ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Alerts Federal Agencies to Patch Actively Exploited Linux Kernel Flaw

criticalVulnerability exploited in the wildimportance 60CVE-2024-1086CVE-2024-24919

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1086
Use-After-Free Local Privilege Escalation in Linux Kernel nf_tables

CVE-2024-1086 is a use-after-free vulnerability (CWE-416) in the Linux kernel's netfilter nf_tables component, tracked in CISA's catalog as a Linux Kernel Use-After-Free Vulnerability. A local attacker who can interact with the nf_tables netfilter subsystem can trigger the dangling memory reference to gain elevated privileges on the affected host. Successful exploitation yields local privilege escalation, effectively giving the attacker higher (typically root-level) access on an already-compromised machine. Any Linux system running a kernel with the affected nf_tables code is potentially impacted, which spans most modern server, cloud, and embedded Linux deployments. The flaw is being exploited in the wild: it was added to CISA KEV on 2024-05-30 with known ransomware use, and EPSS assigns a 28.1% probability of exploitation within 30 days (98th percentile).

Do: Apply patched kernel updates from your Linux distribution or vendor as soon as they are available, prioritizing hosts listed in CISA KEV (federal agencies must act per the KEV deadline). Until patching, reduce exposure by limiting unprivileged users' ability to create user namespaces and interact with nf_tables, and confirm whether the nf_tables/netfilter modules are loaded on your systems. Because ransomware operators are using this flaw post-compromise, patching should precede or accompany ransomware-hardening reviews on Linux servers.

7.828% KEV ransomware PoC ×4
  • Linux Kernel
masshundreds of millions of deployments (Linux is the default kernel across most servers, cloud instances, and embedded devices)
CVE-2024-24919
Information Disclosure in Internet-Facing Check Point Quantum Security Gateways

Check Point Quantum Security Gateways contain an information disclosure flaw (CWE-200) that can expose information stored on the appliance to unauthorized parties. It is triggered when an attacker targets a gateway connected to the internet with IPSec VPN, Remote Access VPN, or Mobile Access enabled, sending crafted requests to the exposed VPN services. A successful attacker gains unauthorized access to information on the gateway, and CISA notes known use of this flaw in ransomware campaigns. The issue spans multiple Check Point product lines: CloudGuard Network, Quantum Scalable Chassis, Quantum Security Gateways, and Quantum Spark Appliances. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV catalog on 2024-05-30 with ransomware use listed, and EPSS assigns a 100% probability of exploitation within 30 days, though no public proof-of-concept is known.

Do: Apply the hotfix Check Point distributes per its advisory (SK170863) to all internet-facing gateways running IPSec VPN, Remote Access VPN, or Mobile Access; this is also the CISA KEV required action. Where the hotfix cannot be applied immediately, restrict or disable the Remote Access VPN and Mobile Access software blades as an interim mitigation. Review gateway and VPN logs for signs of exploitation and prioritize remediation given confirmed ransomware use.

8.6100% KEV ransomware
  • Check Point Quantum Security Gateways
  • Check Point CloudGuard Network
  • Check Point Quantum Scalable Chassis
  • +1 more
largetens of thousands of internet-exposed VPN gateways (10k-100k systems)
Full article249 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMay 30, 2024Linux / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a security flaw impacting the Linux kernel to the Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

Tracked as CVE-2024-1086 (CVSS score: 7.8), the high-severity issue relates to a use-after-free bug in the netfilter component that permits a local attacker to elevate privileges from a regular user to root and possibly execute arbitrary code.

"Linux kernel contains a use-after-free vulnerability in the netfilter: nf_tables component that allows an attacker to achieve local privilege escalation," CISA said.

Netfilter is a framework provided by the Linux kernel that allows the implementation of various network-related operations in the form of custom handlers to facilitate packet filtering, network address translation, and port translation.

The vulnerability was addressed in January 2024. That said, the exact nature of the attacks exploiting the flaw is presently unknown.

Also added to the KEV catalog is a newly disclosed security flaw impacting Check Point network gateway security products (CVE-2024-24919, CVSS score: 7.5) that allows an attacker to read sensitive information on Internet-connected Gateways with remote access VPN or mobile access enabled.

In light of the active exploitation of CVE-2024-1086 and CVE-2024-24919, federal agencies are recommended to apply the latest fixes by June 20, 2024, to protect their networks against potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/05/cisa-alerts-federal-agencies-to-patch.html