ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Trend Micro Releases Urgent Fix for Actively Exploited Critical Security Vulnerability

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-8361
Improper Input Validation in Realtek SDK miniigd SOAP Service Enables Remote RCE

The Realtek SDK, a software development kit embedded in routers, gateways, and similar network equipment sold under many OEM brands, contains an improper input validation flaw (CWE-20) in its miniigd UPnP SOAP service. A remote, unauthenticated attacker can trigger it by sending a crafted NewInternalClient request to the vulnerable SOAP interface, causing execution of malicious code on the device. Successful exploitation gives attackers control of affected devices, which can be used for botnet recruitment, staging further attacks, or ransomware operations. Affected parties are owners of devices built on the Realtek SDK, particularly routers and gateways with the UPnP service exposed to the internet. Exploitation is ongoing: CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2023-09-18 and EPSS assigns it a 100% probability of exploitation within 30 days, though ransomware use is not confirmed.

Do: Inventory devices that use the Realtek SDK and check whether the miniigd UPnP/SOAP service is reachable from untrusted networks; apply firmware updates from your device vendor as soon as available, or per CISA's required action, disable UPnP or block the service from internet exposure if mitigations are unavailable. No patch level is published in this dataset, so verify fix status against OEM advisories and review device logs for crafted NewInternalClient SOAP requests.

100% KEV
  • Realtek SDK
mass≈1,000,000+ devices (hundreds of thousands of internet-exposed hosts observed in public scans; SDK embedded in many OEM routers)
CVE-2017-6884
Command Injection in Zyxel EMG2926 Router Diagnostics

CVE-2017-6884 is an OS command injection flaw (CWE-78) in the diagnostic tools of Zyxel EMG2926 routers, located in the nslookup function. An attacker can trigger it through multiple vectors, notably by supplying a malicious ping_ip parameter to the expert/maintenance/diagnostic/nslookup URI, causing attacker-controlled commands to execute on the router. Successful exploitation yields arbitrary command execution on the gateway, providing a foothold that can be used for further network compromise, including by ransomware operators. Any operator of a Zyxel EMG2926 router is affected, and many of these gateways were deployed through internet service providers. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-18 with known ransomware use, and EPSS estimates a 36.8% probability of exploitation within 30 days (98th percentile).

Do: Per CISA's required action, apply mitigations per Zyxel's instructions or discontinue use of the product if mitigations are unavailable. Check whether the router's management interface, including the expert/maintenance/diagnostic/nslookup endpoint, is reachable from the WAN or untrusted networks and restrict access to it; monitor devices for signs of command execution or ransomware-related activity. Fixed firmware versions were not specified in the available data, so consult Zyxel's advisory for the appropriate upgrade path.

8.837% KEV ransomware PoC
  • Zyxel EMG2926 Routers
largetens of thousands of deployed EMG2926 gateways, plausibly 10,000-100,000 affected systems; exact count unknown
CVE-2021-3129
Unauthenticated RCE in Laravel Ignition error-page package (facade/ignition)

Laravel Ignition, the default error-page package bundled with Laravel applications, uses file_get_contents() and file_put_contents() insecurely in its solution-execution feature, allowing unauthenticated remote attackers to read and write arbitrary files on the server. The flaw is triggered by sending a crafted, unauthenticated HTTP request to Ignition's execute-solution endpoint, which is reachable whenever the application runs with debug mode enabled. Attackers can chain the arbitrary file write to execute arbitrary code in the context of the web application, leading to server compromise and, per CISA, ransomware deployment. Any internet-facing Laravel application running a vulnerable version of the Ignition package with debug mode enabled is affected. The vulnerability is known to be exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-18 with ransomware use confirmed, and EPSS assigns it a 99.9% probability of exploitation within 30 days (100th percentile).

Do: Upgrade facade/ignition to 2.5.2 or later on all Laravel applications, or update to a current Laravel release that bundles the fixed package. Ensure production environments run with debug mode disabled and block or restrict the /_ignition/execute-solution endpoint from untrusted access as an interim mitigation. Given confirmed ransomware use, hunt for signs of compromise such as modified environment files, unexpected scheduled tasks, or webshells, and apply the CISA-required mitigations or discontinue use of the product if patching is not possible.

