ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

CISA Puts Chrome and Magento Zero-Days on Must

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-24086CVE-2022-0609

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-0609
Use-After-Free in Google Chromium Animation Component (Chrome, Edge, Opera)

CVE-2022-0609 is a use-after-free vulnerability (CWE-416) in the Animation component of Google's Chromium browser engine that can corrupt heap memory. A remote attacker triggers it by persuading a user to load a crafted HTML page (for example via a malicious or compromised website), with no authentication required beyond opening the page. Successful exploitation can lead to heap corruption and potentially arbitrary code execution in the context of the affected browser. Any browser or application built on Chromium is potentially affected, including Google Chrome, Microsoft Edge, and Opera. The flaw is actively exploited: CISA added it to the KEV catalog on 2022-02-15 with a required action to apply vendor updates, Google confirmed in-the-wild exploitation at disclosure, no public PoC is known, ransomware use is unknown, and EPSS assigns a 22.3% probability of exploitation within 30 days (98th percentile).

Do: Apply the vendor updates immediately: Google fixed this in Chrome 98.0.4758.102 (February 2022), so update Chrome, Microsoft Edge, Opera, and any other Chromium-based browsers or Chromium-embedded applications to releases containing that Chromium fix, and inventory browser versions across your fleet to catch machines lagging on the update. Until fully patched, treat unsolicited links to web pages as an exploitation vector given confirmed in-the-wild use, and comply with CISA's KEV required action to apply updates per vendor instructions.

8.823% KEV
  • Google Chromium (Animation component) Chromium prior to the 98.0.4758.102-era fix; exact version range not specified in the source data
  • Google Chrome Prior to 98.0.4758.102 (per Google's February 2022 stable-channel advisory)
  • Microsoft Edge (Chromium-based) Builds incorporating pre-patch Chromium; fixed via the corresponding February 2022 Chromium update
  • +1 more
mass≈3 billion+ browser users (Chrome alone has an installed base exceeding 3 billion; Chromium also underlies Edge, Opera, and other Chromium-based browsers)
CVE-2022-24086
Unauthenticated RCE via checkout input-validation flaw in Adobe Commerce/Magento

Adobe Commerce and Magento Open Source versions 2.4.3-p1 and earlier and 2.3.7-p2 and earlier contain an improper input validation flaw (CWE-20) in the checkout process. A remote attacker can trigger it with no privileges and no user interaction by submitting crafted input to a store's checkout flow, and successful exploitation results in arbitrary code execution on the server hosting the storefront. Any Adobe Commerce or Magento Open Source storefront running the affected versions is exposed, and because these are internet-facing e-commerce sites the practical exposure is broad. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-15), its EPSS exploitation probability is 99.2% (100th percentile), and news reports describe ongoing attacks against Magento 2 stores, including recurring 'Xurum' attack campaigns and template-based attacks.

Do: Upgrade every store to an Adobe-patched release per the vendor's instructions - i.e., any release newer than 2.4.3-p1 on the 2.4.x line or newer than 2.3.7-p2 on the 2.3.x line - noting that headlines indicate companion Magento CVEs were fixed in the same patch release, so consult Adobe's advisory for the full list. Because exploitation is unauthenticated and confirmed in the wild, prioritize internet-facing shops; WAF rules may reduce risk, but reports indicate WAF bypasses in related Magento attacks, so patching is the only reliable fix. After patching, review web server and application logs for exploitation attempts against the checkout flow and check affected hosts for indicators of compromise.

9.899% KEV
  • Adobe Commerce 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
  • Adobe Magento Open Source 2.4.3-p1 and earlier; 2.3.7-p2 and earlier
massroughly 100,000-300,000 online storefronts (Magento/Adobe Commerce is among the most widely deployed e-commerce platforms)
Full article329 words · extracted from infosecurity-magazine.com · click to collapse

The US authorities have added another nine exploited vulnerabilities for federal agencies to patch, including one zero-day bug being used to hijack e-commerce sites.

The US Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities Catalog yesterday.

The most urgent patches must be applied by March 1. They relate to two zero-day vulnerabilities: an improper input validation flaw in Adobe Commerce and Magento Open Source and a use-after free vulnerability in Google Chrome.

The Adobe bug (CVE-2022-24086) was patched by the firm on Sunday after being given a CVSS score of 9.8.

Exploitable without credentials, the critical vulnerability could allow a remote attacker to execute arbitrary code on an affected system, potentially enabling digital skimming attacks on e-commerce sites that run the CMS software.

Although it claimed to have seen only “very limited” attacks in the wild, the fact that Adobe took the unusual step of issuing an out-of-band patch last weekend highlights the potential impact of exploitation.

The Chrome vulnerability (CVE-2022-0609) is the browser’s first zero-day bug of the year and is rated high severity.

It could allow a remote attacker to create a specially crafted web page, trick a user into visiting it via a phishing attack and then execute arbitrary code on their machine. Google said the update will be incorporated into version 98.0.4758.102 and rolled out over the “coming days/weeks.”

The catalog was launched in November 2021 as part of Binding Operational Directive (BOD) 22-01, designed to make civilian federal government agencies more cyber-resilient.

However, it is also recommended as best practice for all organizations to prioritize their patching efforts according to the list, given that all the bugs therein have been actively exploited in the wild.

The remaining seven on this latest updated list must be fixed by August 15 2022, according to CISA. They include another use-after free flaw in Adobe Flash Player and bugs affecting four Microsoft products: Word, Internet Explorer, Windows and Microsoft Graphics Component.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-chrome-magento-zerodays/