ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity

Week in review: 17 free AWS cybersecurity courses, exploited Chrome zero-day

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-26369
Out-of-Bounds Write RCE in Adobe Acrobat and Reader via Malicious PDFs

Adobe Acrobat and Reader contain an out-of-bounds write (CWE-787) memory-corruption vulnerability in the listed versions. The flaw is triggered by user interaction: a victim must open a malicious file (e.g., a crafted PDF) for exploitation to occur. Successful exploitation gives the attacker arbitrary code execution in the context of the current user. Anyone running affected versions of Acrobat, Acrobat DC, Acrobat Reader, or Acrobat Reader DC is exposed, and because Reader is the dominant PDF viewer, that spans effectively all unpatched desktops that open PDFs. The bug was exploited as a zero-day before being patched, was added to CISA's KEV catalog on 2023-09-14 with CISA warning of active attacks, and EPSS assigns a roughly 7% probability of exploitation in the next 30 days (94th percentile).

Do: Upgrade all Acrobat and Reader installations to builds newer than 23.003.20284 and 20.005.30516/20.005.30514 per Adobe's security bulletin, as required by the CISA KEV listing (added 2023-09-14) which mandates applying vendor mitigations or discontinuing use. Until patched, caution users against opening PDFs from untrusted sources and consider blocking automatic PDF opening in browsers or email. Because the flaw was exploited as a zero-day, hunt for signs of compromise on endpoints that were running the affected versions.

7.87% KEV
  • Adobe Acrobat / Acrobat DC / Acrobat Reader / Acrobat Reader DC 23.003.20284 and earlier
  • Adobe Acrobat / Acrobat Reader 20.005.30516 and earlier
  • Adobe Acrobat / Acrobat Reader 20.005.30514 and earlier
masshundreds of millions of users (Acrobat/Reader is the world's dominant PDF viewer; effectively every unpatched desktop that opens PDFs)
CVE-2023-36761
Information Disclosure Flaw in Microsoft Word Actively Exploited (CVE-2023-36761)

CVE-2023-36761 is an information disclosure vulnerability in Microsoft Word caused by improper input validation (CWE-20). It is triggered when a user opens a specially crafted document, requiring user interaction but no authentication or special privileges, per the CVSS vector (AV:N/PR:N/UI:R). A successful attacker gains access to sensitive information from the affected system, with public reporting indicating the flaw can leak authentication material such as NTLM credentials. Anyone running affected versions of Word, including Word within Microsoft 365 Apps, Microsoft Office, and Office LTSC, is exposed, and the flaw was fixed in Microsoft's September 2023 Patch Tuesday updates. The vulnerability was exploited as a zero-day before patching: CISA added it to the Known Exploited Vulnerabilities catalog on September 12, 2023, and its EPSS score of 19.0% (97th percentile) signals elevated near-term exploitation risk.

Do: Apply Microsoft's September 2023 security updates for Microsoft 365 Apps, Office, Office LTSC, and Word immediately, per vendor instructions and CISA KEV requirements. Until patched, treat unsolicited documents as untrusted and consider restricting outbound SMB/NTLM traffic to limit credential leakage. Given confirmed in-the-wild exploitation and no known public PoC, prioritize this KEV remediation and verify patch deployment across endpoints.

6.520% KEV
  • Microsoft Word Supported versions per Microsoft's advisory; fixed in September 2023 security updates (no specific version ranges provided in source data)
  • Microsoft 365 Apps (Word component) Supported versions; fixed in September 2023 security updates
  • Microsoft Office Supported versions; fixed in September 2023 security updates
  • +1 more
masshundreds of millions of users/devices (Word ships with Microsoft 365 and Office across enterprise and consumer fleets)
CVE-2023-36802
Use-After-Free Privilege Escalation in Microsoft Streaming Service Proxy

CVE-2023-36802 is a use-after-free vulnerability (CWE-416) in the Microsoft Streaming Service Proxy, a component that ships with Windows, that allows an attacker to escalate privileges. It is triggered by a local attacker who can already execute code on a target machine and interacts with the streaming service proxy component in a way that mishandles freed memory. Successful exploitation typically yields elevated (SYSTEM/kernel-level) privileges, giving an attacker full control of the host and making it a common link in chained attack sequences alongside other exploits. Any Windows system carrying the affected component is potentially affected, which in practice means a very broad installed base of Windows client and server machines. The flaw is being actively exploited — CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-12 — though no public proof-of-concept is known and Microsoft's severity scoring was not yet available in the source data; EPSS estimates a high 27.5% chance of exploitation within 30 days (98th percentile).

