New High-Severity Vulnerability Reported in Pulse Connect Secure VPN
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-22893 | Use-After-Free RCE in Ivanti Pulse Connect Secure License Services Ivanti Pulse Connect Secure, a widely deployed SSL VPN appliance, contains a use-after-free vulnerability in its license services. A remote, unauthenticated attacker can trigger the flaw via the license services and gain arbitrary code execution on the appliance, which is a high-value target because it terminates VPN sessions for enterprise networks. Any organization running an affected Pulse Connect Secure release is potentially affected; the source data does not specify exact version ranges, so administrators should compare their release against Ivanti's advisory. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and its 47.2% EPSS score (99th percentile) indicates a high likelihood of exploitation within 30 days. Do: Apply the updates per Ivanti's instructions immediately, as CISA's required action specifies. Because exploited appliances have often retained persistent webshells/backdoors even after patching, also hunt for indicators of compromise (modified appliance files, unexpected processes or accounts) and follow Ivanti's remediation guidance rather than only installing the update. Until patched, restrict or closely monitor internet access to the appliance. | 10.0 | 47% | KEV ransomware |
| largetens of thousands of internet-exposed Pulse Connect Secure VPN appliances (order of magnitude ~10^4-10^5) | |
| CVE-2021-22894 | Authenticated Buffer Overflow RCE in Ivanti Pulse Connect Secure Collaboration Suite CVE-2021-22894 is a buffer overflow in the Collaboration Suite (meeting room) functionality of Ivanti Pulse Connect Secure, classified under CWE-94 (improper control of code generation). A remote attacker who is already authenticated to the appliance can trigger the overflow by supplying a maliciously crafted meeting room, causing attacker-controlled code to run on the appliance. Successful exploitation yields code execution as the root user, giving the attacker full control of the VPN appliance at the operating-system level. Any organization running Pulse Connect Secure with the Collaboration Suite feature enabled is potentially affected; specific affected version ranges are not specified in the available data. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), confirming in-the-wild exploitation, with an elevated 41.3% EPSS probability of exploitation in the next 30 days and no public proof-of-concept known. Do: Apply Ivanti's supplied updates for Pulse Connect Secure per vendor instructions immediately, as the flaw is on CISA's KEV list with a required-action deadline. Restrict or disable the Collaboration/meeting feature if not needed, ensure it is not reachable without authentication, and review appliance and authentication logs for signs of exploitation (unexpected processes, files, or sessions running as root). | 8.8 group max | 41% | KEV |
| large≈tens of thousands of internet-exposed Pulse Connect Secure appliances (public 2021 scans showed roughly 20,000–50,000 Pulse Secure VPN endpoints) | |
| CVE-2021-22908 | A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execu A buffer overflow vulnerability exists in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user. As of version 9.1R3, this permission is not enabled by default. NVD description · AI analysis pending | 8.8 | 69% |
| — |
Full article478 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananMay 25, 2021
Ivanti, the company behind Pulse Secure VPN appliances, has published a security advisory for a high severity vulnerability that may allow an authenticated remote attacker to execute arbitrary code with elevated privileges.
"Buffer Overflow in Windows File Resource Profiles in 9.X allows a remote authenticated user with privileges to browse SMB shares to execute arbitrary code as the root user," the company said in an alert published on May 14. "As of version 9.1R3, this permission is not enabled by default."
The flaw, identified as CVE-2021-22908, has a CVSS score of 8.5 out of a maximum of 10 and impacts Pulse Connect Secure versions 9.0Rx and 9.1Rx. In a report detailing the vulnerability, the CERT Coordination Center said the issue stems from the gateway's ability to connect to Windows file shares through a number of CGI endpoints that could be leveraged to carry out the attack.
"When specifying a long server name for some SMB operations, the 'smbclt' application may crash due to either a stack buffer overflow or a heap buffer overflow, depending on how long of a server name is specified," CERT/CC detailed in a vulnerability note published on Monday, adding it was able to trigger the vulnerable code by targeting the CGI script '/dana/fb/smb/wnf.cgi.'
Pulse Secure customers are recommended to upgrade to PCS Server version 9.1R.11.5 when it becomes available. In the interim, Ivanti has published a workaround file ('Workaround-2105.xml') that can be imported to disable the Windows File Share Browser feature by adding the vulnerable URL endpoints to a blocklist and thus activate necessary mitigations to protect against this vulnerability.
It bears noting that users running PCS versions 9.1R11.3 or below would need to import a different file named 'Workaround-2104.xml,' necessitating that the PCS system is running 9.1R11.4 before applying the safeguards in 'Workaround-2105.xml.'
While Ivanti has recommended turning off Windows File Browser on the Admin UI by disabling the option 'Files, Window [sic]' for specific user roles, CERT/CC found the steps were inadequate to protect against the flaw during its testing.
"The vulnerable CGI endpoints are still reachable in ways that will trigger the 'smbclt' application to crash, regardless of whether the 'Files, Windows' user role is enabled or not," it noted.
"An attacker would need a valid DSID and 'xsauth' value from an authenticated user to successfully reach the vulnerable code on a PCS server that has an open Windows File Access policy."
The disclosure of a new flaw arrives weeks after the Utah-based IT software company patched multiple critical security vulnerabilities in Pulse Connect Secure products, including CVE-2021-22893, CVE-2021-22894, CVE-2021-22899, and CVE-2021-22900, the first of which was found to be actively exploited in the wild by at least two different threat actors.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/05/new-high-severity-vulnerability.html