ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-1472
Unauthenticated Privilege Escalation (Zerologon) in Microsoft Netlogon Domain Controllers

CVE-2020-1472, widely known as "Zerologon," is an elevation-of-privilege flaw in how the Netlogon secure channel is established over the Netlogon Remote Protocol (MS-NRPC) on Microsoft domain controllers. An unauthenticated attacker with network reachability to a domain controller sends specially crafted Netlogon messages to establish a vulnerable secure channel and then runs a specially crafted application on the network to obtain domain administrator access. Successful exploitation yields domain administrator privileges, effectively full compromise of the Active Directory environment, and the flaw is known to be used in ransomware operations. Any organization running affected Windows Server versions (2008 through 20H2) as domain controllers is exposed, along with environments using Netlogon implementations from Samba and distributions or products from Fedora, openSUSE, Canonical (Ubuntu), Debian, Synology, and Oracle. Exploitation is highly active: a public Zerologon PoC/exploit is available, the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03, with known ransomware use), and EPSS estimates a 99.4% probability of exploitation within 30 days.

Do: Apply the vendor updates on all domain controllers and other affected systems immediately, following Microsoft's two-phase Netlogon secure channel guidance (the enforcement phase of the phased rollout began in Q1 2021). Audit Netlogon secure-channel connections and event logs for clients still using vulnerable connections before enabling full enforcement, and install updated packages for Samba and other Netlogon implementations from Fedora, openSUSE, Ubuntu, Debian, Synology, and Oracle. Given known ransomware use, prioritize patching any domain controller reachable from user networks, VPNs, or the internet.

5.599% KEV ransomware PoC
  • Microsoft Windows Server (when acting as a domain controller)
  • Samba (Netlogon secure channel implementation)
  • Fedora Project Fedora Linux
  • +5 more
massmillions of domain controllers worldwide (essentially every Active Directory domain), with hundreds of thousands of domain controllers/RPC endpoints…
CVE-2021-24074
Windows TCP/IP Remote Code Execution Vulnerability

Windows TCP/IP Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.8
group max
26%
  • microsoft windows 10
  • microsoft windows 7
  • microsoft windows 8.1
  • +1 more
CVE-2021-1732
Out-of-Bounds Write Local Privilege Escalation in Microsoft Win32k (CVE-2021-1732)

CVE-2021-1732 is a local elevation-of-privilege vulnerability (CWE-787, out-of-bounds write) in Microsoft's Win32k kernel driver, publicly characterized as an "offset confusion" in the Win32k ConsoleControl routine. It is triggered locally: a process with only low privileges can invoke the vulnerable Win32k functionality without any user interaction, causing a user-supplied offset/pointer to be mishandled in kernel mode and memory to be written out of bounds. An attacker who successfully exploits the flaw can execute code in the kernel and elevate to SYSTEM, gaining full control of the host — which makes it a valuable second-stage link in malware and ransomware chains. Any system running the affected Windows 10 releases (1803, 1809, 1909, 2004, 20H2) or Windows Server 2019/1909/2004/20H2 is exposed, though exploitation requires the attacker to already run code locally on the target. The flaw was fixed in Microsoft's February 2021 Patch Tuesday updates, was added to CISA's KEV catalog on 2021-11-03 with known ransomware use, and carries a very high EPSS score (78.4%, 100th percentile), indicating sustained exploitation pressure.

Do: Apply Microsoft's February 2021 (or later) Windows cumulative security updates to all affected Windows 10 and Windows Server systems, per vendor instructions — CISA's KEV listing requires federal agencies to patch. Prioritize hosts exposed to untrusted local users or already compromised by malware (e.g., ransomware or Raspberry Robin activity, which has used chained Windows LPEs), and hunt on unpatched hosts for signs of post-exploitation privilege escalation to SYSTEM.

7.878% KEV ransomware PoC ×2
  • Microsoft Windows 10 1803
  • Microsoft Windows 10 1809
  • Microsoft Windows 10 1909
  • +6 more
mass≈1 billion+ Windows devices (the listed builds spanned the mainstream Windows 10/Server install base)
CVE-2021-21017
Heap-Based Buffer Overflow in Adobe Acrobat and Reader Allows RCE via Malicious PDF

CVE-2021-21017 is a heap-based buffer overflow (out-of-bounds write, CWE-122/CWE-787) in Adobe Acrobat and Reader DC that corrupts memory when a specially crafted PDF is processed. Exploitation requires user interaction: a victim must open the malicious PDF file, after which an unauthenticated, network-based attacker can execute arbitrary code in the context of the current user. Successful exploitation effectively gives the attacker the privileges of the victim user on the endpoint, including the ability to run programs and read or modify data. Users running Acrobat Reader DC or Acrobat DC at or below versions 2020.013.20074, 2020.001.30018, or 2017.011.30188 on the Continuous, Classic 2020, and Classic 2017 tracks are affected. The bug was addressed in Adobe's February 2021 updates but has been exploited in the wild - it was added to the CISA KEV catalog on 2021-11-03 - and EPSS assigns an 86.3% probability of exploitation within 30 days (100th percentile).

Do: Upgrade all Acrobat and Reader installations to Adobe's February 2021 patched releases or later, per the vendor's instructions, as required by CISA KEV (added 2021-11-03). Inventory endpoints running Continuous, Classic 2020, or Classic 2017 builds at or below the listed versions and verify the running version after patching. Until patched, avoid opening PDFs from untrusted sources, since exploitation requires a victim to open a malicious file.

