ZeroHour
The Recordpublished ()ingested

CISA says latest VMware analytics bug being exploited

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-20887CVE-2016-9079CVE-2016-0165

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-0165
Local Privilege Escalation in Microsoft Win32k Kernel Driver

CVE-2016-0165 is a Win32k elevation-of-privilege flaw in the Windows kernel-mode driver, affecting Windows Vista SP2 through Windows 10 version 1511 and the corresponding Server editions. An attacker must already be able to run a crafted application locally on the affected machine, at which point the flaw can be triggered to escape the user context. Successful exploitation grants the attacker SYSTEM/kernel-level privileges, providing complete confidentiality, integrity, and availability impact on the host. Any organization running the listed Windows versions is exposed, especially servers and workstations used for shared access. The flaw has been exploited in the wild: it was used as a zero-day in targeted attacks attributed to the FruityArmor APT, it carries a 13.8% EPSS probability of exploitation within 30 days, and CISA added it to the KEV on 2023-06-22, requiring federal agencies to apply vendor updates.

Do: Apply the vendor security updates for CVE-2016-0165 per Microsoft's instructions on all affected Windows Vista, Server 2008/2012, Windows 7, 8.1, RT 8.1, and Windows 10 1507/1511 systems, prioritizing KEV-driven remediation. Because this is a local privilege escalation, limit interactive and remote logon rights to untrusted users on hosts that cannot be patched immediately, and ensure endpoint monitoring watches for the FruityArmor-style targeted attack activity. Systems such as Vista, Windows 7, and Windows 10 1507/1511 that are past mainstream support should be upgraded to a supported OS release where possible.

7.814% KEV
  • microsoft windows vista SP2
  • microsoft windows 7 SP1
  • microsoft windows 8.1 all supported at time of disclosure
  • +5 more
masshundreds of millions of Windows PCs and servers (the affected OS versions spanned essentially the entire Windows install base at disclosure)
CVE-2016-9079
Use-After-Free in Mozilla Firefox and Tor Browser SVG Animation Exploited in the Wild

CVE-2016-9079 is a use-after-free flaw (CWE-416) in the SVG Animation component of Mozilla's Gecko engine, affecting Firefox before 50.0.2, Firefox ESR before 45.5.1, and Thunderbird before 45.5.1, as well as the Firefox-ESR-based Tor Browser and distro-packaged builds on Debian and Red Hat Enterprise Linux. It is triggered when the browser renders SVG content with animations, typically by loading a crafted web page, causing a freed SVG animation object to be reused and corrupting memory. A successful attack can lead to arbitrary code execution in the browser context or disclosure of sensitive memory contents; the assigned CVSS 3.1 score of 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N) reflects network-triggered memory corruption with high confidentiality impact and no privileges required. The in-the-wild exploit observed at disclosure targeted Firefox and Tor Browser users on Windows. The flaw has public PoC exploits, carries an EPSS 30-day exploitation probability of 87.4% (100th percentile), and was added to the CISA KEV catalog on 2023-06-22 with a required action to apply vendor updates.

Do: Upgrade Firefox to 50.0.2 or later, Firefox ESR to 45.5.1 or later, and Thunderbird to 45.5.1 or later, and install the corresponding patched Tor Browser build; users on Windows were the observed in-the-wild targets, so prioritize those hosts. On Debian and Red Hat Enterprise Linux, apply the vendor's updated firefox/thunderbird/tor packages per their advisories, consistent with the CISA KEV required action. As an interim mitigation, restrict loading of untrusted web content with animated SVG and verify no machines in the environment are still running Firefox versions older than 50.0.2.

7.587% KEV PoC ×3
  • mozilla Firefox < 50.0.2
  • mozilla Firefox ESR < 45.5.1
  • mozilla Thunderbird < 45.5.1
  • +3 more
mass~200-300 million Firefox users/install base at the time of disclosure (late 2016), plus roughly 1-2 million Tor Browser daily users (Windows-targeted…
CVE-2023-20887
Unauthenticated Command Injection RCE in VMware Aria Operations for Networks

VMware Aria Operations for Networks (formerly vRealize Network Insight) contains a command injection flaw (CWE-77) that allows an attacker with network access to the appliance to run arbitrary operating-system commands. Because the attack requires no authentication, privileges, or user interaction (CVSS:3.1/AV:N/AC:L/PR:N/UI:N), any party able to reach the product's network interface can trigger it, gaining remote code execution with high impact on confidentiality, integrity, and availability. Any organization running the product is affected, with internet-facing deployments at the greatest risk. Exploitation is confirmed in the wild — CISA added the flaw to the KEV catalog on 2023-06-22, a public proof-of-concept exploit is available, and EPSS puts the 30-day exploitation probability at 98.3% (top percentile). Ransomware use is currently unknown.

Do: Apply the vendor's patched update to all Aria Operations for Networks deployments as soon as possible — this is also CISA's required KEV action (apply updates per vendor instructions); verify the installed build against VMware's advisory for affected ranges. Until patching is complete, restrict network access to the appliance (firewall rules, VPN, or management-segment isolation), prioritizing any instance reachable from the internet since no authentication is required to exploit. Hunt for indicators of command injection exploitation, as in-the-wild exploitation has been confirmed.

9.898% KEV PoC
  • VMware Aria Operations for Networks (formerly vRealize Network Insight)
moderate≈10,000+ appliance deployments worldwide (low tens of thousands of appliance nodes); only a small fraction, likely hundreds to low thousands of instances, are…
Full article413 words · extracted from therecord.media · click to collapse

A new vulnerability affecting a popular VMware network analytics product is being exploited by hackers, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

CISA added CVE-2023-20887 to its catalog of known exploited vulnerabilities on Thursday, days after several researchers raised concerns about the issue and VMware confirmed that it is seeing exploitation in the wild.

The vulnerability affects VMware Aria Operations for Networks, a product used by network administrators to manage deployments of VMware and Kubernetes.

“A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution,” VMware said in its advisory.

It has a 9.8 out of 10 CVSS score, indicating a critical severity, and was reported by someone working with Trend Micro Zero Day Initiative.

VMware confirmed on June 13 that exploit code was published after a researcher known as SinSinology shared it on their GitHub page.

CISA and VMware urged customers to update their systems to the latest version.

Jacob Fisher, a researcher with security firm GreyNoise, said last week that they “have observed attempted mass-scanning activity utilizing the Proof-Of-Concept code.” GreyNoise CEO Andrew Morris shared charts showing exploitation of the vulnerability.

We're observing exploitation of VMWare CVE-2023-20887 in @GreyNoiseIO https://t.co/Xz1pWgdQFm pic.twitter.com/puaVDDJGo5

— Andrew Morris (@Andrew___Morris) June 20, 2023

CISA added five other vulnerabilities to its catalog, including three affecting the Roundcube Webmail service that were exploited by Russian hackers targeting Ukrainian government officials.

Ukraine’s computer emergency response team (CERT-UA) and researchers from Recorded Future’s Insikt Group attributed the campaign to APT28 — also known as Fancy Bear and BlueDelta — which multiple Western governments believe is run within the the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU).

The campaign targeted the email inboxes of a regional prosecutor's office, an undisclosed Ukrainian executive authority, other government entities and an organization involved in military aircraft infrastructure upgrade and refurbishment.

Alongside the Roundcube bugs are two vulnerabilities from 2016 – Mozilla Firefox bug CVE-2016-9079 and Microsoft Win32k issue CVE-2016-0165.

All of the vulnerabilities have to be patched by July 13, CISA said.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-latest-vmware-analytics-bug-being-exploited