ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino

FBI Issues Alert on Russian Threats Targeting Ubiquiti Routers

mediumVulnerabilityimportance 35CVE-2023-23397

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-23397
Zero-Click Elevation of Privilege in Microsoft Outlook (Forced NTLM Credential Leak)

CVE-2023-23397 is an elevation of privilege vulnerability in Microsoft Outlook caused by improper input validation (CWE-20) combined with authentication bypass via spoofed authentication data on the channel (CWE-294), allowing an attacker to force Outlook to authenticate to an attacker-controlled SMB/WebDAV server. It is triggered when Outlook processes a crafted email or calendar object — for example a meeting or task reminder whose sound property points to an attacker-supplied UNC path — and requires no user interaction. That authentication exchange leaks the victim's NTLM credential hash, which the attacker can crack offline or relay to authenticate as the victim and access resources such as Exchange mailboxes, effectively escalating privileges. Affected software spans Microsoft 365 Apps, Microsoft Office (including the Long Term Servicing Channel), and Microsoft Outlook, which are deployed across enterprises, governments, and militaries worldwide. It is actively exploited in the wild — added to CISA's Known Exploited Vulnerabilities catalog on 2023-03-14 with a 97.4% EPSS — and Microsoft has warned of exploitation by Russia-aligned threat actors in campaigns against government and military mail servers, with patches shipped in Microsoft's March 2023 security updates.

Do: Apply Microsoft's March 2023 security updates to Microsoft 365 Apps, Office/LTSC, and Outlook immediately, per CISA's required action. As interim mitigation, enable Extended Protection for Authentication or add accounts to the Protected Users group to block the NTLM credential leak, and audit calendar and task reminder sound properties for UNC paths (Microsoft published an audit/cleanup script for this) while watching for unexpected outbound SMB/WebDAV connections from hosts running Outlook.

9.897% KEV
  • Microsoft 365 Apps Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • Microsoft Office Long Term Servicing Channel (LTSC) Affected builds as covered by Microsoft's March 2023 security updates; see Microsoft advisory for exact build ranges
  • +1 more
masson the order of hundreds of millions of users (Outlook ships with Microsoft Office/Microsoft 365, the dominant enterprise and government email suite)
Full article446 words · extracted from infosecurity-magazine.com · click to collapse

A joint Cybersecurity Advisory (CSA) issued by the Federal Bureau of Investigation (FBI), National Security Agency (NSA), US Cyber Command and international partners has raised alarms regarding Russian state-sponsored cyber actors’ exploitation of compromised Ubiquiti EdgeRouters.

Identified as the Russian General Staff Main Intelligence Directorate (GRU), 85th Main Special Service Center (GTsSS), these actors, also known as APT28, Fancy Bear and Forest Blizzard (Strontium), have utilized compromised EdgeRouters to harvest credentials, proxy network traffic and host spear-phishing landing pages and custom tools.

“There are a number of reasons EdgeRouters are particularly vulnerable to compromise,” explained Patrick Tiquet, vice president of security & architecture at Keeper Security. “EdgeRouters are shipped with vulnerable default login settings; they lack robust firewall settings and rely on manual firmware updates.”

In an advisory published on Tuesday, the agencies emphasized the urgency for owners of affected devices to take remedial actions to thwart these malicious activities effectively. Despite recent disruption of a GRU botnet by the US Department of Justice and its international partners, the CSA stressed the necessity of implementing recommended mitigations to safeguard against future compromises and identify existing ones.

Ubiquiti EdgeRouters, known for their user-friendly Linux-based operating system, are vulnerable due to default credentials and limited firewall protections, making them appealing targets for cyber actors. 

“Another issue is that the EdgeRouter itself provides a perfect position within the network for threat actors to either move laterally or to enable more advanced command-and-control functions for achieving their objectives,” commented John Gallagher, vice president of Viakoo Labs at Viakoo.

“Application-based discovery that finds IoT applications and devices can be a useful tool in finding if the IoT router is communicating with unauthorized applications.”

Because of these dangers, the CSA urged the immediate application of mitigation strategies outlined in the advisory to mitigate the risks associated with APT28 activity.

More generally, the document underscores the wide-ranging impact of APT28’s activities, targeting industries ranging from aerospace and defense to technology across various countries, including the US and Ukraine. Exploiting vulnerabilities such as CVE-2023-23397 to collect NTLMv2 digests from targeted Outlook accounts, these actors have persisted in their malicious endeavors despite patch releases by organizations like Microsoft.

Read more on these attacks: Russian APT28 Exploits Outlook Bug to Access Exchange

To combat these threats effectively, network owners are advised to conduct hardware factory resets, update firmware, change default credentials and implement robust firewall rules. Additionally, timely patching and disabling vulnerable protocols like NTLM are crucial steps in mitigating risks posed by such cyber threats.

The FBI also seeks collaboration from organizations and individuals to report any suspicious or criminal activities related to APT28’s operations on compromised EdgeRouters.

Image credit: rafapress / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/fbi-alert-russian-threats-ubiquiti/