ZeroHour
Help Net Securitypublished ()ingested @helpnetsecurity2

Week in review: PoC for Splunk Enterprise RCE flaw released, scope of Okta breach widens

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-41998
+2 in the same advisory: …42000 …41999
Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface.

Arcserve UDP prior to 9.2 contained a vulnerability in the com.ca.arcflash.rps.webservice.RPSService4CPMImpl interface. A routine exists that allows an attacker to upload and execute arbitrary files.

NVD description · AI analysis pending
9.815% PoC
  • arcserve udp
CVE-2023-42917
+1 in the same advisory: …42916
WebKit Memory Corruption in Apple iOS, macOS, and Safari Enables Arbitrary Code Execution

CVE-2023-42917 is a memory corruption flaw (CWE-787, out-of-bounds write class) in Apple's WebKit browser engine, addressed with improved locking. It is triggered when a device processes maliciously crafted web content, meaning an attacker can reach vulnerable code simply by getting a user to load attacker-controlled web content. Successful exploitation may lead to arbitrary code execution with the privileges of the affected application. All users of the affected Apple platforms — iPhone, iPad, Mac (Sonoma), and Safari — are exposed, and the CPE data also indicates WebKitGTK as shipped by Debian and Fedora is in scope. The flaw is being actively exploited: Apple reported it was exploited in the wild against versions of iOS before 16.7.1, it was added to CISA KEV on 2023-12-04, and EPSS assigns a 9.4% probability of exploitation in the next 30 days (95th percentile).

Do: Upgrade to iOS 17.1.2, iPadOS 17.1.2, macOS Sonoma 14.1.2, and Safari 17.1.2; organizations with devices on the older iOS 16 line should check Apple's advisories for backported fixes, since the in-the-wild exploitation was reported against iOS versions before 16.7.1. Linux defenders running Debian or Fedora should apply the latest WebKitGTK security updates from their distribution. As a KEV entry (added 2023-12-04), remediation is mandatory for federal agencies per CISA's required action; verify device versions via MDM or inventory and prioritize internet-facing and high-risk users.

8.8
group max
9% KEV
  • apple iphone os (iOS) versions prior to iOS 17.1.2; exploitation reported against versions of iOS before 16.7.1
  • apple ipados versions prior to iPadOS 17.1.2
  • apple macos (Sonoma) versions prior to macOS Sonoma 14.1.2
  • +4 more
masson the order of 1 billion+ devices/users (Apple's active iPhone/iPad/Mac/Safari installed base)
CVE-2023-46214
In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users

In Splunk Enterprise versions below 9.0.7 and 9.1.2, Splunk Enterprise does not safely sanitize extensible stylesheet language transformations (XSLT) that users supply. This means that an attacker can upload malicious XSLT which can result in remote code execution on the Splunk Enterprise instance.

NVD description · AI analysis pending
8.889%
  • splunk cloud
  • splunk splunk
CVE-2023-49103
Unauthenticated phpinfo credential leak in ownCloud graphapi

CVE-2023-49103 is an unauthenticated information disclosure flaw in ownCloud's graphapi app (0.2.x before 0.2.1 and 0.3.x before 0.3.1), which ships a third-party GetPhpInfo.php page that returns the full PHP phpinfo output when its URL is requested. An attacker with no credentials or user interaction simply accesses that URL over the network, and the phpinfo output reveals all of the webserver's environment variables plus other potentially sensitive configuration details. In containerized deployments these environment variables frequently include the ownCloud admin password, mail server credentials, and license key, giving attackers direct credentials for the server; notably, disabling the graphapi app does not remove the exposed file. Affected deployments are ownCloud installations running the vulnerable graphapi versions, especially ownCloud Docker images built after February 2023, while containers built before February 2023 are not vulnerable to the credential disclosure. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-30, the EPSS score is 78.4% (top percentile), and public reporting says threat actors have begun exploiting the flaw, though no public PoC is known.

Do: Upgrade the graphapi app to version 0.2.1 or 0.3.1, and note that simply disabling the app is not sufficient — ensure the GetPhpInfo.php file is removed per vendor instructions. Operators of containerized ownCloud deployments (Docker images from February 2023 onward) should assume the ownCloud admin password, mail server credentials, and license key were exposed, rotate them, and review web logs for requests to the GetPhpInfo.php URL. CISA KEV requires applying vendor mitigations or discontinuing use of the product if mitigations are unavailable.