Do: Apply Microsoft's security updates for this vulnerability via the vendor's mitigation instructions (Windows Update/patch channel), as required by the CISA KEV listing, prioritizing internet-reachable and multi-user Windows hosts. Since exploitation requires local access, limit who can run code on Windows systems and review endpoints for signs of local privilege escalation activity; confirm the patch landed by checking installed updates against Microsoft's advisory.

7.828% KEV
  • Microsoft Streaming Service Proxy
mass≈hundreds of millions of Windows devices (the Streaming Service Proxy component ships with Windows, so exposure broadly mirrors the Windows install base)
CVE-2023-4863
Out-of-Bounds Write in Google Chromium WebP Image Codec Actively Exploited

CVE-2023-4863 is a heap-based buffer overflow (CWE-787) in the WebP image codec used by Google Chromium, allowing a remote attacker to write outside the intended bounds of allocated memory. It is triggered when a user visits a crafted HTML page containing malicious WebP image data, so no authentication or special privileges are required, only that the victim loads attacker-controlled content in an affected application. Successful exploitation gives the attacker an out-of-bounds memory write in the affected process, which can lead to application crashes or memory corruption with the potential for code execution. Exposure is unusually broad because, per the advisory, the flaw can affect any application that uses the WebP codec, meaning the browsing public and any software bundling WebP decoding are plausibly in scope. The flaw was added to the CISA KEV catalog on 2023-09-13, indicating confirmed exploitation in the wild; EPSS assigns it a 100% probability of exploitation within 30 days, ransomware use is unknown, and no public proof-of-concept is known.

Do: Update Google Chrome and all other Chromium-based browsers to the latest stable release containing the WebP fix (the patched Chrome 116.0.5845.187 shipped in September 2023), and update or rebuild any other software that bundles the WebP/libwebp codec (fixed in libwebp 1.3.2). Until patching is complete, treat untrusted web content as the attack vector and, per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use of affected software if mitigations are unavailable. Verify remediation by checking installed browser and application versions against the vendor advisories.

8.8100% KEV PoC ×4
  • Google Chromium WebP
mass~3+ billion users (Chromium-based browsers account for roughly two-thirds of global browser usage)
Full article998 words · extracted from helpnetsecurity.com · click to collapse

Week in review

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

The blueprint for a highly effective EASM solution
In this Help Net Security interview, Adrien Petit, CEO at Uncovery, discusses the benefits that organizations can derive from implementing external attack surface management (EASM) solutions, the essential capabilities an EASM solution should possess, and how it deals with uncovering hidden systems.

How should SMBs navigate the phishing minefield?
In this Help Net Security interview, Pete Hoff, CISO at Wursta, offers advice to SMB security leaders and professionals on how to minimize the threat phishing presents to their organization’s operations and long-term success.

Requests via Facebook Messenger lead to hijacked business accounts
Hijackers of Facebook business accounts are relying on fake business inquiries and threats of page/account suspension to trick targets into downloading password-stealing malware.

Microsoft, Adobe fix zero-days exploited by attackers (CVE-2023-26369, CVE-2023-36761, CVE-2023-36802)
September 2023 Patch Tuesday is here, with fixes for actively exploited vulnerabilities in Adobe Acrobat and Reader (CVE-2023-26369), Microsoft Word (CVE-2023-36761), and Microsoft Streaming Service Proxy (CVE-2023-36802).

Microsoft Teams phishing: Enterprises targeted by ransomware access broker
A threat actor known for providing ransomware gangs with initial access to enterprise systems has been phishing employees via Microsoft Teams.

Attackers use fallback ransomware if LockBit gets blocked
Your security solutions might stave off a LockBit infection, but you might still end up with encrypted files: according to Symantec’s threat researchers, some affiliates are using the 3AM ransomware as a fallback option in case LockBit gets flagged and blocked.

