ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Veritas Backup Exec flaws to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-1388
Local Privilege Escalation in Microsoft Windows Certificate Dialog (CVE-2019-1388)

CVE-2019-1388 is an elevation-of-privilege vulnerability in the Windows Certificate Dialog that fails to properly enforce user privileges (CWE-269). An attacker who can already run code or open crafted certificate content on a local machine can trigger the vulnerable dialog and cause privileged components to execute attacker-chosen actions without proper privilege checks. Successful exploitation yields high-impact control of confidentiality, integrity, and availability, effectively a full SYSTEM-level compromise of the host. Essentially every Windows client and server release in service at disclosure is affected, including Windows 7, 8.1 and RT 8.1, Windows 10 versions 1507 through 1903, and Windows Server 2008, 2012 and 1903. The flaw was fixed in Microsoft's November 2019 security updates, but CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-07 with known ransomware use, and EPSS currently estimates an 8.6% probability of exploitation within 30 days (95th percentile).

Do: Apply Microsoft security updates (November 2019 cumulative updates or later) to all in-scope Windows 7, 8.1, 10, RT 8.1 and Server 2008/2012/1903 systems, prioritizing hosts where unprivileged users can log on, per the KEV required action. For legacy releases past mainstream support, confirm Extended Security Update (ESU) coverage or plan migration, and verify installed patch levels via the OS build number. Because CISA notes known ransomware use, review incident timelines and endpooint logs for local-privilege-escalation activity preceding ransomware deployment.

7.89% KEV ransomware
  • microsoft windows 10 1507
  • microsoft windows 10 1607 affected builds as listed by Microsoft; fixed in November 2019 security updates
  • microsoft windows 10 1709 affected builds as listed by Microsoft; fixed in November 2019 security updates
  • +9 more
masshundreds of millions of Windows endpoints and servers (the affected release list covered nearly the entire Windows installed base at the time of disclosure)
CVE-2021-27877
+2 in the same advisory: …27878 …27876
Unauthenticated RCE in Veritas Backup Exec Agent via Legacy SHA Authentication

Veritas Backup Exec Agent — the remote agent component of Veritas Backup Exec — still accepts a legacy 'SHA' authentication scheme that current versions no longer use but had never disabled, an improper authentication flaw tracked as CVE-2021-27877. Because the obsolete scheme remains enabled, a remote, unauthenticated attacker can authenticate to the Agent's network service and issue privileged commands, effectively achieving remote code execution on the host (CVSS 3.1: 9.8, Critical). Any Backup Exec deployment running a version before 21.2 is affected wherever the Agent service is reachable — either exposed to the internet or reachable inside the network after an initial compromise. A public proof-of-concept remote code execution exploit is available, and the flaw carries a very high near-term exploitation likelihood (EPSS ~65%). The bug is actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-04-07 with known ransomware use, and the ALPHV/BlackCat ransomware affiliate has been reported targeting Veritas Backup Exec flaws.

Do: Upgrade Veritas Backup Exec to 21.2 or later per vendor instructions, as required by CISA's Known Exploited Vulnerabilities catalog. As an interim mitigation, restrict the Backup Exec Agent service (TCP/10000) to trusted backup servers and block it from untrusted networks, including the internet. Given confirmed ransomware use by ALPHV/BlackCat, prioritize patching internet-exposed and high-value backup servers.

9.8
group max
65% KEV ransomware PoC
  • Veritas Backup Exec (Agent component) all versions before 21.2 (fixed in 21.2)
  • Veritas Backup Exec Agent as shipped with Backup Exec before 21.2
large≈ tens of thousands of internet-exposed Backup Exec Agent hosts (order of 10⁴), within a plausibly 100,000+ deployment installed base (estimate)
CVE-2023-26083
Memory Leak Information Disclosure in Arm Mali GPU Kernel Drivers

A memory leak (CWE-401) in Arm's Mali GPU kernel drivers affects Midgard (all versions r6p0-r32p0), Bifrost (all versions r0p0-r42p0), Valhall (all versions r19p0-r42p0), and Avalon (r41p0-r42p0), allowing a non-privileged local user to perform valid GPU processing operations that expose sensitive kernel metadata. A local attacker or app on an affected device gains an information-disclosure primitive that reads otherwise protected kernel memory (CVSS 3.1 base score 3.3, confidentiality impact only), potentially aiding further attacks. Exposure applies to any device whose CPU incorporates an affected Mali GPU and runs the corresponding driver, most commonly Android smartphones and tablets built on licensed Mali designs. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-07), indicating active exploitation, and Arm has issued patched drivers, with fixes also delivered through vendor/Android update channels; ransomware use is unknown.

Do: Apply Arm's patched Mali kernel driver releases (versions beyond the affected ranges) via your SoC/OEM vendor, and on Android devices install the latest Google/OEM security updates, per CISA's required action. Inventory fleets for devices running affected Mali driver generations (Android phones, tablets, and embedded/edge devices) and confirm they receive the fixed driver; note that patching is mandatory for U.S. federal agencies under the KEV program despite the low severity of this local information-disclosure flaw.

3.31% KEV
  • Arm Midgard GPU Kernel Driver all versions r6p0 through r32p0
  • Arm Bifrost GPU Kernel Driver all versions r0p0 through r42p0
  • Arm Valhall GPU Kernel Driver all versions r19p0 through r42p0
  • +2 more
masshundreds of millions of devices (order of magnitude 10^8-10^9) with licensed Mali GPUs and affected driver versions
Full article332 words · extracted from securityaffairs.com · click to collapse

US CISA has added Veritas Backup Exec flaws, which were exploited in ransomware attacks, to its Known Exploited Vulnerabilities catalog.

U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added the following five new issues to its Known Exploited Vulnerabilities Catalog:

  • CVE-2021-27876 – Veritas Backup Exec Agent File Access Vulnerability
  • CVE-2021-27877 – Veritas Backup Exec Agent Improper Authentication Vulnerability
  • CVE-2021-27878 – Veritas Backup Exec Agent Command Execution Vulnerability
  • CVE-2019-1388 – Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
  • CVE-2023-26083 – Arm Mali GPU Kernel Driver Information Disclosure Vulnerability

This week Mandiant researchers reported that an affiliate of the ALPHV/BlackCat ransomware gang, tracked as UNC4466, was observed exploiting the three above vulnerabilities in the Veritas Backup solution to gain initial access to the target network.

Unlike other ALPHV affiliates, UNC4466 doesn’t rely on stolen credentials for initial access to victim environments. Mandiant researchers first observed this affiliate targeting Veritas issues in the wild on October 22, 2022. 

The CVE-2023-26083 flaw in the Arm Mali GPU driver is chained with other issues to install commercial spyware, as reported by Google’s Threat Analysis Group (TAG) in a recent report.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this flaw by April 28, 2023.

Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections:

  • The Teacher – Most Educational Blog
  • The Entertainer – Most Entertaining Blog
  • The Tech Whizz – Best Technical Blog
  • Best Social Media Account to Follow (@securityaffairs)

Please nominate Security Affairs as your favorite blog.

Nominate here: https://docs.google.com/forms/d/e/1FAIpQLSfaFMkrMlrLhOBsRPKdv56Y4HgC88Bcji4V7OCxCm_OmyPoLw/viewform

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/144561/security/veritas-backup-exec-known-exploited-vulnerabilities-catalog.html