7.578% KEV
  • ownCloud graphapi (graphapi app) 0.2.x before 0.2.1; 0.3.x before 0.3.1
largeTens of thousands of internet-exposed ownCloud instances (order of magnitude 10k–100k), within a self-hosted user base in the millions
CVE-2023-6345
Integer Overflow in Google Chrome's Skia Enables Sandbox Escape (Actively Exploited)

CVE-2023-6345 is an integer overflow (CWE-190) in Skia, the 2D graphics rendering library used by Google Chrome and other Chromium-based browsers. It is triggered when a compromised renderer processes a malicious file, allowing a remote attacker who has already gained code execution in the renderer process to escape the Chrome sandbox and run code with broader privileges. Users of Google Chrome prior to 119.0.6045.199 are affected, as are Chromium-based derivatives including Microsoft Edge (Chromium) and Chromium packages shipped by Debian and Fedora. The flaw was rated High by Chromium, carries a CVSS 3.1 score of 9.6, and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-30. Google has patched the bug in Chrome 119.0.6045.199, and news reporting confirms it was being actively exploited in the wild at the time of the fix.

Do: Update Google Chrome to 119.0.6045.199 or later and restart the browser to fully apply the fix; on Debian and Fedora, apply the updated chromium packages from the distro repositories, and allow Microsoft's Chromium fix to flow into Edge before trusting affected builds. Verify browser versions (chrome://version or equivalent) across managed fleets, and note that because this is CISA KEV-listed (added 2023-11-30), US federal agencies must patch per vendor instructions or discontinue use by the required deadline.

9.616% KEV
  • Google Chrome prior to 119.0.6045.199
  • Google Chromium (Skia graphics library) Skia in Chromium prior to the fix released with Chrome 119.0.6045.199
  • Microsoft Edge (Chromium-based)
  • +2 more
masshundreds of millions to billions of Chrome and Chromium-based browser installations
Full article1,267 words · extracted from helpnetsecurity.com · click to collapse

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

Week in review

Vulnerability disclosure: Legal risks and ethical considerations for researchers
In this Help Net Security interview, Eddie Zhang, Principal Consultant at Project Black, explores the complex and often controversial world of vulnerability disclosure in cybersecurity.

How passkeys are reshaping user security and convenience
In this Help Net Security interview, Anna Pobletts, Head of Passwordless at 1Password, talks about passkey adoption and its acceleration in 2024. This trend is particularly notable among highly-regulated services like fintech and banking, where users seek a sign-in experience that is simple and familiar.

Strategies for cultivating a supportive culture in zero-trust adoption
In this Help Net Security interview, Wolfgang Goerlich, Advisory CISO at Cisco, discusses the benefits of implementing a mature zero-trust model for both security and business outcomes, revealing a decrease in reported security incidents and enhanced adaptability.

Bridging the risk exposure gap with strategies for internal auditors
In this Help Net Security interview, Richard Chambers, Senior Internal Audit Advisor at AuditBoard, discusses the transformational role of the internal audit function and risk management in helping organizations bridge the gap in risk exposure.

AWS Kill Switch: Open-source incident response tool
AWS Kill Switch is an open-source incident response tool for quickly locking down AWS accounts and IAM roles during a security incident.

Vigil: Open-source LLM security scanner
Vigil is an open-source security scanner that detects prompt injections, jailbreaks, and other potential threats to Large Language Models (LLMs).

Mosint: Open-source automated email OSINT tool
Mosint is an automated email OSINT tool written in Go designed to facilitate quick and efficient investigations of target emails. It integrates multiple services, providing security researchers with rapid access to a broad range of information.

PoC for Splunk Enterprise RCE flaw released (CVE-2023-46214)
A proof-of-concept (PoC) exploit for a high-severity flaw in Splunk Enterprise (CVE-2023-46214) that can lead to remote code execution has been made public. Users are advised to implement the provided patches or workarounds quickly.

Released: AI security guidelines backed by 18 countries
The UK National Cyber Security Centre (NCSC) has published new guidelines that can help developers and providers of AI-powered systems “build AI systems that function as intended, are available when needed, and work without revealing sensitive data to unauthorised parties.”

Critical ownCloud flaw under attack (CVE-2023-49103)
Attackers are trying to exploit a critical information disclosure vulnerability (CVE-2023-49103) in ownCloud, a popular file sharing and collaboration platform used in enterprise settings.

Okta breach: Hackers stole info on ALL customer support users
The scope of the recent breach of the Okta customer support system is much wider than initially established, the company has admitted on Tuesday: the attackers downloaded a report that contained the names and email addresses of all Okta customer support system users.

PoCs for critical Arcserve UDP vulnerabilities released
Arcserve has fixed critical security vulnerabilities (CVE-2023-41998, CVE-2023-41999, CVE-2023-42000) in its Unified Data Protection (UDP) solution, PoCs for which have been published by Tenable researchers on Monday.

