Windows zero-day exploit used in targeted attacks by FruityArmor APT
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-0165 | Local Privilege Escalation in Microsoft Win32k Kernel Driver CVE-2016-0165 is a Win32k elevation-of-privilege flaw in the Windows kernel-mode driver, affecting Windows Vista SP2 through Windows 10 version 1511 and the corresponding Server editions. An attacker must already be able to run a crafted application locally on the affected machine, at which point the flaw can be triggered to escape the user context. Successful exploitation grants the attacker SYSTEM/kernel-level privileges, providing complete confidentiality, integrity, and availability impact on the host. Any organization running the listed Windows versions is exposed, especially servers and workstations used for shared access. The flaw has been exploited in the wild: it was used as a zero-day in targeted attacks attributed to the FruityArmor APT, it carries a 13.8% EPSS probability of exploitation within 30 days, and CISA added it to the KEV on 2023-06-22, requiring federal agencies to apply vendor updates. Do: Apply the vendor security updates for CVE-2016-0165 per Microsoft's instructions on all affected Windows Vista, Server 2008/2012, Windows 7, 8.1, RT 8.1, and Windows 10 1507/1511 systems, prioritizing KEV-driven remediation. Because this is a local privilege escalation, limit interactive and remote logon rights to untrusted users on hosts that cannot be patched immediately, and ensure endpoint monitoring watches for the FruityArmor-style targeted attack activity. Systems such as Vista, Windows 7, and Windows 10 1507/1511 that are past mainstream support should be upgraded to a supported OS release where possible. | 7.8 | 14% | KEV |
| masshundreds of millions of Windows PCs and servers (the affected OS versions spanned essentially the entire Windows install base at disclosure) | |
| CVE-2016-1010 | Integer Overflow RCE in Adobe Flash Player and AIR CVE-2016-1010 is an integer overflow (CWE-190) in Adobe Flash Player and Adobe AIR that allows attackers to execute arbitrary code via unspecified vectors, most plausibly by inducing a user to open attacker-supplied Flash content, consistent with the user-interaction requirement in its CVSS 3.1 score of 8.8. It affects Flash Player before 18.0.0.333 (Extended Support Release) and 19.x through 21.x before 21.0.0.182 on Windows and OS X, Flash Player before 11.2.202.577 on Linux, and Adobe AIR, AIR SDK, and AIR SDK & Compiler releases before 21.0.0.176, with Samsung X14J firmware also listed as an affected bundler of the Flash component. Successful exploitation yields arbitrary code execution in the context of the Flash runtime, typically sufficient to install malware or move laterally under the user's privileges. Anyone still running these now end-of-life runtimes, including embedded deployments such as the Samsung X14J firmware, is exposed. CISA added the flaw to the KEV catalog on 2022-05-25, and related reporting ties Windows zero-day Flash exploitation to targeted attacks by the FruityArmor APT, indicating in-the-wild exploitation; EPSS assigns a 19.4% probability of exploitation within 30 days (97th percentile), though no public PoC is known. Do: Upgrade Flash Player to 18.0.0.333 (ESR), 21.0.0.182 (Windows/OS X), or 11.2.202.577 (Linux), and Adobe AIR, AIR SDK, and AIR SDK & Compiler to 21.0.0.176. Since all impacted products are end-of-life, CISA's required action is to disconnect them if still in use; prioritize removing or disabling Flash/AIR entirely and verify that no embedded deployments (e.g., Samsung X14J firmware) still rely on Flash. Hunt for signs of targeted exploitation consistent with FruityArmor APT activity, such as unexpected Flash content and suspicious child processes spawned from browsers or Flash-enabled applications. | 8.8 | 19% | KEV |
| masson the order of hundreds of millions of desktop installations at the time of disclosure (Flash was near-universal on PCs); a far smaller, shrinking legacy base… | |
| CVE-2016-3393 | Remote Code Execution in Microsoft Windows GDI/GDI+ Graphics Component CVE-2016-3393 is a remote code execution vulnerability in the Windows Graphics Device Interface (GDI/GDI+), the component that renders text, images and graphics across Windows. An attacker triggers it by getting a user to visit a crafted website or otherwise view attacker-supplied content that is rendered through GDI (the CVSS vector confirms user interaction is required), and successful exploitation yields arbitrary code execution in the context of the current user. Affected software spans essentially the entire Windows estate of the era: Windows Vista SP2, Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607, and Windows Server 2008 SP2 and R2 SP1 and Server 2012 and 2012 R2. The flaw was patched in Microsoft's November 2016 Patch Tuesday, which fixed five zero-days being exploited in the wild, and reporting at the time attributed exploitation of this Windows graphics zero-day to the FruityArmor APT in targeted attacks. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-25), has a high EPSS score (68.7%, 99th percentile), and no public proof-of-concept is known. Do: Apply the November 2016 Microsoft security updates for the Windows Graphics Component to every affected Windows client and server version, per vendor instructions and CISA KEV's required action. For versions past end of support (Vista, 7, 8.1, RT 8.1, Server 2008/2012), move to a supported Windows release or apply Extended Security Updates. Until patched, discourage users from visiting untrusted websites or opening untrusted documents/images, and prioritize remediation on internet-facing servers and endpoints used by high-value users, given the documented targeted-attack use by the FruityArmor APT. | 7.8 | 69% | KEV |
| mass~hundreds of millions of Windows PCs and servers at the time of disclosure (affected versions spanned nearly the entire Windows installed base); today the… | |