9.8100% KEV ransomware PoC ×3
  • Laravel Ignition (facade/ignition error-page package) Prior to 2.5.2 (CISA data lists affected as 'Laravel Ignition' without a version range; 2.5.2 is the vendor's patched release)
largetens of thousands of internet-facing Laravel apps with debug mode enabled, out of an installed base of hundreds of thousands of Laravel sites
CVE-2022-22265
Use-After-Free in Samsung Mobile NPU Driver Allows Local Code Execution

CVE-2022-22265 is a use-after-free flaw — an improper check or handling of exceptional conditions (CWE-703) — in the neural processing unit (NPU) driver on Samsung mobile devices. A local attacker with limited privileges, such as a malicious app already on the handset, can trigger the flaw without user interaction, causing an arbitrary memory write and arbitrary code execution, effectively a full local privilege escalation. All Samsung mobile devices running a Samsung Mobile Security Release older than the January 2022 (SMR Jan-2022 Release 1) patch level are affected. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-09-18, confirming exploitation in the wild, although CISA lists ransomware use as unknown and EPSS assigns a modest 0.4% probability of exploitation in the next 30 days.

Do: Apply the January 2022 Samsung Mobile Security Release (SMR Jan-2022 Release 1) or any later monthly Samsung security update to all Samsung mobile devices, and verify patch levels via Settings > Software update, prioritizing KEV-listed, unpatched fleets. Because the flaw requires local access, avoid installing untrusted apps on devices pending the update. CISA's required action is to apply vendor mitigations or discontinue use if updates are unavailable.

7.8<1% KEV
  • Samsung Mobile Devices (Android) — NPU driver all devices/patch levels prior to SMR Jan-2022 Release 1
  • Google Android (CPE platform encoding for the affected Samsung devices) as running on Samsung devices without the January 2022 Samsung security update
masstens to hundreds of millions of Samsung Android devices in the affected install base; exact unpatched subset unknown
CVE-2022-31462
+4 in the same advisory: …31460 …31463 …31461 …31459
Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth bro

Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • owllabs meeting owl pro firmware
CVE-2023-28434
+1 in the same advisory: …28432
Bucket Policy Bypass in MinIO Object Storage Lets Users Write to Any Bucket

CVE-2023-28434 is a security feature bypass (CWE-269) in MinIO, an open-source multi-cloud object storage server, where metadata bucket name checking is not properly enforced while processing PostPolicyBucket requests. An attacker holding credentials granted the wildcard bucket permission arn:aws:s3:::* can send crafted requests to bypass the bucket name checks and put an object into any bucket, provided Console API access is enabled. The result is that bucket-level policy isolation can be violated, and in observed attacks the flaw (publicly dubbed Evil_MinIO) has been used against MinIO storage servers. All MinIO releases before RELEASE.2023-03-20T20-16-18Z are affected, with risk concentrated in deployments that expose the Console API and use wildcard-scope credentials. The vulnerability is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-19, public exploit code exists, and news reports describe ongoing attacks on MinIO servers.

Do: Upgrade MinIO to RELEASE.2023-03-20T20-16-18Z or later, which contains the fix. If patching is delayed, apply the documented workaround involving the MINIO_BROWSER/browser API access setting as described in the advisory, and avoid granting credentials the wildcard arn:aws:s3:::* permission alongside Console API access. Since this is in CISA KEV (added 2023-09-19, required action: apply vendor mitigations or discontinue use) and the Evil_MinIO exploit has been used in real attacks, review exposed MinIO consoles for signs of compromise as part of remediation.

8.8
group max
8% KEV PoC
  • MinIO All releases prior to RELEASE.2023-03-20T20-16-18Z
largeon the order of tens of thousands of internet-exposed MinIO instances, plus uncounted private and embedded deployments
CVE-2023-41179
Arbitrary command execution in Trend Micro Apex One and Worry-Free Business Security

CVE-2023-41179 is a code-injection flaw (CWE-94) in the third-party AV uninstaller module shipped with Trend Micro Apex One (on-premises and SaaS), Worry-Free Business Security, and Worry-Free Business Security Services. An attacker who has first obtained administrative console access on the target system can manipulate this module to execute arbitrary commands. Successful exploitation yields remote code execution on the affected installation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). Any organization running these Trend Micro endpoint-security management products is affected, especially those whose consoles are reachable by multiple or untrusted administrators. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-21 and Trend Micro released urgent fixes, though no public proof-of-concept is known and ransomware use has not been confirmed.

