ZeroHour
CyberScooppublished ()ingested @jeffstone500

Microsoft patches two zero-days exploited by FruityArmor, SandCat hacking groups

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0808
+1 in the same advisory: …0797
Local Privilege Escalation in Microsoft Win32k on Windows 7 and Server 2008

CVE-2019-0808 is an elevation-of-privilege flaw in the Windows Win32k kernel component, which fails to properly handle objects in memory, allowing a local, low-privileged attacker to execute code in the kernel and take full control of the system (CVSS 3.1: 7.8, high impact on confidentiality, integrity and availability). It is triggered by a local attacker running crafted actions against vulnerable Win32k system calls; a public proof of concept based on the NtUserMNDragOver call path is available. Per the source data, affected products are Windows 7 and Windows Server 2008 (exact service-pack/version ranges are not specified in the data). The bug was one of two Win32k zero-days patched in the March 2019 Patch Tuesday, was being actively exploited in targeted attacks attributed to the FruityArmor and SandCat groups, and Microsoft followed with an out-of-band fix after Google disclosed the zero-day. It is listed in CISA KEV (added 2021-11-03, ransomware use unknown), and EPSS currently assigns roughly a 53% probability of exploitation within 30 days (99th percentile).

Do: Apply the March 2019 Microsoft security updates (or the out-of-band fix) for Windows 7 and Windows Server 2008, including Extended Security Updates for systems past the January 2020 end of support, per the CISA KEV required action. Prioritize shared/terminal and RDS hosts where low-privileged users log in, since successful exploitation grants kernel-level privileges, and review those systems for indicators of the FruityArmor/SandCat targeted intrusions. No reliable workaround is documented for this Win32k flaw, so patching is the primary mitigation.

7.853% KEV PoC
  • Microsoft Windows 7
  • Microsoft Windows Server 2008
massroughly 500 million+ Windows 7 / Windows Server 2008 installations (Windows 7 held ~40% desktop OS share in early 2019)
Full article500 words · extracted from cyberscoop.com · click to collapse
Skip to main content

Get our latest cybersecurity news first on Google.

Click here!

Both bugs are known as elevation of privilege vulnerabilities, and could allow outsiders to manipulate Windows machines into authorizing an action that should not be allowed.

Microsoft, RSA 2019
(Scoop News Group)

Microsoft has released security updates for two vulnerabilities that researchers say have been exploited by suspected nation-state hacking groups dubbed FruityArmor and SandCat.

The March edition of Microsoft’s Patch Tuesday — when the company introduces fixes for reported security problems — includes 64 updates, 17 of which were rated as “critical.” Attackers already have leveraged at least two of the bugs, CVE-2019-0808 and CVE-2019-0797, according to researchers from Google and Russian security vendor Kaspersky Lab.

Both bugs are known as elevation of privilege vulnerabilities, and could allow outsiders to manipulate Windows machines into authorizing an action that should not be allowed.

“An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode,” Microsoft wrote in a security bulletin about the vulnerabilities. “An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.”

The warning is not just theoretical.

Kaspersky researchers Vasily Berdnikov and Boris Larin said in a blog post Wednesday they believe hacking groups including FruityArmor and SandCat are using the CVE-2019-0797 vulnerability.

FruityArmor, identified as a cyber-espionage group, previously has targeted victims located in Thailand, Iran, Algeria, Yemen, Saudi Arabia and Sweden, SC Magazine has reported. Researchers affiliated with governments and activist groups appeared to fit the victim profile. SandCat is a new threat group that researchers say is most active in the Middle East.

Google made CVE-2019-0808 public last week, revealing it had been used against Windows 7 users. Hackers combined that vulnerability with another issue in Chrome to take control of targeted computers. CVE-2019-0808 was patched in the latest version of Chrome.

Latest Podcasts

Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-zero-days-exploited-fruityarmor-sandcat/