CISA Warns of Active Exploitation of 'PwnKit' Linux Vulnerability in the Wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2018-4344 | Memory Corruption Flaw in Apple iOS, macOS, tvOS, and watchOS (Pre-2018 Releases) CVE-2018-4344 is a memory corruption vulnerability (CWE-119) in Apple's operating systems that was fixed with improved memory handling in the Fall 2018 releases. It carries a local attack vector with user interaction required (CVSS AV:L/UI:R), meaning exploitation requires the victim to process attacker-supplied content, and successful exploitation yields high confidentiality, integrity, and availability impact, consistent with potential arbitrary code execution. Every user running versions prior to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 is affected, spanning iPhone/iPad, Mac, Apple TV, and Apple Watch. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2022-06-27, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use is listed as unknown. EPSS currently estimates a 2.9% probability of exploitation within 30 days (86th percentile). Do: Upgrade affected devices to iOS 12, macOS Mojave 10.14, tvOS 12, or watchOS 5 or later per Apple's instructions, as required by the CISA KEV listing. Inventory your fleet for Apple devices running outdated OS versions; for hardware that cannot run iOS 12, treat the device as permanently unpatched and replace or isolate it. Because the flaw is confirmed exploited in the wild and appears in KEV, prioritize these updates in patch cycles, particularly on user workstations and BYOD endpoints. | 7.8 | 3% | KEV |
| masshundreds of millions of Apple devices ran iOS/macOS/tvOS/watchOS versions below the 2018 fixes at disclosure, with an unknown but likely substantial share… | |
| CVE-2019-8605 | Use-After-Free in Apple iOS, macOS, tvOS, watchOS Enables Privileged Code Execution CVE-2019-8605 is a use-after-free memory corruption flaw (CWE-416) affecting Apple's iOS, macOS (Mojave), tvOS, and watchOS, addressed with improved memory management in iOS 12.3, macOS Mojave 10.14.5, tvOS 12.3, and watchOS 5.2.1. It is triggered locally: a malicious application running on a device (the CVSS vector requires user interaction, meaning the victim must run the malicious app) exploits the stale-memory condition. A successful attack allows the application to execute arbitrary code with system privileges, i.e., a privilege escalation or sandbox escape beyond normal app permissions. Any iPhone, iPad, Mac, Apple TV, or Apple Watch running an OS version older than the fixed releases is affected. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), indicating known in-the-wild exploitation, with a high EPSS score of ~17.5% (97th percentile) and no known public proof-of-concept. Do: Update iPhones/iPads to iOS 12.3 or later, Macs to macOS Mojave 10.14.5 or later, Apple TVs to tvOS 12.3 or later, and Apple Watches to watchOS 5.2.1 or later. Use MDM or endpoint inventory to identify devices still running older OS versions, prioritizing KEV-driven patching requirements. Until patched, limit exposure by installing applications only from trusted sources, since exploitation requires running a malicious local application. | 7.8 | 18% | KEV |
| masshundreds of millions of Apple devices ran affected OS versions at disclosure; devices remaining on pre-fix versions today are likely in the millions (exact… | |
| CVE-2020-3837 | Memory Corruption in Apple iOS, macOS, tvOS, watchOS Enables Kernel-Level Code Execution Apple patched an out-of-bounds write (CWE-787), a memory corruption flaw in kernel memory handling, across iOS/iPadOS, macOS Catalina, tvOS and watchOS. The flaw is triggered by a local application performing the faulty memory access, and the CVSS vector indicates user interaction (running the application) is required. A successful attacker can execute arbitrary code with kernel privileges, meaning full compromise of the affected device. Anyone running iPhone/iPad, Mac, Apple TV or Apple Watch software older than iOS/iPadOS 13.3.1, macOS Catalina 10.15.3, tvOS 13.3.1 and watchOS 6.1.2 respectively is affected. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27), so exploitation has been observed in the wild, and EPSS assigns a 16.1% probability of exploitation within 30 days (97th percentile). Do: Update all Apple endpoints to the fixed releases: iOS and iPadOS 13.3.1 or later, macOS Catalina 10.15.3 or later, tvOS 13.3.1 or later, and watchOS 6.1.2 or later; apply per vendor instructions to satisfy the KEV required action. Inventory managed and BYOD Apple devices for OS versions below these builds and prioritize patching, since the flaw is KEV-listed and mobile spyware campaigns targeting iPhones are active (e.g., LightSpy, though no confirmed link to this CVE is in the data). Until devices are patched, limit installing applications from untrusted sources, as triggering requires running a local application. | 7.8 | 16% | KEV |
| masswell over 1 billion active Apple devices in the affected installed base (iPhone/iPad/Mac/Apple TV/Apple Watch) | |
