Ransomware gangs increasingly deploy zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-23397 | Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak) CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates. Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook. | 9.8 | 97% | KEV |
| masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite) | |
| CVE-2023-28252 | Heap Overflow in Microsoft Windows CLFS Driver Enables Local Privilege Escalation CVE-2023-28252 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Common Log File System (CLFS) driver that allows privilege escalation. The flaw is triggered when the kernel's CLFS driver processes malformed or maliciously crafted log file data, corrupting heap memory; an attacker who can already run code on a target system (e.g., a low-privileged user or an attacker chained with another flaw such as a remote code execution bug) can leverage it to gain SYSTEM-level privileges. Because the CLFS driver ships with supported Windows client and server releases, essentially the entire Windows installed base is potentially exposed. The vulnerability is being actively exploited: CISA added it to the KEV catalog on 2023-04-11 with known ransomware use, and EPSS estimates a 49.0% probability of exploitation within 30 days (99th percentile). It was addressed in Microsoft's April 2023 security updates, and the required remediation action is to apply the vendor updates. Do: Apply Microsoft's April 2023 (or later) cumulative security updates to all Windows clients and servers per vendor instructions, prioritizing high-value and domain infrastructure systems given the known ransomware use; there is no public PoC or known workaround, so patching is the primary mitigation. Note that this is a local elevation-of-privilege flaw, so also hunt for prior low-privilege access or exploitation chains on hosts, and confirm remediation by checking installed update levels across the estate. | 7.8 | 49% | KEV ransomware PoC |
| masshundreds of millions of Windows devices (the CLFS driver is present across essentially all modern Windows 10/11 and Windows Server installations) |
Full article745 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Microsoft issued a patch for a zero-day that researchers at Kaspersky said was used to deliver Nokoyawa ransomware.
In a move meant to maximize the damage and reach of its ransomware campaign, a cybercrime group recently deployed a Microsoft zero-day vulnerability to execute a global digital extortion campaign against small and medium-sized businesses, researchers at the cybersecurity firm Kaspersky said Tuesday.
The use of a previously unknown software vulnerability is notable because zero-days had been primarily deployed by skilled nation-state threat groups, according to Boris Larin, lead security researcher with Kaspersky’s Global Research and Analysis Team. Now, however, “cybercriminals have the resources to acquire zero-days and routinely use them in attacks. There are also exploit developers willing to help them and develop exploit after exploit.”
The increasing adoption of zero-days by ransomware gangs is yet another troubling development when it comes to defending against the scourge of these types of digital crimes, especially as groups already appear to have become more aggressive in their targets and demands from victims to comply with ransom demands.
The zero-day in question has been patched by Microsoft and assigned CVE-2023-28252 on Tuesday. The cybercrime group used it to try and deliver the Nokoyawa ransomware variant on the targets, according to Larin. The group associated with the attack is notable for its use of a large number of similar exploits against the Windows Common Log File System, Larin said in a writeup published Tuesday, deploying at least five different versions since June 2022 in attacks against retail, wholesale, energy, manufacturing, health care and software development targets.
“The criminals responsible for Nokoyawa activity have demonstrated a notable level of technical resourcefulness for some time,” said Tom Hegel, a senior threat researcher with the cybersecurity firm SentinelLabs. It’s not all that “surprising to see such a profitable enterprise employing zero-day exploits. Their continued success in obtaining ransom payments suggests that they will persist in developing and acquiring more advanced methods of initial access to their target organizations.”
The CVE patched Tuesday would allow attackers with authentication privileges to run code on the target system and launch an elevation-of-privilege exploit, Larin said. His writeup did not include additional details about the vulnerability or how to trigger it in order to “ensure that everyone has enough time to patch their systems before other actors develop exploits” for the bug, he wrote. The writeup will be updated in nine days, he added.
In addition to issuing a patch for the zero-day on Tuesday, Microsoft also fixed 97 other flaws as part of its monthly Patch Tuesday initiative, according to a breakdown from Bleeping Computer.
The notification of the zero-day marks the second consecutive month where an already-exploited vulnerability was patched by the company, Security Week’s Ryan Naraine noted. In March, the company detailed a Microsoft Outlook bug, tracked as CVE-2023-23397, that had been exploited for nearly a year by a “Russia-based threat actor … in targeted attacks against a limited number of organizations in government, transportation, energy, and military sectors in Europe,” the company said in a blog post.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Election official says Tina Peters would be consultant, won’t have access to election systems
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/microsoft-zero-day-patch-tuesday-ransomware/