Attackers hit software firm Retool to get to crypto companies and assets
Retool, the company behind the popular development platform for building internal business software, has suffered a breach that allowed attackers to access and take over accounts of 27 cloud customers, all in the crypto industry.

Microsoft Teams users targeted in phishing attack delivering DarkGate malware
A new phishing campaign taking advantage of an easily exploitable issue in Microsoft Teams to deliver malware has been flagged by researchers.

Chrome zero-day exploited in the wild, patch now! (CVE-2023-4863)
Google has rolled out a security update for a critical Chrome zero-day vulnerability (CVE-2023-4863) exploited in the wild.

MetaStealer malware is targeting enterprise macOS users
Enterprise macOS users are being targeted by attackers slinging new information-stealing malware dubbed MetaStealer.

Serial cybersecurity founders get back in the game
Last year’s data on the rise in the number of second timers getting back on the startup rollercoaster despite the looming recession shows that building a cybersecurity startup during times of economic turmoil can have distinct upsides.

Empowering consumer privacy with network security
In this Help Net Security video, Shawn Edwards, CSO at Zayo Group, discusses how businesses can ensure a secure network to protect themselves and their consumers.

Great security training is a real challenge
Everyone claims to take security seriously, but if CISOs and department leads are not regularly and frequently (this is the key part) refreshing, testing, or even deploying red team tactics against all employees, then they are not being totally honest with themselves.

Strategies for harmonizing DevSecOps and AI
In this Help Net Security video, Greg Ellis, General Manager of Application Security at Digital.ai, discusses how implementing AI-powered tools that continuously test and monitor code for threats makes it possible to fortify large enterprises against attackers and other security risks.

Modernizing fraud prevention with machine learning
The number of digital transactions has skyrocketed. As consumers continue to spend and interact online, they have growing expectations for security and identity verification.

The rise and evolution of supply chain attacks
In this Help Net Security video, Dick O’Brien, Principal Intelligence Analyst in the Symantec Threat Hunter team, discusses the transformation of supply chain attacks.

17 free AWS cybersecurity courses you can take right now
Here’s a collection of free AWS cybersecurity courses you can use to elevate your knowledge about the platform.

The critical role of authorization in safeguarding financial institutions
In this Help Net Security video, David Brossard, CTO at Axiomatics, discusses how, whether it’s protecting their own or their customers’ specific privacy/confidentiality while also adhering to global compliance regulations, there is a lot to think through regarding access control.

CISOs need to be forceful to gain leverage in the boardroom
Over 70% of CISOs feel that the importance of information security is not recognised by senior leadership, according to BSS.

Bruschetta-Board: Multi-protocol Swiss Army knife for hardware hackers
Bruschetta-Board is a device for all hardware hackers looking for a fairly-priced all-in-one debugger and programmer that supports UART, JTAG, I2C & SPI protocols and allows to interact with different targets’ voltages (i.e., 1.8, 2.5, 3.3 and 5 Volts!).

Email forwarding flaws enable attackers to impersonate high-profile domains
Sending an email with a forged address is easier than previously thought, due to flaws in the process that allows email forwarding, according to a research team led by computer scientists at the University of California San Diego.

Companies need to rethink how they implement identity security
More than 80% of organizations have experienced an identity-related breach that involved the use of compromised credentials, half of which happened in the past 12 months, according to Silverfort and Osterman Research.

CIS SecureSuite membership: Leverage best practices to improve cybersecurity
Whether you’re facing a security audit or interested in configuring systems securely, CIS SecureSuite Membership is here to help.

Securing OTA with Harman International’s Michal Geva
Michal Geva, General Manager, OTA and Cybersecurity at Harman International joined the Left to Our Own Devices podcast to discuss the automotive industry’s adoption of remote updates and the security risks that come with them.

Download: Ultimate guide to Certified in Cybersecurity
The ultimate guide covers everything you need to know about the entry-level Certified in Cybersecurity certification and how to get started with FREE training and exam through ISC2’s 1MCC program!

New infosec products of the week: September 15, 2023
Here’s a look at the most interesting products from the past week, featuring releases from Armis, Cisco, CTERA, Kingston Digital, Purism, and Swissbit.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/09/17/week-in-review-17-free-aws-cybersecurity-courses-exploited-chrome-zero-day/