ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Void Banshee APT exploited "lingering Windows relic" in zero-day attacks

criticalExploit / PoCimportance 60CVE-2024-38112

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability Exploited in the Wild (CVE-2024-38112)

CVE-2024-38112 is a spoofing flaw (CWE-451) in the Microsoft Windows MSHTML platform, the Windows component used to render web content, including by applications that embed the legacy Internet Explorer engine. It is triggered when a user interacts with attacker-controlled content rendered through MSHTML: the attack requires no privileges, travels over the network, and needs user interaction (UI:R per its CVSS vector), letting an attacker misrepresent critical UI information to the victim. Despite being classified as spoofing, the CVSS impact scores are high across confidentiality, integrity, and availability, and the CVSS base score is 7.5 (High). Any system running the affected Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server (2008, 2012, 2016, 2019) releases is affected. Exploitation is confirmed in the wild: Microsoft patched it as an actively exploited zero-day in July 2024, CISA added it to the Known Exploited Vulnerabilities catalog on 2024-07-09, and reporting indicates it had been exploited for over a year before the fix.

Do: Apply Microsoft's July 2024 security updates (Patch Tuesday) across all affected Windows 10, Windows 11, and Windows Server versions, prioritizing internet-facing and user workstations given confirmed in-the-wild exploitation and the 84.2% EPSS score. Until patched, remind users to avoid interacting with untrusted web or document content, since exploitation requires user interaction. Track the fix against CISA's KEV catalog deadlines and verify patch status on all endpoints.

7.584% KEV
  • Microsoft Windows 10 1507
  • Microsoft Windows 10 1607
  • Microsoft Windows 10 1809
  • +9 more
masshundreds of millions of Windows devices (essentially all desktops and servers on the listed Windows 10/11 and Windows Server releases)
Full article732 words · extracted from helpnetsecurity.com · click to collapse

The zero-day exploit used to leverage CVE-2024-38112, a recently patched Windows MSHTML vulnerability, was wielded by an APT group dubbed Void Banshee to deliver malware to targets in North America, Europe, and Southeast Asia, threat hunters with Trend Micro’s Zero Day Initiative have shared.

How Void Banshee used CVE-2024-38112

As previously explained by Check Point researcher Haifei Li, the attackers used files that were specially crafted to exploit the vulnerability but were made to look like PDFs.

“The threat actor leveraged CVE-2024-38112 to execute malicious code by abusing the MHTML protocol handler and x-usc directives through internet shortcut (URL) files. Using this technique, the threat actor was able to access and run files directly through the disabled Internet Explorer instance on Windows machines,” Trend Micro researchers noted.

“This MHTML code execution vulnerability was used to infect users and organizations with Atlantida malware.”

The attack chain (Source: Trend Micro)

The threat actors used spear-phishing tactics to direct targets to ZIP files containing copies of books in PDF format, along with malicious files disguised as PDFs. The ZIP files were hosted on online libraries, cloud sharing sites, Discord, and compromised websites.

“Some PDF lures we uncovered during our analysis of the Void Banshee campaign include textbooks and reference material such as Clinical Anatomy, which suggests the campaign is targeting highly skilled professionals and students who often use reference materials and places where digital copies of books are collected,” the threat hunters say.

Victims thought that they were opening PDF files, but were actually executing an internet shortcut file that exploited to flaw to trigger the remnants of Internet Explorer browser to lead to a compromised website that hosted a malicious HTML Application.

The HTA file contained a Visual Basic Script that used PowerShell to download an additional script and execute it, create a new process for it, download additional trojan loaders and, finally, deliver the Atlantida stealer.

“[The stealer] targets sensitive information from various applications, including Telegram, Steam, FileZilla, various cryptocurrency wallets, and web browsers. This malware focuses on extracting stored sensitive and potentially valuable data, such as passwords and cookies, and it can also collect files with specific extensions from the infected system’s desktop,” they noted.

“Moreover, the malware captures the victim’s screen and gathers comprehensive system information. The stolen data is then compressed into a ZIP file and transmitted to the attacker via TCP.”

According to Check Point, Void Banshee have been exploiting CVE-2024-38112 for over a year.

“The ability of APT groups like Void Banshee to exploit disabled services such as IE poses a significant threat to organizations worldwide,” Trend Micro threat hunters noted.

“Since services such as IE have a large attack surface and no longer receive patches, it represents a serious security concern to Windows users. Furthermore, the ability of threat actors to access unsupported and disabled system services to circumvent modern web sandboxes such as IE mode for Microsoft Edge highlights a significant industry concern.”

Microsoft failing at coordinated vulnerability disclosure

Both Check Point and Trend Micro researchers noticed the exploitation of CVE-2024-38112 in mid-May 2024 and disclosed their findings to Microsoft. Microsoft released fixes for the vulnerability on July 2024 Patch Tuesday that make it so that MHTML can no longer be used inside internet shortcut files (.url), and credited the former in the vulnerability’s security advisory.

But both companies were surprised when Microsoft released the fixes without a heads-up to them.

“This is not the first time [Microsoft] telling us they’re going to patch the issue in month X but released the patch earlier without notifying us,” Li said, and noted that “coordinated disclosure can’t be just one-side coordination.”

Dustin Childs, head of threat awareness at the ZDI, pointed out other instances of researchers complaining about Microsoft’s lack of communication, and pointed out that making the coordinated vulnerability disclosure (CVD) process frustrating for researchers could have negative consequences for Microsoft.

“If you don’t offer a bounty payout and don’t coordinate with researchers or properly credit them, why in the world would anyone report bugs to you?” he asked.

For coordinated vulnerability disclosure to work, both parties – vendors and researchers – have certain responsibilities, he pointed out, and “it’s time to have the vendors step up and do theirs.”

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/07/16/cve-2024-38112-void-banshee/