ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Adds Three Security Flaws with Active Exploitation to KEV Catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-2551
Unauthenticated Remote Code Execution in Oracle WebLogic Server via IIOP

CVE-2020-2551 is a critical flaw in the WLS Core Components of Oracle WebLogic Server that allows an unauthenticated attacker with network access to the IIOP protocol to remotely compromise the server. An attacker sends crafted IIOP requests directly to a listening WebLogic instance and gains takeover of the server, with high impact to confidentiality, integrity, and availability (CVSS 9.8). Oracle WebLogic Server versions 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, and 12.2.1.4.0 are affected, spanning widely deployed enterprise and government middleware environments. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-11-16, and EPSS assigns a 93.2% probability of exploitation within 30 days (100th percentile), indicating active and likely broad targeting. Because exploitation requires only network reachability to the IIOP listener and no credentials or user interaction, internet-exposed WebLogic servers are the primary targets.

Do: Apply the Oracle fixes for CVE-2020-2551 (October 2020 Critical Patch Update) to each affected WebLogic release, or move to a patched supported release per Oracle's instructions, consistent with CISA's KEV required action. Until patched, block or restrict IIOP traffic to WebLogic listeners (default port 7001) from untrusted networks and remove direct internet exposure of WebLogic admin and application servers. Review access logs for anomalous IIOP connections and check patched and unpatched hosts for signs of compromise.

9.893% KEV
  • Oracle WebLogic Server (Oracle Fusion Middleware, WLS Core Components) 10.3.6.0.0, 12.1.3.0.0, 12.2.1.3.0, 12.2.1.4.0
largeorder of 10,000–50,000 internet-exposed WebLogic instances (public internet-wide scans have repeatedly shown tens of thousands of hosts exposing WebLogic…
CVE-2023-1671
Command Injection RCE in Sophos Web Appliance Warn-Proceed Handler

Sophos Web Appliance contains a command injection flaw (CWE-77) in the handler that processes 'warn and proceed' requests from the appliance's block page, allowing untrusted input to reach a shell command. An attacker who can reach the warn-proceed endpoint sends a crafted request whose parameters inject arbitrary operating system commands, resulting in remote code execution on the appliance. Successful exploitation gives the attacker control of the appliance host, a foothold at the network perimeter, and a platform for follow-on actions such as credential theft or lateral movement. Any organization running Sophos Web Appliance, especially where the appliance's web interface or warning pages are reachable from the internet, is affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-11-16, and EPSS assigns it a 100% probability of exploitation in the next 30 days, though no public proof-of-concept is known.

Do: Update Sophos Web Appliance to the fixed release identified in Sophos's advisory and confirm the running build is patched; restrict access to the appliance's web interface to trusted networks and review access logs for suspicious requests to the warn-proceed endpoint. If mitigations are unavailable or the deployment is on an unsupported build, follow the CISA KEV required action and discontinue use of the product.

9.8100% KEV PoC
  • Sophos Web Appliance Affected version ranges not enumerated in source data; per the vendor advisory, releases prior to the patched build are vulnerable — apply the vendor's fixed re
moderate≈ low thousands of appliances (on-prem secure web gateway; public scans show only a few thousand internet-exposed instances)
CVE-2023-2551
PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.

PHP Remote File Inclusion in GitHub repository unilogies/bumsys prior to 2.1.1.

NVD description · AI analysis pending
8.82% PoC
  • bumsys project bumsys
CVE-2023-34992
A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized c

A improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet allows attacker to execute unauthorized code or commands via crafted API requests.

NVD description · AI analysis pending
9.880%
  • fortinet fortisiem
CVE-2023-36553
A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2

A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiSIEM version 5.4.0 and 5.3.0 through 5.3.3 and 5.2.5 through 5.2.8 and 5.2.1 through 5.2.2 and 5.1.0 through 5.1.3 and 5.0.0 through 5.0.1 and 4.10.0 and 4.9.0 and 4.7.2 allows attacker to execute unauthorized code or commands via crafted API requests.

NVD description · AI analysis pending
9.82%
  • fortinet fortisiem
CVE-2023-36584
Mark of the Web (MOTW) Security Feature Bypass in Microsoft Windows

Microsoft Windows' Mark of the Web (MOTW) feature, which tags files downloaded from the internet so that security checks such as SmartScreen warnings and opening restrictions can apply, fails to correctly apply the mark in affected Windows versions. An attacker can trigger the bypass by delivering a crafted file over the network (typically downloaded or opened by a user), so Windows treats the file as originating from a trusted local source; the CVSS vector confirms network attack surface with required user interaction (AV:N/UI:R). A successful bypass lets a specially crafted application run without the security warnings and restrictions normally applied to internet-originated files, weakening endpoint defenses during malware delivery (per CVSS, integrity and availability are partially impacted with no confidentiality impact from the bypass itself). Any organization or user running Windows 10 (1507, 1809, 21H1, 22H2), Windows 11 (21H2, 22H2), or Windows Server 2008 through 2022 is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-11-16, confirming in-the-wild exploitation, and EPSS assigns a roughly 3.1% probability of exploitation in the next 30 days (87th percentile); no public proof-of-concept is known.

Do: Apply the November 2023 Windows cumulative security updates for each affected Windows 10, Windows 11, and Windows Server version, consistent with CISA's KEV required action (apply vendor mitigations or discontinue use if updates are unavailable). Prioritize user workstations and any systems where users open downloaded files or documents, since exploitation requires user interaction with a crafted internet-delivered file. Verify patch coverage across all listed Windows branches, as exploitation is confirmed in the wild and the primary gain is defeating MOTW-based warnings to aid malware delivery.

