New Microsoft Word zero-day used to spread 'lawful intercept' malware, analysts say
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2017-8759 | Remote Code Execution in Microsoft .NET Framework via Malicious Documents (CWE-94) CVE-2017-8759 is a code injection flaw (CWE-94) in Microsoft .NET Framework's handling of SOAP WSDL parsing, in which untrusted content referenced by a document or application is parsed and used during object instantiation, allowing attacker-controlled code to run. An attacker triggers it by delivering a specially crafted document — notably a Microsoft Word file referencing a malicious WSDL URL — and gets code execution when the document is opened and .NET downloads and parses the referenced content. Successful exploitation gives the attacker code execution with the privileges of the current user, sufficient to install malware, steal data, or facilitate further compromise. Any Windows system running .NET Framework versions 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2, or 4.7 is affected, which at disclosure covered the vast majority of Windows desktops and servers in use. The flaw was a zero-day exploited in the wild at disclosure (September 2017, used in targeted attacks including BlackOasis), is listed in CISA's Known Exploited Vulnerabilities catalog, and public proof-of-concept exploits are available. Do: Apply Microsoft's security updates addressing this vulnerability to all affected .NET Framework versions on Windows endpoints and servers, per the CISA KEV required action. Prioritize user-facing systems that open documents and are internet-exposed, and verify installed .NET Framework versions before and after remediation. As a compensating control, exercise caution with untrusted documents and block or inspect outbound fetches of WSDL references embedded in Office files. | 7.8 | 89% | KEV PoC ×2 |
| masshundreds of millions of Windows devices (affected .NET Framework versions were enabled by default across broadly deployed Windows client and server releases) |
Full article674 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
A well-funded spy group appears to have recently acquired a highly-sophisticated zero day vulnerability to deploy a remote access trojan, developed by infamous surveillance technology firm FinFisher, against a Russian-speaking "entity."
A well-funded spy group appears to have acquired a highly sophisticated zero-day vulnerability and used it to deploy a remote access trojan against a Russian-speaking “entity,” according to evidence discovered by U.S. cybersecurity firm FireEye.
Researchers with FireEye found the disruptive software vulnerability, which affects recent versions of Microsoft Word, in July. The trojan, known as FinSpy, is made by infamous surveillance technology firm FinFisher, a blog post by FireEye states.
The Microsoft Word flaw remained unpatched until Tuesday afternoon, when Microsoft issued its monthly security update. This vulnerability, labeled CVE-2017-8759, was used as recently as late August to hack into systems, FireEye analyst Ben Read told CyberScoop.
Analysts originally uncovered CVE-2017-8759 while examining a highly targeted phishing email that was written in Russian. The email contained an attachment that when opened exploited a software flaw in the word processor to remotely download FinSpy from a computer server controlled by the attacker. In this case, the valuable vulnerability was being leveraged to infect computers with a piece of FinFisher software that would remain hidden while collecting information, including activity logs, emails, login credentials and other communications.
“We assess with moderate confidence that this malicious document was used by a nation-state to target a Russian-speaking entity for cyber espionage purposes,” the FireEye blog post says.
The simultaneously use of FinFisher’s remote access trojan with the previously undisclosed Microsoft Word vulnerability suggests that the controversial German technology firm, otherwise known as Gamma Group or Lench IT Solutions, may be behind both products, according to Read.
“This shows that business is going well for FinFisher, as it’s clear that people are buying these expensive zero-days and obviously using them,” Read told CyberScoop.
The is no evidence to suggest that this variant of FinSpy reviewed by FireEye had been sold or shared by any other party aside from FinFisher prior to the discovery of CVE-2017-8759. Read said he could assess “with high confidence” that the remote access trojan his team discovered was developed by FinFisher.
The use of FinSpy in tandem with new zero-days, like the CVE-2017-8759 vulnerability, represents FinFisher ability to continuously discover significant software vulnerabilities for its clients. In the past, those clients have included governments, law enforcement and intelligence agencies.
The findings published Tuesday represent the second time in recent months that FireEye has discovered a hacker using a rare zero-day vulnerability to deploy FinFisher malware. In the first incident, the attack also used a phishing email written in Russian. The April activity was believed to be financially motivated. It’s unclear whether these two cases are in any way related or if they were independently launched for differing reasons, Read said.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/new-microsoft-word-zero-day-used-russian-language-spyware-campaign-analysts-say/