| CVE-2020-9907 | Memory Corruption with Kernel Privileges in Apple iOS, iPadOS, and tvOS Apple patched a kernel memory corruption flaw (CWE-787, out-of-bounds write) in iOS 13.6, iPadOS 13.6, and tvOS 13.4.8 by removing the vulnerable code. The flaw is triggered locally: an application running on the device (local attack vector, user interaction required per the CVSS scoring) can corrupt kernel memory and execute arbitrary code with kernel privileges. A successful attacker gains the highest privilege level on the device, effectively escalating from an application to full kernel control. Anyone running an iPhone, iPad, or Apple TV on versions earlier than iOS/iPadOS 13.6 or tvOS 13.4.8 is affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-06-27, indicating exploitation in the wild, though no public proof-of-concept is known and EPSS estimates a roughly 3.9% chance of exploitation in the next 30 days. Do: Upgrade iPhones and iPads to iOS/iPadOS 13.6 or later and Apple TV devices to tvOS 13.4.8 or later, per CISA's required action to apply vendor updates. Because the KEV listing confirms in-the-wild exploitation, prioritize patching and check current builds via Settings > General > Software Update. On unpatched devices, limit exposure by only installing trusted applications, since triggering the flaw requires an application running locally on the device. | 7.8 | 4% | KEV |
| masshundreds of millions of Apple devices at the time of disclosure (subset of the iOS/iPadOS installed base on pre-13.6 builds, plus legacy Apple TV units) | |
| CVE-2021-30533 | PopupBlocker Policy Bypass in Google Chrome (CVE-2021-30553) Google Chrome prior to 91.0.4472.77 contains a security bypass (CWE-863, incorrect authorization) in its PopupBlocker component, caused by insufficient enforcement of navigation policies. A remote attacker can trigger the flaw by luring a user to a page containing a crafted iframe, which bypasses the browser's navigation restrictions without requiring privileges or complex conditions. The gain is an integrity impact per the CVSS vector (C:N/I:H/A:N): the attacker can navigate or load content contrary to the enforced popup/navigation policy, though confidentiality and availability are not directly affected. Users running vulnerable versions of Google Chrome and Fedora's Chromium builds predating the fix are affected. The issue is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-06-27, ransomware use unknown), indicating exploitation in the wild, and a public proof-of-concept reference exists in the Chromium bug tracker (crbug.com/1145553). Do: Update Google Chrome and any Chromium-based browsers to 91.0.4472.77 or later (verify via chrome://settings/help). On Fedora systems, apply the distribution's updated Chromium packages through dnf/update the OS per vendor instructions. CISA KEV listing requires federal agencies to complete this update by the assigned due date; defenders should confirm browser versions fleet-wide and watch for crafted-iframe navigation bypasses. | 6.5 | 17% | KEV PoC |
| mass≈3 billion Chrome users/devices worldwide (Chrome holds roughly 65% browser market share); only installs still running pre-91.0.4472.77 builds at disclosure… | |
| CVE-2021-30983 | Kernel Buffer Overflow in Apple iOS and iPadOS Enables Arbitrary Code Execution CVE-2021-30983 is a buffer overflow (CWE-120) in Apple iOS and iPadOS, caused by improper memory handling, that was corrected in iOS 15.2 and iPadOS 15.2. It is triggered locally by an application running on the device (CVSS local attack vector with user interaction), so a user must run a malicious or compromised app for the flaw to be reached. Successful exploitation allows that application to execute arbitrary code with kernel privileges, giving the attacker near-complete control of the affected iPhone or iPad. Anyone using an iPhone or iPad running a version earlier than iOS/iPadOS 15.2 is affected. The vulnerability is confirmed exploited in the wild, having been added to CISA's Known Exploited Vulnerabilities catalog on 2022-06-27, with EPSS estimating a 2.9% probability of exploitation within 30 days; no public proof-of-concept is known. Do: Upgrade all iPhones and iPads to iOS 15.2 or iPadOS 15.2 or later per Apple's instructions, as this is the required action in CISA's KEV catalog. Use MDM or device inventory to identify any devices still below 15.2 and prioritize them for patching; until updated, limit app installation from untrusted sources, since exploitation requires running an application on the device. | 7.8 | 3% | KEV |
| masshundreds of millions of iPhone/iPad devices (Apple's active installed base exceeds 1 billion; every device not yet updated to iOS/iPadOS 15.2 is affected) | |
