE-2023-0669) to the KEV catalog. While patches for the flaw were released recently, the exploitation has been linked to a cybercrime group affiliated with a ransomware operation.

Huntress, in an analysis published earlier this week, said it observed the infection chain leading to the deployment of TrueBot, a Windows malware attributed to a threat actor known as Silence and which shares connections with Evil Corp, a Russian e-crime crew that exhibits tactical overlaps with another financially motivated group dubbed TA505.

With TA505 facilitating the deployment of Clop ransomware in the past, it's being suspected that the attacks are a precursor to deploying file-locking malware on targeted systems.

Furthermore, security blog Bleeping Computer reported that the Clop ransomware crew reached out to the publication and claimed to have exploited the flaw to steal data stored in the compromised servers from over 130 companies.

Federal Civilian Executive Branch (FCEB) agencies are required to apply the fixes by March 3, 2023, to secure the networks against active threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/02/cisa-warns-of-active-attacks-exploiting.html