ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Microsoft Streaming Service bug to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2023-29360

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-29360
Untrusted Pointer Dereference in Microsoft Streaming Service Grants SYSTEM Privileges

CVE-2023-29360 is an untrusted pointer dereference (CWE-822) in the Microsoft Streaming Service, the kernel-level streaming component that ships with Windows. A local attacker who can run code on an affected system can trigger the flaw to dereference an attacker-controlled pointer, elevating their privileges from an ordinary user to SYSTEM. Successful exploitation gives the attacker full control of the host, making it a useful post-compromise step for threat actors, including in ransomware chains (CISA notes ransomware use as unknown). Any Windows system that includes the Microsoft Streaming Service is affected; the vulnerability was addressed by Microsoft's security updates in 2023. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-02-29, and EPSS estimates a 22.1% probability of exploitation in the next 30 days (98th percentile).

Do: Apply Microsoft's June 2023 (or later) security updates on all Windows client and server hosts, per the CISA required action to apply vendor mitigations or discontinue use; there is no indication of a workaround, so patching is the primary mitigation. Prioritize systems where local privilege escalation has real impact — multi-user endpoints, RDP-exposed servers, and hosts with evidence of prior compromise — since exploitation requires local execution. Confirm patch levels against Microsoft's advisories and treat the KEV listing as a remediation deadline for your environment.

8.422% KEV
  • Microsoft Streaming Service (Windows kernel streaming component)
masseffectively the global Windows installed base
Full article224 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft Streaming Service vulnerability to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the CVE-2023-29360 (CVSS Score 8.4) Microsoft Streaming Service Untrusted pointer dereference vulnerability to its Known Exploited Vulnerabilities (KEV) catalog.

An attacker can exploit this vulnerability to gain SYSTEM privileges. The vulnerability was discovered by Thomas Imbert (@masthoon) from Synacktiv (@Synacktiv) through the Trend Micro Zero Day Initiative.

The availability of proof-of-concept (PoC) codes allowed multiple threat actors to include the malicious code in their attack chain.

In February, the analysis of some Raspberry Robin samples before October 2023, revealed that the operators also used an exploit for CVE-2023-29360. The exploit for the vulnerability CVE-2023-29360 was publicly disclosed in June, and Raspberry Robin employed it in August.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by March 21, 2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – Hacking, Known Exploited Vulnerabilities catalog)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/159796/security/cisa-adds-microsoft-streaming-service-bug-known-exploited-vulnerabilities-catalog.html