Microsoft accuses China of abusing vulnerability disclosure requirements
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-35211 | Unauthenticated RCE (Remote Memory Escape) in SolarWinds Serv-U Microsoft researchers discovered a remote code execution flaw in SolarWinds Serv-U, an out-of-bounds write (CWE-787) described as a "Remote Memory Escape" in the Windows-based Serv-U products. A remote, unauthenticated attacker can trigger the flaw over the network against servers running a version before 15.2.3 HF2 and gain privileged access to the machine hosting Serv-U, with a maximum CVSS 10.0 score reflecting no required privileges, no user interaction, and impact beyond the application's security scope. Both Serv-U Managed File Transfer and Serv-U Secure FTP for Windows are affected. The vulnerability has been exploited in the wild: Microsoft attributed July 2021 attacks exploiting the Serv-U zero-day to Chinese threat actors, later warned of an uptick in exploitation attempts, and the flaw was added to CISA KEV on 2021-11-03 with known ransomware use. Do: Upgrade Serv-U to 15.2.3 Hotfix 2 (HF2) or later per SolarWinds' instructions immediately, as the flaw is in CISA KEV with known exploitation including ransomware use. Audit Serv-U servers and their logs for signs of exploitation or compromise, and restrict internet exposure of Serv-U/FTP and SSH ports to trusted parties. | 10.0 | 91% | KEV ransomware |
| largeestimated tens of thousands of Serv-U deployments worldwide, with a few thousand instances directly internet-exposed | |
| CVE-2021-42321 | Authenticated RCE via Insecure Deserialization in Microsoft Exchange Server CVE-2021-42321 is an insecure deserialization remote code execution flaw in on-premises Microsoft Exchange Server, tied to insufficient validation by Exchange's ChainedSerializationBinder. Per the CVSS vector, it is triggered over the network by an authenticated user with low privileges and no user interaction, by submitting crafted serialized data that Exchange fails to safely deserialize. A successful attacker gains arbitrary code execution on the Exchange server with high impact to confidentiality, integrity, and availability, giving a foothold in the mail environment. Organizations running affected on-premises Exchange deployments are in scope. The flaw was actively exploited before patches shipped in November 2021, has public PoC exploits, was added to CISA's KEV on 2021-11-17 with known ransomware use, and carries an EPSS of 91.7% (99.9+ percentile). Do: Apply the November 2021 Microsoft Exchange Server security updates per vendor instructions to affected on-premises Exchange 2016/2019 deployments. Given confirmed in-the-wild exploitation and known ransomware use, check Exchange servers for signs of compromise, verify backups, and review accounts holding privileged Exchange roles, since exploitation requires authenticated access — enforce MFA and audit impersonation/admin role assignments while patching. | 8.8 | 92% | KEV ransomware PoC ×2 |
| masshundreds of thousands of internet-facing on-premises Exchange servers (on the order of 10^5 endpoints, supporting millions of mailbox users) | |
| CVE-2022-26134 | Unauthenticated OGNL Injection RCE in Atlassian Confluence Server/Data Center Atlassian Confluence Server and Data Center contain an unauthenticated remote code execution flaw caused by improper neutralization of expression-language (OGNL) input (CWE-917): an attacker with network access to the application can submit a crafted request that is evaluated as an expression and executed by the server. Successful exploitation lets a remote, unauthenticated attacker run arbitrary code with the privileges of the Confluence process, without any credentials. All organizations running self-managed Confluence Server or Data Center are affected, particularly instances exposed to the internet; Confluence Cloud is not listed among the affected products. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-06-02 with ransomware use marked as known, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile). CVSS has not yet been scored in this data, but the KEV listing and known ransomware use make unpatched, internet-facing instances a top-priority patching target. Do: Immediately upgrade to the patched Confluence release specified in Atlassian's 2022-06-02 security advisory, and until patched follow the CISA required action to block all internet traffic to and from affected instances. Because in-the-wild exploitation and ransomware use are confirmed, also hunt for compromise indicators on both patched and unpatched hosts, such as webshells, unexpected child processes of the Confluence service, and unusual outbound connections. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largetens of thousands of internet-exposed instances (public scan counts of roughly 60,000-90,000 Confluence Server/Data Center hosts around the June 2022… |
Full article873 words · extracted from therecord.media · click to collapse
