ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 495 by Pierluigi Paganini

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-37383
Cross-Site Scripting in Roundcube Webmail via SVG animate attributes

CVE-2024-37383 is a cross-site scripting vulnerability (CWE-79) in Roundcube Webmail caused by insufficient handling of SVG 'animate' attributes when HTML email content is rendered. An attacker triggers it by sending a crafted HTML email containing a malicious SVG animate element; when the recipient views the message in Roundcube, attacker-controlled JavaScript executes in the context of the victim's webmail session. Successful exploitation allows theft of session cookies and credentials, access to mailbox contents, sending mail as the victim, or redirection to phishing pages, and has been used in campaigns that steal credentials and email. All Roundcube Webmail deployments before 1.5.7 and 1.6.x before 1.6.7 are affected, including Roundcube packages shipped with Debian; because the attack requires only viewing a malicious email, any exposed webmail user is a potential victim. The flaw is under active exploitation: unknown threat actors have used it in phishing campaigns, it carries an EPSS of 73.3%, and CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-24.

Do: Upgrade Roundcube to version 1.5.7 or 1.6.7 (or later) immediately; Debian users should install the updated roundcube package from their repository. Organizations subject to CISA BOD 22-01 must apply vendor mitigations or discontinue use per the KEV entry. Review webmail logs for phishing emails containing SVG animate elements and investigate for credential theft or anomalous mailbox activity.

6.173% KEV
  • Roundcube Webmail before 1.5.7 and 1.6.x before 1.6.7 (i.e., 1.6.0 through 1.6.6 and earlier releases)
  • Debian Linux (Roundcube webmail package)
masslikely millions of webmail users across hundreds of thousands of deployed instances, with tens of thousands of instances internet-exposed
CVE-2024-44068
An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920.

An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation.

NVD description · AI analysis pending
8.11%
  • samsung exynos 9820 firmware
  • samsung exynos 9825 firmware
  • samsung exynos 980 firmware
  • +1 more
CVE-2024-47575
Unauthenticated RCE in Fortinet FortiManager and FortiManager Cloud

CVE-2024-47575 is a missing-authentication flaw (CWE-306) in Fortinet FortiManager and FortiManager Cloud, rated critical at CVSS 9.8. An unauthenticated remote attacker can send specially crafted requests to the affected management interface and execute arbitrary code or commands, with no credentials, privileges, or user interaction required. Every supported FortiManager branch from 6.2 through 7.6 and four FortiManager Cloud branches are affected, meaning any organization using these products as the central management plane for FortiGate firewalls is exposed, and compromise of the appliance can provide a foothold across the entire managed firewall estate. The flaw was exploited as a zero-day in an active campaign before patches were available, was added to CISA KEV on 2024-10-23 (ransomware use not yet confirmed), and carries a 95.1% EPSS probability of exploitation within 30 days.

Do: Upgrade FortiManager and FortiManager Cloud to the fixed releases listed in Fortinet advisory FG-IR-24-423 (FortiManager 7.6.1+, 7.4.5+, 7.2.8+, 7.0.13+, 6.4.15+, or 6.2.13+; Cloud 7.4.5+, 7.2.8+, 7.0.13+, or 6.4.8+), or apply the interim mitigations of restricting which IP addresses may connect to the fgfm service, disabling fgfm where it is not required, and applying the vendor's IPS signature. Hunt logs for signs of exploitation, such as unexpected fgfm requests, unknown IPs, or unexplained device registrations on the FortiManager. As a CISA KEV entry, federal agencies and other CISA-directed organizations must apply the mitigations or discontinue use of the product by the required deadline.

9.895% KEV PoC
  • Fortinet FortiManager 7.6.0
  • Fortinet FortiManager 7.4.0 through 7.4.4
  • Fortinet FortiManager 7.2.0 through 7.2.7
  • +7 more
moderate≈5,000 internet-exposed FortiManager/Cloud instances (order of thousands); total on-prem deployments likely higher
Full article516 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly SecurityAffairs newsletter arrived! Every week the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime  

Cisco Confirms Security Incident After Hacker Offers to Sell Data

Using gRPC and HTTP/2 for Cryptominer Deployment: An Unconventional Approach

Threat actor abuses Gophish to deliver new PowerRAT and DCRAT

Researchers link Polyfill supply chain attack to huge network of copycat gambling sites

Fake LockBit, Real Damage: Ransomware Samples Abuse AWS S3 to Steal Data 

Illicit Uses for Deepfake Technology

Largest Retail Breach in History: 350 Million “Hot Topic” Customers’ Personal & Payment Data Exposed — As a Result of Infostealer Infection          

Landmark, an administrator for insurance firms, says 800,000 affected by data breach

Voice-enabled AI agents can automate everything, even your phone scams

UnitedHealth says Change Healthcare hack affects over 100 million, the largest-ever US healthcare data breach  

Four REvil Ransomware Members Sentenced in Rare Russian Cybercrime Convictions

Malware

New Bumblebee Loader Infection Chain Signals Possible Resurgence   

Threat Actors Push ClickFix Fake Browser Updates Using Stolen Credentials  

ReliaQuest Uncovers New Black Basta Social Engineering Technique  

Unmasking Lumma Stealer: Analyzing Deceptive Tactics with Fake CAPTCHA  

TeamTNT’s Docker Gatling Gun Campaign

From cyber attacks to sabotage: How Israel’s covert operations are targeting Iran’s vital assets  

Hacking

Fake attachment. Roundcube mail server attacks exploit CVE-2024-37383 vulnerability   

“Hey ESET, Wait for the Leak”: Dissecting the “OctoberSeventh” Wiper targeting ESET customers in Israel

Internet Archive breached again through stolen access tokens   

End-to-End Encrypted Cloud Storage in the Wild A Broken Ecosystem  

CVE-2024-44068: Samsung m2m1shot_scaler0 device driver page use-after-free in Android  

Fortinet warns of new critical FortiManager flaw used in zero-day attacks

Investigating FortiManager Zero-Day Exploitation (CVE-2024-47575)  

Cisco Patches Vulnerability Exploited in Large-Scale Brute-Force Campaign 

Pwn2Own Ireland 2024: Day Three Results

An Update on Windows Downdate   

Threat Actors Are Exploiting Vulnerabilities Faster Than Ever  

Intelligence and Information Warfare 

“Hey ESET, Wait for the Leak”: Dissecting the “OctoberSeventh” Wiper targeting ESET customers in Israel  

The Crypto Game of Lazarus APT: Investors vs. Zero-days

Iranian hacker group aims at US election websites and media before vote, Microsoft says      

Burning Zero Days: FortiJump FortiManager vulnerability used by nation state in espionage via MSPs  

Amazon identified internet domains abused by APT29     

RDP configuration files as a means of obtaining remote access to a computer or “Rogue RDP” (CERT-UA#11690)

Joint Statement by FBI and CISA on PRC Activity Targeting Telecommunications

Chinese hackers targeted Trump and Vance’s phone data       

Cybersecurity

SEC Charges Four Companies With Misleading Cyber Disclosures   

Digital Echo Chambers and Erosion of Trust – Key Threats to the US Elections  

Apple will pay security researchers up to $1 million to hack its private AI cloud

The Global Surveillance Free-for-All in Mobile Ad Data  

Apple: Security research on Private Cloud Compute

How the ransomware attack at Change Healthcare went down: A timeline  

Irish Data Protection Commission fines LinkedIn Ireland €310 million  

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/170301/security/security-affairs-newsletter-round-495-by-pierluigi-paganini-international-edition.html