Apple patches two zero-days used to target iOS users (CVE-2023-42916 CVE-2023-42917)
With the latest round of security updates, Apple has fixed two zero-day WebKit vulnerabilities (CVE-2023-42916, CVE-2023-42917) that “may have been exploited against versions of iOS before iOS 16.7.1.”

SMBs face surge in “malware free” attacks
“Malware free” attacks, attackers’ increased reliance on legitimate tools and scripting frameworks, and BEC scams were the most prominent threats small and medium businesses (SMBs) faced in Q3 2023, says the inaugural SMB Threat Report by Huntress, a company that provides a security platform and services to SMBs and managed service providers (MSPs).

Slovenian power company hit by ransomware
Slovenian power generation company Holding Slovenske Elektrarne (HSE) has been hit by ransomware and has had some of its data encrypted.

Google fixes Chrome zero day exploited in the wild (CVE-2023-6345)
Google has released an urgent security update to fix a number of vulnerabilities in Chrome browser, including a zero-day vulnerability (CVE-2023-6345) that is being actively exploited in the wild.

CISA urges water facilities to secure their Unitronics PLCs
News that Iran-affiliated attackers have taken over a programmable logic controller (PLC) at a water system facility in Pennsylvania has been followed by a public alert urging other water authorities to immediately secure their own PLCs.

Why it’s the perfect time to reflect on your software update policy
Historically, software updates have been an opportunity for developers to strike a balance between introducing new features and addressing known vulnerabilities. However, in the face of an increasingly nimble attacker community and an overall jump in attack sophistication, this balance has tipped towards a more urgent need for rapid security responsiveness.

Bridging the gap between cloud vs on-premise security
With the proliferation of SaaS applications, remote work and shadow IT, organizations feel obliged to embrace cloud-based cybersecurity. And rightly so, because the corporate resources, traffic, and threats are no longer confined within the office premises.

Security leaders on high alert as GenAI poses privacy and security risks
In this Help Net Security video, Neil Cohen, Head of Go-To-Market at Portal26, discusses why security leaders are concerned about GenAI privacy and security risks. While the advantages of GenAI are indisputable, a lack of visibility will result in reduced efficiency and increased vulnerabilities in areas such as governance, privacy, and beyond.

Guarding the gateway: Securing dispersed networks
In this Help Net Security video, Martin Roesch, CEO of Netography, discusses why the shift is happening now, the top challenges organizations face to secure their dispersed networks, and how to successfully evolve with and secure today’s networks.

Enterprises prepare for the inevitable cyber attack
In this Help Net Security video, Rahul Pawar, Global VP of Security Go-To-Market, CTO of Global Services & Solutions at Commvault, discusses why business leaders must play a key role in ensuring companies prioritize cyber preparedness.

What custom GPTs mean for the future of phishing
In this Help Net Security video, Tal Zamir, CTO of Perception Point, believes this will be a powerful tool malicious actors will use to amp up phishing campaigns, as they’ll gain an efficient way to boost customized phishing email output beyond their use of traditional ChatGPT.

Key drivers of software security for financial services
In this Help Net Security video, Chris Eng, Chief Research Officer at Veracode, discusses how financial organizations would benefit from increased automation and secure coding techniques to help them prevent, detect, and respond to vulnerabilities faster than ever.

Report: The state of authentication security 2023
This survey set out to explore these challenges, to identify common practices, and to provide insight into how organizations can bolster their defenses.

Generative AI security: Preventing Microsoft Copilot data exposure
Copilot is an AI assistant that lives inside each of your Microsoft 365 apps — Word, Excel, PowerPoint, Teams, Outlook, and so on. Microsoft’s dream is to take the drudgery out of daily work and let humans focus on being creative problem-solvers.

Product showcase: New ESET Home Security
ESET HOME Security subscriptions are available on all major operating systems —Windows, macOS, Android, and iOS. With the new offering, ESET introduces two groundbreaking features to bolster online security and privacy—VPN and Identity Protection.

Infosec products of the month: November 2023
Here’s a look at the most interesting products from the past month, featuring releases from: Action1, Amazon, Aqua Security, ARMO, Datadog, Devo Technology, Druva, Entrust, Enzoic, Fortanix, GitHub, Illumio, Immuta, IRONSCALES, Kasada, Lacework, Malwarebytes, Nitrokey, OneSpan, Paladin Cloud, Snappt, ThreatModeler, and Varonis.

New infosec products of the week: December 1, 2023
Here’s a look at the most interesting products from the past week, featuring releases from Amazon, Datadog, Entrust, Fortanix, GitHub, Nitrokey, and Paladin Cloud.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/12/03/week-in-review-poc-for-splunk-enterprise-rce-flaw-released-scope-of-okta-breach-widens/