ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Attackers are leveraging Follina. What can you do?

highExploit / PoC exploited in the wildimportance 60CVE-2022-30190CVE-2021-40444

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-40444
Remote Code Execution via MSHTML Rendering Engine in Microsoft Windows/Office (CVE-2021-40444)

CVE-2021-40444 is a remote code execution vulnerability in the Microsoft MSHTML browser rendering engine, which Microsoft Office documents can load on Windows systems. It is triggered when a user is convinced to open a specially crafted Office document containing a malicious ActiveX control hosted by the MSHTML engine (tracked as a path-traversal-class issue, CWE-22). A successful attacker gains the ability to run arbitrary code in the context of the logged-on user, with greater impact when that user has administrative rights. Any Windows system that can open Office documents is exposed, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H1) and Windows Server 2004/2008. Exploitation is confirmed in the wild: Microsoft observed targeted attacks at disclosure, the flaw is in CISA's KEV with known ransomware use, and Microsoft released security updates on September 14, 2021.

Do: Apply Microsoft's security updates released September 14, 2021 for your Windows version immediately; this is a CISA KEV item with known ransomware use, so patching is treated as mandatory. As interim protection, keep Microsoft Defender Antivirus/Defender for Endpoint signatures current (enterprise detection build 1.349.22.0 or newer, with alerts appearing as 'Suspicious Cpl File Execution') and avoid opening untrusted Office documents, since exploitation requires user interaction with a crafted file.

8.897% KEV ransomware PoC ×2
  • microsoft MSHTML as shipped in the affected Windows releases
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all versions covered by Microsoft's September 2021 security updates
  • +4 more
masshundreds of millions of Windows PCs and servers (nearly all Windows desktop/laptop installs on affected versions at disclosure)
CVE-2022-30190
MSDT URL Protocol Remote Code Execution in Microsoft Windows (Follina)

CVE-2022-30190 (Follina) is a remote code execution flaw in the Microsoft Windows Support Diagnostic Tool (MSDT) when MSDT is invoked through its ms-msdt URL protocol by a calling application such as Microsoft Word. Attackers trigger it by luring a user into opening a malicious document — typically a Word/RTF file whose link or remotely linked template launches the ms-msdt: URI with attacker-supplied commands — and CVSS 3.1 rates it 7.8 with a local attack vector and required user interaction. A successful exploit runs arbitrary code with the privileges of the calling application, allowing the attacker to install programs, view, change or delete data, or create new accounts in the user's context. Per the CISA data, affected platforms are Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 21H2, Windows 11 21H2, and Windows Server 2008 and 2012 — essentially any Windows installation that ships MSDT, with Office/Word as the common delivery vector. Exploitation is confirmed in the wild: Microsoft acknowledged it as an exploited zero-day, CISA added it to the KEV on 2022-06-14 with known ransomware use, EPSS puts the 30-day exploitation probability at 99.2% (99th percentile), and contemporaneous reporting also tied its use to espionage actors including APT28.

Do: Apply Microsoft's security updates per vendor instructions (the fix shipped in the June 2022 Patch Tuesday releases for the affected Windows versions), as required by CISA's KEV. If patching must be delayed, follow Microsoft's documented mitigation to disable the MSDT URL protocol (remove or restrict the HKEY_CLASSES_ROOT\ms-msdt registry key) and enforce Office Protected View / block Word from fetching remote templates over the network. Hunt for exploitation by checking whether Office processes (WINWORD.exe) launch msdt.exe or sdiagnhost.exe, or whether ms-msdt: URIs are invoked unexpectedly.

7.899% KEV ransomware PoC
  • Microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • Microsoft Windows 11 21H2
  • Microsoft Windows 7
  • +4 more
mass≈1 billion+ Windows devices (effectively the entire supported Windows installed base)

Indicators of compromiseAll →

TypeIndicatorContext
domainseller-notification.live22 – PH URL: http://45.76.53[.]253/1.html Payload: https://seller-notification[.]live/Zgfbe234dg Gathers info from browsers, registry, user acc
Full article447 words · extracted from helpnetsecurity.com · click to collapse

As the world is waiting for Microsoft to push out a patch for CVE-2022-30190, aka “Follina”, attackers around the world are exploiting the vulnerability in a variety of campaigns.

A complex vulnerability

Microsoft has described CVE-2022-30190 as a Microsoft Windows Support Diagnostic Tool (MSDT) remote code execution vulnerability, confirmed it affects an overwheming majority of Windows and Windows Server versions, and advised on a workaround to be implemented until a patch is ready.

Vulnerability analysts and security researchers have shared their own view of the complexity of the issue(s) behind that one CVE:

It's up to MS to define what they want CVE-2022-30190 to be. But I predict it'll be the PowerShell injection on the PCWDiagnostic component.
If you're only focusing on the protocol, that's sort of like picking a web browser CVE out of thin air for an attack starting with http://

— Will Dormann (@wdormann) June 1, 2022

My take on the three different Follina issues.

Fix all three in coming months, close attack surface. https://t.co/TlBT2vsYKm

— Kevin Beaumont (@GossiTheDog) June 2, 2022

The wider security community has been poking and creating proof-of-concept exploits for the flaw, as well as converting MSDT exploits so they can be used with other protocol handlers for a different kind of attack.

Attacks in the wild

After the attacks spotted in April and May, which revealed the existence of the flaw and its active exploitation to the wider security community, reports soon started trickling in about other campaigns leveraging it across the globe:

Malware signed by stolen certificates is using #Follina vulnerability to spread evil #AsyncRAT into the #Palau paradise. Seems targeted. Read more on #AvastDecoded https://t.co/hxHsYwEGU4

— Avast Threat Labs (@AvastThreatLabs) June 3, 2022

#Follina CVE-2022-30190https://t.co/uo7yZDWxSu
.RTF
Employment Agreement
Submitted: 2022-06-02 22 – PH
URL: http://45.76.53[.]253/1.html
Payload: https://seller-notification[.]live/Zgfbe234dg
Gathers info from browsers, registry, user accounts etc
Uploads ZIP to 45.77.156[.]179 pic.twitter.com/c9E0G1PLvM

— Kimberly (@StopMalvertisin) June 3, 2022

Ukraine 🇺🇦 : Ukrainian CERT announces that #cyberattacks targeted Ukrainian government organizations using:
– booby-trapped emails
– Cobalt Strike Beacon malware
– CVE-2021-40444 and CVE-2022-30190

The origin of the attack is not specified.

Via @_CERT_UAhttps://t.co/Ti0aBgzBGa

— Cyber, etc… (@cyber_etc) June 2, 2022

What can defenders do until patches are released?

We have already mentioned Microsoft’s advice, which involves disabling the MSDT URL protocol.

ACROS Security has released free micropatches for various editions of Windows and Windows Server, to be used via their 0patch agent.

SANS Senior Instructor Jake Williams recently answered plainly a number of questions regarding Follina, possible mitigations, and how to detect exploitation attempts.

Security companies have been adding signatures and rules for detecting malicious documents exploiting CVE-2022-30190, as well as providing general advice.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/06/03/patch-cve-2022-30190/