ZeroHour
Security Affairspublished ()ingested @securityaffairs

Analysis of the evolution of exploit kits in the threat landscape

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-0189
Memory Corruption RCE in Microsoft IE Scripting Engines (JScript/VBScript)

CVE-2016-0189 is a memory corruption flaw (out-of-bounds write, per CWE-787) in Microsoft's JScript 5.8 and VBScript 5.7/5.8 scripting engines, as used in Internet Explorer 9 through 11 and other products that embed those engines. It is triggered remotely when a user is lured into viewing a crafted website that mishandles script, corrupting memory in the browser process. A successful attacker gains arbitrary code execution in the context of the current user (or can crash the browser, causing denial of service), with no authentication required but user interaction needed. Anyone running Internet Explorer 9-11 on Windows, or other products using the affected scripting engines, was exposed. Exploitation is well established: public write-ups document its use in drive-by exploit kit attacks and subsequent 'God Mode' local privilege-escalation variants, it is listed in CISA KEV (added 2022-03-28) with known ransomware use, and EPSS assigns a 94.1% probability of exploitation within 30 days.

Do: Apply the vendor-supplied Microsoft security updates for Internet Explorer and the JScript/VBScript scripting engines per CISA's required action, prioritizing endpoints used for web browsing and email since this is delivered via drive-by website attacks and is known to be used by ransomware operators. Systems that no longer receive updates for IE 9-11 should be migrated to a supported browser or OS. Check your environment against CISA KEV to confirm remediation status.

7.594% KEV ransomware PoC
  • microsoft Internet Explorer 9 through 11
  • microsoft JScript scripting engine 5.8 (as used in Internet Explorer 9-11 and other products)
  • microsoft VBScript scripting engine 5.7 and 5.8 (as used in Internet Explorer 9-11 and other products)
masshundreds of millions of Windows endpoints at disclosure (IE 9-11 shipped as the default Windows browser); residual exposure on legacy/enterprise Windows…
CVE-2018-4878
Use-After-Free RCE in Adobe Flash Player before 28.0.0.161

CVE-2018-4878 is a use-after-free (CWE-416) in Adobe Flash Player before 28.0.0.161, caused by a dangling pointer in the Primetime SDK's media-player handling of listener objects. An attacker triggers it by persuading a user to open attacker-controlled Flash content — typically a malicious SWF delivered via email, Office documents, or malvertising/exploit kits — because the CVSS vector (AV:L, UI:R) requires local user interaction. Successful exploitation yields arbitrary code execution with the privileges of the user running Flash. Anyone running a vulnerable Flash Player was exposed, including Red Hat Enterprise Linux Desktop/Server/Workstation users running Red Hat's packaged Flash plugin. The flaw was exploited as a zero-day in January–February 2018 (documented by McAfee and distributed alongside the Fallout exploit kit), and it remains in CISA's KEV with known ransomware use.

Do: Upgrade Adobe Flash Player to 28.0.0.161 or later, including Red Hat's flash-plugin package on RHEL Desktop/Server/Workstation. Because Flash is now end-of-life, CISA's required KEV action is to remove or disconnect Flash entirely where still in use — audit browsers, Office configurations, and legacy RHEL hosts for residual Flash installs, and block SWF content delivered via email and the web. Given confirmed in-the-wild exploitation, known ransomware use, and 89.5% EPSS, prioritize this in remediation tracking.

