ZeroHour
The Recordpublished ()ingested

Russian missile fuel maker targeted with recent Office zero

criticalRansomwareimportance 60CVE-2021-40444

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-40444
Remote Code Execution via MSHTML Rendering Engine in Microsoft Windows/Office (CVE-2021-40444)

CVE-2021-40444 is a remote code execution vulnerability in the Microsoft MSHTML browser rendering engine, which Microsoft Office documents can load on Windows systems. It is triggered when a user is convinced to open a specially crafted Office document containing a malicious ActiveX control hosted by the MSHTML engine (tracked as a path-traversal-class issue, CWE-22). A successful attacker gains the ability to run arbitrary code in the context of the logged-on user, with greater impact when that user has administrative rights. Any Windows system that can open Office documents is exposed, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H1) and Windows Server 2004/2008. Exploitation is confirmed in the wild: Microsoft observed targeted attacks at disclosure, the flaw is in CISA's KEV with known ransomware use, and Microsoft released security updates on September 14, 2021.

Do: Apply Microsoft's security updates released September 14, 2021 for your Windows version immediately; this is a CISA KEV item with known ransomware use, so patching is treated as mandatory. As interim protection, keep Microsoft Defender Antivirus/Defender for Endpoint signatures current (enterprise detection build 1.349.22.0 or newer, with alerts appearing as 'Suspicious Cpl File Execution') and avoid opening untrusted Office documents, since exploitation requires user interaction with a crafted file.

8.897% KEV ransomware PoC ×2
  • microsoft MSHTML as shipped in the affected Windows releases
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all versions covered by Microsoft's September 2021 security updates
  • +4 more
masshundreds of millions of Windows PCs and servers (nearly all Windows desktop/laptop installs on affected versions at disclosure)
Full article477 words · extracted from therecord.media · click to collapse

Russian organizations, including a major defense contractor, have been targeted in a suspected cyber-espionage operation that is abusing a recently disclosed Office zero-day.

Security firm Malwarebytes, which first spotted some of the attacks, identified one of the targets as JSC GREC Makeyev, a known developer of liquid and solid fuel for Russia's ballistic missiles and space rocket program.

This looks like an #APT attack that is targeting "JSC Makeyev Design Bureau". (A Russian missile design company)
The #maldoc exploits CVE-2021-40444 to drop a tiny DLL downloader.
The final payload is packed using Themida and uses several anti-analysis techniques.
(Thread 1/3) pic.twitter.com/E1mF5hyENV

— Jazi (@h2jazi) September 16, 2021

The attacks were a classic spear-phishing campaign that sent boobytrapped Office documents to the organization's employees.

The documents, claiming to be Word files from the company's HR department, contained an exploit for CVE-2021-40444, a vulnerability in the old Internet Explorer MHTML component that can be exploited via Office files to run malicious code on unpatched Windows systems and install malware.

"The email asks employees to please fill out the form and send it to HR, or reply to the mail. When the receiver wants to fill out the form they will have to enable editing. And that action is enough to trigger the exploit," Malwarebytes researchers explained today.

"The attack depends on MSHTML loading a specially crafted ActiveX control when the target opens a malicious Office document. The loaded ActiveX control can then run arbitrary code to infect the system with more malware."

Identity of the attackers still unknown

Other Office documents containing the same exploit were also spotted, this time posing as fines for "illegal activity," issued by Russia's Ministry of the Interior.

Malwarebytes said it was unable to link these documents to specific targets and that it is still investigating the identity of the group or groups behind the attacks leveraging the CVE-2021-40444 exploit.

"Given the targets, especially the first one, we suspect that there may be a state-sponsored actor behind these attacks," the company said today.

Malwarebytes noted that attacks against Russian organizations are generally rare, which the company isn't wrong about.

In May 2021, in a rare report, the FSB said that foreign "cyber mercenaries" had breached several Russian government agencies. Those attacks were later tied to Chinese cyber-espionage groups by security firms like SentinelOne and Group-IB.

Microsoft patched CVE-2021-40444 on September 14, during the September 2021 Patch Tuesday.

Attacks abusing this former zero-day have also targeted Russian telcos, and, according to RiskIQ, an individual associated with the Ryuk/Conti ransomware gang has also started experimenting with this vector.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/russian-missile-fuel-maker-targeted-with-recent-office-zero-day