| CVE-2021-4034 | Out-of-Bounds Read/Write Local Privilege Escalation in polkit pkexec (PwnKit) CVE-2021-4034 ('PwnKit') is an out-of-bounds read and write (CWE-125/CWE-787) in polkit's setuid-root pkexec utility, which mishandles the calling parameter count and ends up trying to execute environment variables as commands. A local attacker who runs pkexec with crafted environment variables can induce it to execute arbitrary code, gaining administrative (root) rights on the target machine. Because polkit is installed by default on mainstream Linux distributions — including Red Hat Enterprise Linux and its many variants, with the flaw also tracked against Canonical, SUSE, Oracle, Siemens, and StarWind Software products — essentially every standard Linux installation was exposed. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-06-27 with known ransomware use, and EPSS assigns a 94.9% probability of exploitation (100th percentile). Public proof-of-concept exploits are widely available, making exploitation trivial for any user with local access to an unpatched host. Do: Apply the polkit/pkexec updates from each distribution vendor immediately per vendor instructions, as required by the CISA KEV catalog. If patching must be delayed, removing the setuid bit from pkexec (e.g., chmod 0755 /usr/bin/pkexec) is a widely documented interim mitigation, though it may affect functionality that relies on pkexec. Prioritize hosts where untrusted or low-privilege users can log in, and hunt for prior exploitation given known ransomware use. | 7.8 | 95% | KEV ransomware PoC ×4 |
| masstens of millions of Linux servers and workstations (polkit/pkexec ships by default on virtually all mainstream distributions) | |
| CVE-2022-29499 | Unauthenticated RCE in Mitel MiVoice Connect Service Appliance CVE-2022-29499 is an improper input-validation flaw (CWE-20) in the Service Appliance component (SA 100, SA 400, and Virtual SA) of Mitel MiVoice Connect, affecting releases through 19.2 SP3. A remote, unauthenticated attacker can trigger it by sending improperly validated data to the appliance over the network; the CVSS vector (AV:N/AC:L/PR:N/UI:N) confirms no privileges, user interaction, or special conditions are required. Successful exploitation yields remote code execution with high impact on confidentiality, integrity, and availability, giving the attacker a foothold on the appliance inside the organization's voice/UC environment. Any organization running a MiVoice Connect deployment that includes one of the Service Appliances is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-27 with known ransomware use, and press reports describe the Lorenz ransomware group and others exploiting this Mitel VoIP zero-day for initial access into business networks (EPSS: 55.6% chance of exploitation in 30 days). Do: Apply Mitel's update for the Service Appliance component per the vendor's instructions, since all releases up through 19.2 SP3 are affected; do not delay, as ransomware groups are actively exploiting the flaw for initial access. Identify whether your MiVoice Connect deployment includes an SA 100, SA 400, or Virtual SA, restrict the appliance's web interface from direct internet exposure until patched, and after updating check the appliance for signs of compromise or follow-on ransomware activity. | 9.8 | 56% | KEV ransomware |
| largeestimated tens of thousands of business deployments with thousands of internet-exposed Service Appliances (clearly an estimate) |
Full article280 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananJun 29, 2022
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) this week moved to add a Linux vulnerability dubbed PwnKit to its Known Exploited Vulnerabilities Catalog, citing evidence of active exploitation.
The issue, tracked as CVE-2021-4034 (CVSS score: 7.8), came to light in January 2022 and concerns a case of local privilege escalation in polkit's pkexec utility, which allows an authorized user to execute commands as another user.
Polkit (formerly called PolicyKit) is a toolkit for controlling system-wide privileges in Unix-like operating systems, and provides a mechanism for non-privileged processes to communicate with privileged processes.
Successful exploitation of the flaw could induce pkexec to execute arbitrary code, granting an unprivileged attacker administrative rights on the target machine. It's not immediately clear how the vulnerability is being weaponized in the wild, nor is there any information on the identity of the threat actor that may be exploiting it.
Also included in the catalog is CVE-2021-30533, a security shortcoming in Chromium-based web browsers that was leveraged by a malvertising threat actor codenamed Yosec to deliver dangerous payloads last year.
Furthermore, the agency added the newly disclosed Mitel VoIP zero-day (CVE-2022-29499) as well as five Apple iOS vulnerabilities (CVE-2018-4344, CVE-2019-8605, CVE-2020-9907, CVE-2020-3837, and CVE-2021-30983) that were recently uncovered as having been abused by Italian spyware vendor RCS Lab.
To mitigate any potential risk of exposure to cyberattacks, it's recommended that organizations prioritize timely remediation of the issues. Federal Civilian Executive Branch Agencies, however, are required to mandatorily patch the flaws by July 18, 2022.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/06/cisa-warns-of-active-exploitation-of.html