Microsoft on Friday accused state-backed hackers in China of abusing the country’s vulnerability disclosure requirements in an effort to discover and develop zero-day exploits. In July 2021, the Cyberspace Administration of China (CAC) issued stricter rules around disclosing vulnerabilities for companies operating within its borders. Concerns that the Chinese military would exploit vulnerabilities before reporting them more broadly was an integral part of the investigation into the handling of the widespread Log4j vulnerability. Reports emerged earlier this year that the Chinese government had sanctioned Alibaba for reporting the vulnerability to Apache first, rather than to the government. The Homeland Security Department’s Cyber Safety Review Board spoke with the Chinese government and “did not find evidence” that China used its advanced knowledge of the weakness to exploit networks. But in a 114-page security report released on Friday, Microsoft openly accused the Chinese government of abusing the new rules and outlines how state-aligned groups have increasingly exploited vulnerabilities globally since they were implemented. “The increased use of zero days over the last year from China-based actors likely reflects the first full year of China’s vulnerability disclosure requirements for the Chinese security community and a major step in the use of zero-day exploits as a state priority,” Microsoft said. “While we observe many nation state actors developing exploits from unknown vulnerabilities, China-based nation state threat actors are particularly proficient at discovering and developing zero-day exploits.” Microsoft said the rules went into effect in September 2021 and marked “a first in the world for a government to require the reporting of vulnerabilities into a government authority for review prior to the vulnerability being shared with the product or service owner.” The tech giant added that the regulation “might enable elements in the Chinese government to stockpile reported vulnerabilities toward weaponizing them.” China’s Foreign Ministry did not respond to requests for comment about Microsoft’s claims. Microsoft went on to pin the abuse of specific zero-day vulnerabilities on Chinese government hackers, including SolarWinds vulnerability CVE-2021-35211, two vulnerabilities affecting Zoho products and CVE-2021-42321, a zero-day exploit for a Microsoft Exchange vulnerability. Microsoft added that a “China-affiliated actor” likely had the zero-day exploit code for CVE-2022-26134 — a vulnerability affecting Atlassian products — four days before the vulnerability was publicly disclosed on June 2. The actor “likely leveraged it against a US-based entity.” In its report, Microsoft accuses China of conducting prolific global hacking campaigns against both allies and adversaries. The attacks, they wrote, spanned Africa, the Caribbean, the Middle East, Oceania, and South Asia, with a particular focus on countries in Southeast Asia, and the Pacific Islands. “In line with China’s Belt and Road Initiative [BRI] strategy, China-based threat groups targeted entities in Afghanistan, Kazakhstan, Mauritius, Namibia, and Trinidad and Tobago,” Microsoft said. Trinidad and Tobago was the first Caribbean country to join the initiative in 2018, signing construction deals at the outset. Nonetheless, Chinese hackers targeted the country’s networks throughout 2021 and conducted reconnaissance activities against one of its government agencies in March 2022, according to Microsoft. Countries across Southeast Asia and throughout the Pacific were also targeted widely, according to Microsoft, which confirmed reports from several other cybersecurity companies that tracked widespread attacks by Chinese state-backed hackers. State hackers targeted an energy company and an energy-associated government agency in Vietnam in January, while also going after an Indonesian government agency that same month. Another hacking group allegedly connected to the Chinese government compromised more than 100 accounts affiliated with a prominent intergovernmental organization (IGO) in the Southeast Asia region in February and March. That attack coincided with an announcement that the IGO would be meeting with the United States and other regional leaders. A hacking campaign targeting the Solomon Islands also stood out to Microsoft researchers, who noted that the attacks started in May, just one month after China signed a security agreement with the island nation that allowed the country to deploy armed police and military. Malware from a China-based hacking group was found on Solomon Islands government systems in May. Other hacks targeted organizations in Papua New Guinea as well, according to Microsoft. In December 2021, Microsoft obtained a court warrant that allowed it to seize 42 domains used by a Chinese cyber-espionage group in recent operations that targeted organizations in the U.S. and 28 other countries. The tech giant noted that since that action, the same Chinese hacking group has sought to establish the access it lost. Between March and May of this year, the group was able to re-compromise at least five government agencies across the globe. “As China continues to establish bilateral economic relations with more countries— often in agreements associated with BRI— China’s global influence will continue to grow,” Microsoft said. “We assess Chinese state and state-affiliated threat actors will pursue targets in their government, diplomatic, and NGO sectors to gain new insights, likely in pursuit of economic espionage or traditional intelligence collection objectives.”Global hacking campaigns
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-accuses-china-of-abusing-vulnerability-disclosure-requirements