5.43% KEV
  • Microsoft Windows 10 1507, 1809, 21H1, 22H2
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019, 2022
mass≈1 billion+ installations (Windows 10/11 desktop installed base plus widely deployed Windows Server versions)
CVE-2023-36884
Race Condition RCE in Microsoft Windows Search

CVE-2023-36884 is a race condition (TOCTOU) vulnerability in Microsoft Windows Search that permits remote code execution, rated 7.5 (high) on CVSS 3.1. It is triggered over the network with user interaction — for example, when a user opens or interacts with a specially crafted document that causes the vulnerable search code path to race, allowing arbitrary code execution in the context of the current user. An attacker gains code execution on the victim's Windows system, which the RomCom threat actor chained with Firefox flaws to deploy backdoors against political targets, and CISA notes known ransomware use. Virtually every supported Windows client and server release at the time is affected, spanning Windows 10 1507 through 22H2, Windows 11 21H2/22H2, and Windows Server 2008 through 2022. The flaw was actively exploited as a zero-day before being fixed in the July 2023 Patch Tuesday; it was added to the CISA KEV catalog on 2023-07-17 and carries a 98.9% EPSS score (100th percentile).

Do: Apply the July 2023 Patch Tuesday Windows security updates to all Windows 10, Windows 11, and Windows Server systems, prioritizing high-value and frequently attacked endpoints since the bug was exploited as a zero-day by RomCom and carries a KEV deadline (US civilian agencies were directed to remediate by August 1, 2023). Because exploitation requires user interaction, caution users against opening untrusted documents, and verify patch status via your patch management or vulnerability scanner against the KEV requirement. If patching is not possible, follow vendor mitigations per CISA's required action or discontinue use.

7.599% KEV ransomware
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2
  • microsoft Windows Server 2008 as listed in the CPE data
  • +4 more
mass≈1 billion+ Windows devices (Windows 10/11 installed base) plus the enterprise Windows Server estate

Indicators of compromiseAll →

TypeIndicatorContext
domainharvard.eduentified a subdomain of the Harvard University – courses.my.harvard[.]edu – that was susceptible to CVE-2020-2551. On the other han
Full article574 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananNov 17, 2023Patch Management / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added three security flaws to its Known Exploited Vulnerabilities (KEV) catalog based on evidence of active exploitation in the wild.

The vulnerabilities are as follows -

  • CVE-2023-36584 (CVSS score: 5.4) - Microsoft Windows Mark-of-the-Web (MotW) Security Feature Bypass Vulnerability
  • CVE-2023-1671 (CVSS score: 9.8) - Sophos Web Appliance Command Injection Vulnerability
  • CVE-2020-2551 (CVSS score: 9.8) - Oracle Fusion Middleware Unspecified Vulnerability

CVE-2023-1671 relates to a critical pre-auth command injection vulnerability that allows for the execution of arbitrary code. CVE-2020-2551 is a flaw in the WLS Core Components that allows an unauthenticated attacker with network access to compromise the WebLogic Server.

There are currently no public reports documenting in-the-wild attacks leveraging CVE-2023-1671, but Cybernews disclosed in July 2023 that it had identified a subdomain of the Harvard University – courses.my.harvard[.]edu – that was susceptible to CVE-2020-2551.

On the other hand, the addition of CVE-2023-36584 to the KEV catalog is based on a report from Palo Alto Networks Unit 42 earlier this week, which detailed spear-phishing attacks mounted by pro-Russian APT group known as Storm-0978 (aka RomCom or Void Rabisu) targeting groups supporting Ukraine's admission into NATO in July 2023.

CVE-2023-36584, patched by Microsoft as part of October 2023 security updates, is said to have been used alongside CVE-2023-36884, a Windows remote code execution vulnerability addressed in July, in an exploit chain to deliver PEAPOD, an updated version of RomCom RAT.

In light of active exploitation, federal agencies are recommended to apply the fixes by December 7, 2023, to secure their networks against potential threats.

Fortinet Discloses Critical Command Injection Bug in FortiSIEM

The development comes as Fortinet is alerting customers of a critical command injection vulnerability in FortiSIEM report server (CVE-2023-36553, CVSS score: 9.3) that could be exploited by attackers to execute arbitrary commands.

CVE-2023-36553 has been described as a variant of CVE-2023-34992 (CVSS score: 9.7), a similar flaw in the same product that was remediated by Fortinet in early October 2023.

"An improper neutralization of special elements used in an OS command vulnerability [CWE-78] in FortiSIEM report server may allow a remote unauthenticated attacker to execute unauthorized commands via crafted API requests," the company said in an advisory this week.

The vulnerability, which impacts FortiSIEM versions 4.7, 4.9, 4.10, 5.0, 5.1, 5.2, 5.3, and 5.4, has been fixed in versions 7.1.0, 7.0.1, 6.7.6, 6.6.4, 6.5.2, 6.4.3, or later.

Update

When reached for comment on the addition of CVE-2023-1671 to the KEV catalog, Sophos shared the following statement with The Hacker News -

More than six months ago, on April 4, 2023, we released an automatic patch to all Sophos Web Appliances, as noted in the Security Advisory on our Trust Center, and in July 2023, we’ve phased out Sophos Web Appliance as previously planned. We appreciate CISA’s notice for any of the small number of remaining Sophos Web Appliance users who turned off auto-patch and/or missed our ongoing updates, and recommend they upgrade to Sophos Firewall for optimal network security moving forward.

(The article was updated after publication to mention that the third security flaw added to the KEV catalog is CVE-2020-2551 and not CVE-2023-2551, which was erroneously referenced in the alert published by CISA.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/11/cisa-adds-three-security-flaws-with.html