ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Log4j Looms Large Over Patch Tuesday

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-43215
+4 in the same advisory: …43883 …41333 …43240 …43893
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution

iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution

NVD description · AI analysis pending
9.8
group max
3%
  • microsoft windows 10
  • microsoft windows 11
  • microsoft windows 7
  • +1 more
CVE-2021-43880
Windows Mobile Device Management Elevation of Privilege Vulnerability

Windows Mobile Device Management Elevation of Privilege Vulnerability

NVD description · AI analysis pending
5.5<1%
  • microsoft windows 11
CVE-2021-43890
Spoofing Vulnerability in Microsoft Windows AppX Installer Actively Exploited

CVE-2021-43890 is a spoofing vulnerability in the AppX Installer (App Installer) component of Microsoft Windows that allows a specially crafted package to masquerade as a trusted application. Triggering it requires user interaction: an attacker distributes a malicious installer package or ms-appinstaller link, typically via phishing, and must convince the user to open it, with impact limited to the privileges of the affected account. Successful exploitation delivers malware — Microsoft observed the Emotet, Trickbot and BazaLoader families in these attacks — and the flaw has also been used in ransomware campaigns, with users operating with administrative rights facing greater impact than low-privileged users. Essentially any Windows system relying on App Installer is affected; the exact affected build ranges are not enumerated in the advisory data, though contemporaneous headlines characterized it as an actively exploited Windows 10 zero-day addressed in the December 2021 Patch Tuesday. Exploitation is confirmed in the wild: CISA added it to KEV on 2021-12-15 with known ransomware use (EPSS 10.3% / 95th percentile), and in late 2023 Microsoft Threat Intelligence reported renewed abuse of the ms-appinstaller URI scheme and disabled that protocol by default in the updated App Installer.

Do: Apply Microsoft's security updates per the vendor advisory (December 2021 Windows updates) and install the updated App Installer using the Microsoft Store links in the advisory. Verify the updated App Installer is in place and that the ms-appinstaller protocol handler is disabled — it is disabled by default in the December 27, 2023 App Installer update. Because exploitation depends on users opening crafted packages, prioritize patching systems where users run with administrative rights and remind users to treat app-installer links and attachments arriving via email or chat with caution.

7.110% KEV ransomware PoC
  • microsoft App Installer (AppX Installer)
  • microsoft Windows
mass~1 billion+ Windows devices (App Installer ships as a built-in Windows component)
Full article411 words · extracted from infosecurity-magazine.com · click to collapse

IT teams knocked for six by a newly disclosed Log4j bug were forced to tackle a new patch load from Microsoft released yesterday, containing 67 new flaws including six zero-days.

The monthly Patch Tuesday release from the computing giant couldn’t have come at a worse time for sysadmins already struggling to find and patch the Apache logging utility instances across their environments.

“Efforts to identify, mitigate, or remediate the Apache Log4j vulnerability continue. In this case it is leaving a lot of teams frustrated, not knowing exactly what they need to do,” argued Ivanti VP of product management, Chris Goettl.

“Apache Log4j is a development library, so you cannot just patch a specific JAR file and call it a day. It falls to your development team or the vendors whose products you may be using.”

He singled out zero-day bug CVE-2021-43890, a spoofing vulnerability in Windows AppX Installer, as the most important for organizations to fix this month. The flaw has apparently been exploited in the wild alongside malware from the Emotet/Trickbot/BazarLoader family.

The five other zero-days have yet to be exploited, but as they’ve been made public, the clock will be ticking.

They can be found in the Encrypting File System (CVE-2021-43893), Windows Installer (CVE-2021-43883), Windows Mobile Device Management (CVE-2021-43880), Windows Print Spooler (CVE-2021-41333) and NTFS Set Short Name (CVE-2021-43240).

“The disclosures include a functional example in the case of the Print Spooler, proof-of-concept for the NTFS and Windows Installer vulnerabilities, so there is some cause to put urgency on the OS updates this month,” said Goettl.

Kev Breen, director of cyber threat research at Immersive Labs, called out CVE-2021-43215, an iSNS Server Memory Corruption vulnerability which can lead to remote code execution and has a CVSS score of 9.8.

However, the good news is that not all organizations run iSNS by default.

“It is a client-server protocol that allows clients to query an iSNS database. To exploit this vulnerability, an attacker only needs to be able to send a specially crafted request to the target server to gain code execution,” said Breen.

“As this protocol is used to facilitate data storage over the network, it would be a high priority target for attackers looking to damage an organization’s ability to recover from attacks like ransomware. These services are also typically trusted from a network perspective – which is another reason attackers would choose this kind of target.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/log4j-looms-large-over-patch/