Do: Apply Trend Micro's security patch/hotfix per vendor instructions immediately, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Because exploitation requires administrative console access, restrict console reachability to trusted networks or VPN, audit administrative accounts for anomalous activity, and monitor for signs of exploitation given the active in-the-wild abuse.

7.25% KEV
  • Trend Micro Apex One (on-premises and SaaS)
  • Trend Micro Worry-Free Business Security
  • Trend Micro Worry-Free Business Security Services
largetens of thousands of installations (order of 10^4-10^5)
Full article625 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananSep 20, 2023Zero Day / Vulnerability

Cybersecurity company Trend Micro has released patches and hotfixes to address a critical security flaw in Apex One and Worry-Free Business Security solutions for Windows that has been actively exploited in real-world attacks.

Tracked as CVE-2023-41179 (CVSS score: 9.1), it relates to a third-party antivirus uninstaller module that's bundled along with the software. The complete list of impacted products is as follows -

  • Apex One - version 2019 (on-premise), fixed in SP1 Patch 1 (B12380)
  • Apex One as a Service - fixed in SP1 Patch 1 (B12380) and Agent version 14.0.12637
  • Worry-Free Business Security - version 10.0 SP1, fixed in 10.0 SP1 Patch 2495
  • Worry-Free Business Security Services - fixed in July 31, 2023, Monthly Maintenance Release

Trend Micro said that a successful exploitation of the flaw could allow an attacker to manipulate the component to execute arbitrary commands on an affected installation. However, it requires that the adversary already has administrative console access on the target system.

The company also warned that it has "observed at least one active attempt of potential exploitation of this vulnerability in the wild," making it essential that users move quickly to apply the patches.

As a workaround, it's recommending that customers limit access to the product's administration console to trusted networks.

CISA Adds Nine Flaws to KEV Catalog

The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added nine flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild -

  • CVE-2014-8361 (CVSS score: N/A) - Realtek SDK Improper Input Validation Vulnerability
  • CVE-2017-6884 (CVSS score: 8.8) - Zyxel EMG2926 Routers Command Injection Vulnerability
  • CVE-2021-3129 (CVSS score: 9.8) - Laravel Ignition File Upload Vulnerability
  • CVE-2022-22265 (CVSS score: 7.8) - Samsung Mobile Devices Use-After-Free Vulnerability
  • CVE-2022-31459 (CVSS score: 6.5) - Owl Labs Meeting Owl Inadequate Encryption Strength Vulnerability
  • CVE-2022-31461 (CVSS score: 6.5) - Owl Labs Meeting Owl Missing Authentication for Critical Function Vulnerability
  • CVE-2022-31462 (CVSS score: 8.8) - Owl Labs Meeting Owl Use of Hard-coded Credentials Vulnerability
  • CVE-2022-31463 (CVSS score: 7.1) - Owl Labs Meeting Owl Improper Authentication Vulnerability
  • CVE-2023-28434 (CVSS score: 8.8) - MinIO Security Feature Bypass Vulnerability

It's worth noting that a fifth flaw impacting Owl Labs Meeting Owl (CVE-2022-31460, CVSS score: 7.4), a case of hard-coded credentials, was previously added to the KEV catalog on June 8, 2022, merely days after Modzero disclosed details of the flaws.

"By exploiting the vulnerabilities[...], an attacker can find registered devices, their data, and owners from around the world," the Swiss security consultancy firm said at the time.

"Attackers can also access confidential screenshots of whiteboards or use the Owl to get access to the owner's network. The PIN protection, which protects the Owl from unauthorized use, can be circumvented by an attacker by (at least) four different approaches."

Even more troublingly, the devices can be turned into rogue wireless network gateways to a local corporate network remotely via Bluetooth by arbitrary users and can be abused to act as a backdoor to owners' local networks. It's currently not known how these vulnerabilities are exploited in the wild.

The security weakness impacting MinIO has come under abuse in recent months, with Security Joes revealing that an unnamed threat actor is exploiting it in conjunction with CVE-2023-28432 (CVSS score: 7.5) to achieve unauthorized code execution on susceptible servers and drop follow-on payloads.

Update

The five security flaws impacting Owl Labs Meeting Owl have been removed from the KEV Catalog as of October 4, 2023, citing lack of sufficient evidence. More details about the removal are available in our story here.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/09/trend-micro-releases-urgent-fix-for.html