ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Windows and Qualcomm bugs to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-43047CVE-2024-43572CVE-2024-43573

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-43047
Use-After-Free in Qualcomm FastConnect and QCA Chipset Firmware

CVE-2024-43047 is a use-after-free vulnerability (CWE-416) in the firmware of several Qualcomm connectivity chipsets and the QAM8295P automotive SoC, where maintaining memory maps of high-level operating system (HLOS) memory causes memory corruption. The flaw is scored with a local attack vector and low privileges required (CVSS 3.1: 7.8), so an attacker needs some local foothold, such as a malicious app on an Android device, and can then leverage the memory corruption for high-impact confidentiality, integrity, and availability effects, in practice a privilege escalation to system or kernel level. Anyone running devices built on the affected chips is exposed, including Android smartphones with FastConnect 6700/6800/6900/7800, devices using QCA-series Wi-Fi chips, and automotive platforms using the QAM8295P. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-08, and news reports describe targeted, limited Android attacks, though ransomware use is unknown and EPSS remains modest at 0.7%.

Do: Apply Qualcomm's fix through your device or system OEM: install the latest Android security updates on affected phones, and update firmware/drivers for QCA-series Wi-Fi chips and the QAM8295P automotive SoC per vendor instructions; because this is a local firmware flaw, there is no user-side mitigation short of patching. Organizations under CISA KEV must remediate per the required action (apply vendor remediations or discontinue use). Prioritize an inventory of Android devices with FastConnect 6700/6800/6900/7800 and QCA6xxx/65xxx chips, noting this flaw is being used in targeted attacks rather than mass-scale campaigns.

7.8<1% KEV
  • qualcomm fastconnect 6700 firmware
  • qualcomm fastconnect 6800 firmware
  • qualcomm fastconnect 6900 firmware
  • +9 more
massplausibly hundreds of millions of devices (affected Qualcomm FastConnect and QCA connectivity chips ship across Android smartphones, PCs with Qualcomm Wi-Fi…
CVE-2024-43573
+1 in the same advisory: …43572
Spoofing Vulnerability in Microsoft Windows MSHTML Platform Exploited in the Wild

CVE-2024-43573 is a spoofing vulnerability in the Microsoft Windows MSHTML platform, classified as an input-neutralization flaw (CWE-79), that can lead to a loss of confidentiality. It is triggered when a user renders attacker-crafted content through the MSHTML engine, the browser-rendering component embedded in Windows that many system surfaces and applications use to display web-like content, causing content or interface elements to appear to come from a trusted source when they are attacker-controlled. An attacker who successfully exploits it can present spoofed content or prompts that deceive users, potentially leading them to reveal sensitive information such as credentials. All Microsoft Windows systems are affected according to CISA's listing, though no specific version breakdown is provided in the source data. The flaw is confirmed to be exploited in the wild (CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-08), EPSS assigns a 44.1% probability of exploitation in the next 30 days (99th percentile), no public PoC is known, and any ransomware association is listed as unknown.

Do: Apply Microsoft's October 2024 security updates (or later cumulative updates) to all Windows clients and servers as soon as possible, following vendor instructions; per CISA's required action, apply vendor mitigations or discontinue use of the affected platform if mitigations are unavailable. Until patched, exercise caution with unsolicited documents, links, and content rendered through Windows surfaces, and watch for spoofed prompts or user-interface elements. Federal agencies should complete remediation by the KEV due date for this entry.

8.1
group max
44% KEV
  • Microsoft Windows
mass≈1 billion+ Windows installations worldwide (MSHTML is present on essentially every Windows client and server)
Full article511 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows and Qualcomm bugs to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2024-43047 Qualcomm Multiple Chipsets Use-After-Free Vulnerability
  • CVE-2024-43572 Microsoft Windows Management Console Remote Code Execution Vulnerability
  • CVE-2024-43573 Microsoft Windows MSHTML Platform Spoofing Vulnerability

Qualcomm this week addressed 20 vulnerabilities in its products, including a potential zero-day issue tracked as CVE-2024-43047 (CVSS score 7.8). The vulnerability stems from a use-after-free bug that could lead to memory corruption.

The zero-day vulnerability resides in the Digital Signal Processor (DSP) service and impacts dozens of chipsets.

“Currently, the DSP updates header buffers with unused DMA handle fds. In the put_args section, if any DMA handle FDs are present in the header buffer, the corresponding map is freed. However, since the header buffer is exposed to users in unsigned PD, users can update invalid FDs. If this invalid FD matches with any FD that is already in use, it could lead to a use-after-free (UAF) vulnerability.” reads the DSP kernel commit. “As a solution,add DMA handle references for DMA FDs, and the map for the FD will be freed only when a reference is found.”

The flaw was reported by cybersecurity researchers Seth Jenkins from Google Project Zero and Conghui Wang from Amnesty International Security Lab. Jenkins Hopefully recommends addressing the issue on Android devices as soon as possible.

Google Threat Analysis Group claims that CVE-2024-43047 may be under limited, targeted exploitation, Wang also confirms in-the-wild activity. 

The researchers haven’t published details about the attacks exploiting the CVE-2024-43047, however, the reporting organizations are known for investigating cyberattacks linked to commercial spyware vendors.

Regarding the Microsoft flaws added by CISA to the KEV catalog, both issues were addressed by the IT giant in Patch Tuesday security updates for October 2024.

Microsoft confirmed that both issues are under active exploitation in the wild.

  • CVE-2024-43572 (CVSS score: 7.8) – Microsoft Management Console Remote Code Execution Vulnerability: The Microsoft Management Console vulnerability, could allow a remote attacker to gain code execution if a user loads a malicious MMC snap-in. Though attacks require social engineering and are likely limited, admins should promptly apply the update to mitigate potential damage.
  • CVE-2024-43573 (CVSS score: 6.5) – Windows MSHTML Platform Spoofing Vulnerability: Although rated Moderate, this actively exploited vulnerability resembles a previously patched flaw used by the APT group Void Banshee. The similarity suggests the original patch may have been inadequate, so prompt testing and deployment of this update are recommended.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by October 29, 2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/169557/security/u-s-cisa-adds-windows-and-qualcomm-bugs-known-exploited-vulnerabilities-catalog.html