7.890% KEV ransomware PoC ×2
  • adobe Flash Player all versions before 28.0.0.161
  • redhat Enterprise Linux Desktop (flash-plugin) Flash Player component before 28.0.0.161
  • redhat Enterprise Linux Server (flash-plugin) Flash Player component before 28.0.0.161
  • +1 more
mass≈ hundreds of millions of desktop installs at time of disclosure; residual unmigrated installs now unknown (Flash is end-of-life)
CVE-2018-5002
Stack Buffer Overflow RCE in Adobe Flash Player

CVE-2018-5002 is a stack-based buffer overflow (out-of-bounds write) in Adobe Flash Player that can lead to remote code execution. It is triggered when the affected Flash Player processes malicious Flash content, typically delivered remotely through a browser or another application that renders SWF content. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Flash Player. Anyone still running affected versions of Adobe Flash Player is affected, though the product is now end-of-life, and CISA's required action is to disconnect or remove it if still in use. The flaw is being exploited in the wild per its inclusion in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-23), with a 25.4% EPSS probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Because Flash Player is end-of-life, the recommended action is to fully uninstall Adobe Flash Player from all systems, prioritizing internet-facing and server workstations, and block or disable Flash content in browsers. Where Flash cannot yet be removed, ensure the latest available Flash release with the 2018 vendor fix for this issue is installed and restrict rendering of untrusted SWF content. Hunt for signs of exploitation per the KEV entry, and treat any remaining Flash-enabled endpoint as a legacy-asset risk.

7.825% KEV
  • Adobe Flash Player All versions released prior to the vendor's 2018 security update addressing this flaw; the product is now end-of-life (no patched release line is maintained)
mass≈ tens of millions of legacy installations worldwide (Flash Player historically shipped on nearly every Windows PC and in major browsers)
CVE-2018-8174
Out-of-Bounds Write RCE in Microsoft Windows VBScript Engine

CVE-2018-8174 is an out-of-bounds write (CWE-787) in the Microsoft Windows VBScript engine, caused by the way it handles objects in memory. An attacker triggers it by convincing a user to visit a specially crafted website or open crafted content that invokes the VBScript engine (for example via Internet Explorer or a document preview), requiring user interaction. Successful exploitation yields remote code execution with the privileges of the logged-on user, enabling program installation, data theft and account takeover. All listed Windows client and server releases are affected: Windows 7, 8.1, RT 8.1, Windows 10 (1607-1803), and Windows Server 2008/2008 R2, 2012/2012 R2, 2016. Exploitation is in the wild: the flaw was fixed in the May 2018 Patch Tuesday, is listed in CISA KEV with known ransomware use, and public PoCs (0patch, ExploitDB 44741) and exploit kit usage have been documented; EPSS puts its 30-day exploitation probability at 88.5%.

Do: Apply Microsoft's May 2018 security updates (and any later cumulative or Extended Security Updates) to every listed Windows client and server release, as required by the CISA KEV listing, prioritizing internet-reachable and user-facing systems given known ransomware use. Upgrade out-of-support platforms (Windows 7/8.1/RT 8.1, Server 2008/2008 R2, 2012/2012 R2) to supported builds or ensure ESU coverage. As interim mitigation, block VBScript execution in Internet Explorer web zones using Microsoft's documented Group Policy/registry settings, and hunt for prior exploitation on legacy systems.

7.588% KEV ransomware PoC ×2
  • microsoft windows 10 1607, 1703, 1709, 1803 (pre-May 2018 security updates)
  • microsoft windows 7 all supported builds prior to the May 2018 security update
  • microsoft windows 8.1 all supported builds prior to the May 2018 security update
  • +4 more
masshundreds of millions of Windows PCs and servers (affected desktop releases dominated the ~1B+ device Windows install base at disclosure)
Full article800 words · extracted from securityaffairs.com · click to collapse

Cyber criminal organizations and state-sponsored hackers continue to use Exploit kits to compromise targets world worldwide

if the use of Exploit kits is decreased across the recent months, some of them were improved by adding the code to exploit recently discovered Flash and Internet Explorer zero-day vulnerabilities.

“Since both Flash and the VBScript engine are pieces of software that can be leveraged for web-based attacks, it was only natural to see their integration into exploit kits. While Internet Explorer is not getting any younger, CVE-2018-8174 brings an update to an otherwise 2-year-old vulnerability (CVE-2016-0189), which is still used in some drive-by campaigns.” reads the analysis published by Malwarebytes. “As far as Flash is concerned, CVE-2018-4878 has been adopted by almost all exploits kits.” 