8.886% KEV
  • Adobe Acrobat Reader DC 2020.013.20074 and earlier (Continuous); 2020.001.30018 and earlier (Classic 2020); 2017.011.30188 and earlier (Classic 2017)
  • Adobe Acrobat DC 2020.013.20074 and earlier (Continuous); 2020.001.30018 and earlier (Classic 2020); 2017.011.30188 and earlier (Classic 2017)
  • Adobe Acrobat 2020.013.20074 and earlier; 2020.001.30018 and earlier; 2017.011.30188 and earlier
  • +1 more
masshundreds of millions of user installs worldwide (Reader is the dominant desktop PDF viewer)
CVE-2021-24078
Windows DNS Server Remote Code Execution Vulnerability

Windows DNS Server Remote Code Execution Vulnerability

NVD description · AI analysis pending
9.811%
  • microsoft windows server 2008
  • microsoft windows server 2012
  • microsoft windows server 2016
  • +1 more
CVE-2021-24100
Microsoft Edge for Android Information Disclosure Vulnerability

Microsoft Edge for Android Information Disclosure Vulnerability

NVD description · AI analysis pending
5.03%
  • microsoft edge
CVE-2021-24114
Microsoft Teams iOS Information Disclosure Vulnerability

Microsoft Teams iOS Information Disclosure Vulnerability

NVD description · AI analysis pending
5.73%
  • microsoft teams
CVE-2021-26701
.NET Core Remote Code Execution Vulnerability

.NET Core Remote Code Execution Vulnerability

NVD description · AI analysis pending
8.130%
  • microsoft .net
  • microsoft .net core
  • microsoft powershell core
  • +1 more
Full article733 words · extracted from thehackernews.com · click to collapse

Microsoft on Tuesday issued fixes for 56 flaws, including a critical vulnerability that's known to be actively exploited in the wild.

In all, 11 are listed as Critical, 43 are listed as Important, and two are listed as Moderate in severity — six of which are previously disclosed vulnerabilities.

The updates cover .NET Framework, Azure IoT, Microsoft Dynamics, Microsoft Edge for Android, Microsoft Exchange Server, Microsoft Office, Microsoft Windows Codecs Library, Skype for Business, Visual Studio, Windows Defender, and other core components such as Kernel, TCP/IP, Print Spooler, and Remote Procedure Call (RPC).

A Windows Win32k Privilege Escalation Vulnerability

The most critical of the flaws is a Windows Win32k privilege escalation vulnerability (CVE-2021-1732, CVSS score 7.8) that allows attackers with access to a target system to run malicious code with elevated permissions. Microsoft credited JinQuan, MaDongZe, TuXiaoYi, and LiHao of DBAPPSecurity for discovering and reporting the vulnerability.

In a separate technical write-up, the researchers said a zero-day exploit leveraging the flaw was detected in a "very limited number of attacks" against victims located in China by a threat actor named Bitter APT. The attacks were discovered in December 2020.

"This zero-day is a new vulnerability which caused by win32k callback, it could be used to escape the sandbox of Microsoft [Internet Explorer] browser or Adobe Reader on the latest Windows 10 version," DBAPPSecurity researchers said. "The vulnerability is high quality and the exploit is sophisticated."

It's worth noting that Adobe, as part of its February patch, addressed a critical buffer overflow flaw in Adobe Acrobat and Reader for Windows and macOS (CVE-2021-21017) that it said could lead to arbitrary code execution in the context of the current user.

The company also warned of active exploitation attempts against the bug in the wild in limited attacks targeting Adobe Reader users on Windows, mirroring aforementioned findings from DBAPPSecurity.

While neither Microsoft nor Adobe has provided additional details, the concurrent patching of the two flaws raises the possibility that the vulnerabilities are being chained to carry out the in-the-wild attacks.

Netlogon Enforcement Mode Goes Into Effect

Microsoft's Patch Tuesday update also resolves a number of remote code execution (RCE) flaws in Windows DNS Server (CVE-2021-24078), .NET Core, and Visual Studio (CVE-2021-26701), Microsoft Windows Codecs Library (CVE-2021-24081), and Fax Service (CVE-2021-1722 and CVE-2021-24077).

The RCE in Windows DNS server component is rated 9.8 for severity, making it a critical vulnerability that, if left unpatched, could permit an unauthorized adversary to execute arbitrary code and potentially redirect legitimate traffic to malicious servers.

Microsoft is also taking this month to push second round of fixes for the Zerologon flaw (CVE-2020-1472) that was originally resolved in August 2020, following which reports of active exploitation targeting unpatched systems emerged in September 2020.

Starting February 9, the domain controller "enforcement mode" will be enabled by default, thus blocking "vulnerable [Netlogon] connections from non-compliant devices."

In addition, the Patch Tuesday update rectifies two information disclosure bugs — one in Edge browser for Android (CVE-2021-24100) that could have revealed personally identifiable information and payment information of a user, and the other in Microsoft Teams for iOS (CVE-2021-24114) that could have exposed the Skype token value in the preview URL for images in the app.

RCE Flaws in Windows TCP/IP Stack

Lastly, the Windows maker released a set of fixes affecting its TCP/IP implementation — consisting of two RCE flaws (CVE-2021-24074 and CVE-2021-24094) and one denial of service vulnerability (CVE-2021-24086) — that it said could be exploited with a DoS attack.

"The DoS exploits for these CVEs would allow a remote attacker to cause a stop error," Microsoft said in an advisory. "Customers might receive a blue screen on any Windows system that is directly exposed to the internet with minimal network traffic. Thus, we recommend customers move quickly to apply Windows security updates this month."

The tech giant, however, noted that the complexity of the two TCP/IP RCE flaws would make it hard to develop functional exploits. But it expects attackers to create DoS exploits much more easily, turning the security weakness into an ideal candidate for exploitation in the wild.

To install the latest security updates, Windows users can head to Start > Settings > Update & Security > Windows Update or by selecting Check for Windows updates.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/02/microsoft-issues-patches-for-in-wild-0.html