| CVE-2016-4171 | Unspecified Remote Code Execution Flaw in Adobe Flash Player CVE-2016-4171 is an unspecified vulnerability in Adobe Flash Player that allows remote code execution; neither the CVE description nor CISA provides technical detail on the underlying flaw. As a Flash RCE, it is presumably triggered by getting a victim to load attacker-supplied Flash content (for example a malicious SWF in a web page or document), though the available data does not confirm the attack vector. Successful exploitation would let an attacker execute arbitrary code with the privileges of the user running Flash, typically yielding a foothold on the endpoint. All Adobe Flash Player deployments are affected per the data, and because Flash reached end-of-life at the end of 2020, anyone still running it is on an unpatched legacy product. The vulnerability is known exploited: CISA added it to the KEV catalog on 2022-03-25 (ransomware use unknown), EPSS assigns a 20.2% probability of exploitation within 30 days (97th percentile), and no public proof-of-concept is known. Do: Per CISA's required action, remove or disconnect Adobe Flash Player wherever it is still in use - the product is end-of-life and unpatched, so there is no fixed version to upgrade to. Audit endpoints and internal applications for Flash dependencies (standalone Flash, projector files, legacy intranet apps), migrate or retire them, and as a stopgap block SWF/Flash content at mail and web gateways. | 9.8 | 20% | KEV |
| massplausibly millions of residual Flash installs worldwide, though the number actively exposed today is unknown (Flash was historically on nearly every PC but is… |
Full article681 words · extracted from securelist.com · click to collapse
A few days ago, Microsoft published the “critical” MS16-120 security bulletin with fixes for vulnerabilities in Microsoft Windows, Microsoft Office, Skype for Business, Silverlight and Microsoft Lync.
One of the vulnerabilities – CVE-2016-3393 – was reported to Microsoft by Kaspersky Lab in September 2016.
Here’s a bit of background on how this zero-day was discovered. A few of months ago, we deployed a new set of technologies in our products to identify and block zero-day attacks. These technologies proved their effectiveness earlier this year, when we discovered two Adobe Flash zero-day exploits – CVE-2016-1010 and CVE-2016-4171. Two Windows EoP exploits have also been found with the help of this technology. One is CVE-2016-0165. The other is CVE-2016-3393.
Like most zero-day exploits found in the wild today, CVE-2016-3393 is used by an APT group we call FruityArmor. FruityArmor is perhaps a bit unusual due to the fact that it leverages an attack platform that is built entirely around PowerShell. The group’s primary malware implant is written in PowerShell and all commands from the operators are also sent in the form of PowerShell scripts.
In this report we describe the vulnerability that was used by this group to elevate privileges on a victim’s machine. Please keep in mind that we will not be publishing all the details about this vulnerability because of the risk that other threat actors may use them in their attacks.
Attack chain description
To achieve remote code execution on a victim’s machine, FruityArmor normally relies on a browser exploit. Since many modern browsers are built around sandboxes, a single exploit is generally not sufficient to allow full access to a targeted machine. Most of the recent attacks we’ve seen that rely on a browser exploit are combined with an EoP exploit, which allows for a reliable sandbox escape.
In the case of FruityArmor, the initial browser exploitation is always followed by an EoP exploit. This comes in the form of a module, which runs directly in memory. The main goal of this module is to unpack a specially crafted TTF font containing the CVE-2016-3393 exploit. After unpacking, the module directly loads the code exploit from memory with the help of AddFontMemResourceEx. After successfully leveraging CVE-2016-3393, a second stage payload is executed with higher privileges to execute PowerShell with a meterpreter-style script that connects to the C&C.
EOP zero-day details
The vulnerability is located in the cjComputeGLYPHSET_MSFT_GENERAL function from the Win32k.sys system module. This function parses the cmap table and fills internal structures. The CMAP structure looks like this:
The most interesting parts of this structure are two arrays – endCount and startCount. The exploit contains the next cmap table with segments:
To compute how much memory to allocate to internal structures, the function executes this code:
After computing this number, the function allocates memory for structures in the following way:
The problem is that if we compute the entire table, we will achieve an integer overflow and the cnt variable will contain an incorrect value.
In kernel, we see the following picture:
The code allocates memory only for 0x18 InternalStruct but then there is a loop for all the segments range (this value was extracted from the file directly):
Using the cmap table, the v44 variable (index) could be controlled and, as a result, we get memory corruption. To achieve it, the attacker can do the following:
- Make an integer overflow in win32k!cjComputeGLYPHSET_MSFT_GENERAL
- Make a specific segment ranges in font file to access interesting memory.
What about Windows 10? As most of you know, the font processing in Windows 10 is performed in a special user mode process with restricted privileges. This is a very good solution but the code has the same bug in the TTF processing.
As a result, if you load/open this font exploit in Windows 10, you will see the crash of fontdrvhost.exe:
Kaspersky Lab detects this exploit as:
- HEUR:Exploit.Win32.Generic
- PDM:Exploit.Win32.Generic
We would like to thank Microsoft for their swift response in closing this security hole.
* More information about the FruityArmor APT group is available to customers of Kaspersky Intelligence Services. Contact: [email protected]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/windows-zero-day-exploit-used-in-targeted-attacks-by-fruityarmor-apt/76396/