One of the most exploited flaws is the CVE-2018-4878 Adobe’s Flash Player flaw that was discovered in January when North-Korea linked APT used it in attacks against South Korean targets.

Adobe addressed the CVE-2018-4878 in February after North Korea’s APT group was spotted exploiting it in targeted attacks.

The CVE-2018-4878 flaw was used by many other actors after Microsoft fixed it, in March security experts at Proofpoint discovered a Microsoft Office document exploit builder kit dubbed ThreadKit that has been used to spread a variety of malware, including banking Trojans and RATs (i.e. TrickbotChthonicFormBook and Loki Bot).

Attackers behing the ThreadKit leveraged the flaw in their weaponized documents.

Another vulnerability included in the exploited kits is the CVE-2018-8174, a critical remote execution vulnerability that affects VBScript implemented in Internet Explorer and Microsoft Office on all supported versions of Windows that was exploited in targeted attacks by an APT group.

The hackers delivered weaponized documents to allow the download of a second-stage payload. Hackers tricked victims into visiting a malicious HTML page that contained the code to trigger the UAF and a shellcode that downloads the malicious payload.

Microsoft has addressed in the May 2018 Patch Tuesday security updates, while in the same periodo, the Advanced Threat Response Team of 360 Core Security Division detected an APT attack exploiting a 0-day vulnerability and captured the world’s first malicious sample that uses it. The experts codenamed the vulnerability as “double kill” exploit.

After the release of the security updates, on May 8, experts from Kaspersky Lab and Malwarebytes published a detailed analysis of the vulnerability, while researchers from Morphisec security firm released a proof-of-concept (PoC) code.

Experts released a Metasploit module for the exploitation of the CVE-2018-8174 once the PoC code was available online.

The availability of the PoC code for the vulnerability is a gift for vxers, in the specific case, the crooks included the code for the CVE-2018-8174 flaw in the RIG exploit kit.

Early in June, experts observed threat actors including the code for the Internet Explorer zero-day vulnerability to the infamous RIG exploit kit that was used to spread several payloads, including Bunitu, Ursnif, and the SmokeLoader dropper.

The CVE-2018-8174 represents an evolution of another VBScript issue discovered 2 years ago tracked CVE-2016-0189 that continues to be exploited by crooks in attacks.

In June, Adobe fixed the CVE-2018-5002 Flash Zero-Day exploited in targeted attacks in the Middle East, but experts confirmed that it has not been yet integrated in Exploit Kits.

“At the time of this writing, a newer Flash vulnerability (CVE-2018-5002) is available but has not been spotted in any EK so far.” continues Malwarebytes.

The Magnitude EK was mainly observed in targeted attacks against targets in South Korea, recently threat actors included the code to exploit both CVE-2018-4878 and CVE-2018-8174 vulnerabilities. The toolkit is considered one of the most sophisticated EKs on the market, courtesy of its own Magnigate filtering, a Base64-encoded landing page, and fileless payload.

Another EK that was observed in attacks in the wild is the GreenFlash Sundown, it was used in attacks via compromised OpenX ad servers, and recently integrated the CVE-2018-4878 to deliver malware such as the Hermes ransomware and cryptocurrency miners.

Another exploit kit to monitor is the GrandSoft EK, which was used only in attacks aimed at Internet Explorer to deliver malware such as the AZORult stealer.

The EK is still relying on the older CVE-2016 -0189 Internet Explorer exploit.

“There is no doubt that the recent influx of zero-days has given exploit kits a much-needed boost. We did notice an increase in RIG EK campaigns, which probably resulted in higher than usual successful loads for its operators.” Malwarebytes concludes. “While attackers are concentrating on Microsoft Office–related exploits, we are observing a cascading effect into exploit kits,” 

Further details, including the IoCs for the above exploit kits are included in the analysis published by Malwarebytes.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – exploit kits, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/73505/hacking/exploit-kits-evolution.html