CISA Adds Twilio Authy and IE Flaws to Exploited Vulnerabilities List
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2012-4792 | Use-After-Free RCE in Microsoft Internet Explorer (CISA KEV) Microsoft Internet Explorer contains a use-after-free vulnerability (CWE-416) in which an attacker can trigger access to an object that was either never properly allocated or has already been deleted, demonstrated in the flaw record by a CDwnBindInfo object. A remote attacker exploits it by enticing a user to a crafted web site, and successful exploitation yields arbitrary code execution in the context of the logged-on user. Potentially affected parties are users of Microsoft Internet Explorer, which CISA notes is an end-of-life product. The bug was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-23, carries a 78.7% EPSS probability of exploitation within 30 days (top percentile), and related reporting ('Miniduke: Web Based Infection Vector', 'Group 72') underscores web-based infection vectors for this class of IE flaw; no public PoC is known and ransomware use is unknown. Do: Per CISA's required action, the impacted product is end-of-life: retire or disconnect any systems still relying on Internet Explorer and move users to a supported browser such as Microsoft Edge. Audit legacy Windows hosts, kiosks, and line-of-business web apps that still invoke IE, and where a supported platform allows it apply Microsoft's cumulative Internet Explorer security update addressing this CVE (MS13-002). On any remaining legacy systems, restrict web browsing to trusted sites until the software is retired. | — | 79% | KEV |
| masshundreds of millions of users historically (IE shipped as the default Windows browser); current still-vulnerable install base unknown | |
| CVE-2024-39891 | Unauthenticated Phone-Number Enumeration in Twilio Authy API (Android/iOS) An unauthenticated endpoint in the Twilio Authy API, reachable through Authy for Android before 25.1.0 and Authy for iOS before 26.1.0, disclosed whether arbitrary phone numbers were registered with the Authy service — an information-disclosure flaw tracked as CWE-203. An attacker could send a stream of phone-number queries to the endpoint over the network with no authentication, privileges, or user interaction, and the API responses revealed the registration status of each number. The attacker's gain was bulk enumeration of which phone numbers use Authy, which is valuable for targeting follow-on phishing, social engineering, or SIM-swap attacks; Authy accounts themselves were not compromised and no credentials or authentication data were exposed. Any user of the affected Android or iOS apps whose phone number could be queried was potentially affected, since the flaw lay in the API's access control rather than in the apps' token generation. The flaw was exploited in the wild in June 2024 and was added to CISA's Known Exploited Vulnerabilities catalog on 2024-07-23 (EPSS currently estimates a 1.7% probability of exploitation in the next 30 days); no public PoC is known. Do: Update the Authy Android app to version 25.1.0 or later and the Authy iOS app to version 26.1.0 or later per Twilio's guidance, which closes the unauthenticated endpoint's permissive responses. No account compromise was reported, but users and defenders should stay alert to targeted phishing or social engineering that could leverage knowledge of a phone number's Authy registration, and organizations tracking CISA KEV should apply vendor mitigations or discontinue use of the product if mitigations are unavailable. | 5.3 | 2% | KEV |
| mass≈ tens of millions of Authy app users (large consumer/enterprise 2FA install base) |
Full article270 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJul 24, 2024Vulnerability / Software Security
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.
The vulnerabilities are listed below -
- CVE-2012-4792 (CVSS score: 9.3) - Microsoft Internet Explorer Use-After-Free Vulnerability
- CVE-2024-39891 (CVSS score: 5.3) - Twilio Authy Information Disclosure Vulnerability
CVE-2012-4792 is a decade-old use-after-free vulnerability in Internet Explorer that could allow a remote attacker to execute arbitrary code via a specially crafted site.
It's currently not clear if the flaw has been subjected to renewed exploitation attempts, although it was abused as part of watering hole attacks targeting the Council on Foreign Relations (CFR) and Capstone Turbine Corporation websites back in December 2012.
On the other hand, CVE-2024-39891 refers to an information disclosure bug in an unauthenticated endpoint that could be exploited to "accept a request containing a phone number and respond with information about whether the phone number was registered with Authy."
Earlier this month, Twilio said it resolved the issue in versions 25.1.0 (Android) and 26.1.0 (iOS) after unidentified threat actors took advantage of the shortcoming to identify data associated with Authy accounts.
"These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise," CISA said in an advisory.
Federal Civilian Executive Branch (FCEB) agencies are required to remediate the identified vulnerabilities by August 13, 2024, to protect their networks against active threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/07/cisa-adds-twilio-authy-and-ie-flaws-to.html