ZeroHour
The Recordpublished ()ingested

Exploit kit adds rare Chrome browser attack chain

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21224
Type Confusion RCE in Google Chrome/Chromium V8 JavaScript Engine

CVE-2021-21224 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used by Google Chrome and Chromium. An attacker triggers it by luring a user to open a crafted HTML page, causing V8 to mishandle object types during execution. Successful exploitation yields arbitrary code execution inside the Chrome renderer's sandbox, typically chained with a separate sandbox escape for full host compromise. Anyone running Google Chrome prior to 90.0.4430.85, or Chromium as packaged by Debian and Fedora, is affected. Exploitation is confirmed in the wild: Google shipped the fix in April 2021 after active attacks, a public PoC exists (crbug.com/1195777), the bug was observed in exploit-kit attack chains, EPSS assigns an 84% probability of near-term exploitation, and CISA added it to the KEV catalog on 2021-11-03.

Do: Update Google Chrome to 90.0.4430.85 or later immediately; Debian and Fedora users should apply the chromium package updates issued by their vendors, per CISA KEV required actions. There is no strong workaround short of disabling JavaScript or restricting browsing to trusted sites. Treat this as urgent, since the flaw was already used in real attacks and exploit-kit chains, where it was typically paired with a sandbox escape for full system compromise.

8.884% KEV PoC
  • google chrome prior to 90.0.4430.85 (fixed in 90.0.4430.85)
  • debian linux (chromium package) Chromium builds prior to upstream fix 90.0.4430.85; fixed package versions not specified in source data
  • fedoraproject fedora (chromium package) Chromium builds prior to upstream fix 90.0.4430.85; fixed package versions not specified in source data
masson the order of billions of users (Chrome's global install base exceeds 1 billion desktops; Chromium additionally ships in Debian and Fedora)
CVE-2021-31956
Local Privilege Escalation via Out-of-Bounds Write in Microsoft Windows NTFS

Microsoft Windows NTFS contains a privilege escalation flaw in which improper handling of integer underflow/overflow (CWE-191) leads to an out-of-bounds write (CWE-787), exploitable via a specially crafted application. A local attacker who can run such an application on a vulnerable Windows system can trigger the flaw and gain elevated privileges on that host. Because the flaw resides in the file system component shipped with Windows, essentially all supported Microsoft Windows releases are in scope. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2021-11-03 with a required action to apply vendor updates, though ransomware usage is unknown and no public proof-of-concept is cataloged. Predictive scoring (EPSS) places the 30-day exploitation probability at 22.3% (98th percentile).

Do: Apply Microsoft security updates on all Windows systems per vendor instructions; this flaw was remediated in Microsoft's June 2021 monthly security (cumulative) updates, so verify each Windows build's installed cumulative update level against the Microsoft advisory. Prioritize patching multi-user and shared systems (terminal/RDS servers, kiosks, shared workstations) where local attackers can run untrusted code. As interim mitigation, restrict execution of untrusted local applications on vulnerable hosts.

7.822% KEV
  • Microsoft Windows Multiple supported Windows releases (specific affected version ranges not enumerated in the source data; see Microsoft advisory for exact affected builds)
mass~1 billion+ Windows systems (NTFS is the default filesystem on virtually every Windows installation)
Full article733 words · extracted from therecord.media · click to collapse

The operators of the Magnitude exploit kit have added support for an attack chain targeting the Chrome web browser, a rare sighting since the very few exploit kits that are still active today have only targeted Internet Explorer over the past few years.

Exploit kits (EKs) are web applications installed on websites that work by detecting the user's browser and launching a web-based exploit to infect the visitor's computer with a payload (malware).

Exploit kits have been used by malware gangs since the late 2000s and were a crucial part of the malware ecosystem in the first half of the 2010s.

Together with email spam, exploit kits were the two most common ways that malware groups targeted and infected users for more than a decade, being used in both cybercrime operations but also by nation-state cyber-espionage efforts.

Their usage began to decline in the late 2010s because of several law enforcement crackdowns against some EK operators and as browser vendors started adding security features to prevent easy exploitation by EK operators.

All in all, EKs have barely had any significant impact on the cybersecurity landscape since 2017, but that hasn't stopped some threat actors from developing new ones.

Over the past four years, several exploits kits like Spelevo, Fallout, RIG, Underminer, RouterEK, and Magnitude have been released, and most of these have been fringe players on the threat landscape.

During that time, EK operators also lost their best programmers who left to work with other cybercrime operators. For the past few years, instead of researching and deploying their own custom zero-day exploits, most EKs have limited themselves to integrating publicly disclosed vulnerabilities into their exploit arsenals.

Throughout recent years, EK operators only focused on attacking Internet Explorer users, as attacks against more modern browsers usually involved two or three-step exploit chains, which operators could rarely develop on their own or get their hands on.

Right now, Magnitude is one of the most active EKs on the market, regularly seeing updates (in the form of rather new IE exploits) added to its arsenal (see 20202021 reports).

Magnitude adds PuzzleMaker's exploit chain

But today, security firm Avast said it found a new exploit chain in the Magnitude codebase that allows it to target Chrome users, something that hasn't been seen in ages for an EK and considered a holy grail for EK operators since this allows them to target most of today's web users.

#MagnitudeEK is now stepping up its game by using CVE-2021-21224 and CVE-2021-31956 to exploit Chromium-based browsers. This is an interesting development since most exploit kits are currently targeting exclusively Internet Explorer, with Chromium staying out of their reach.

— Avast Threat Labs (@AvastThreatLabs) October 19, 2021

According to Avast, the exploit chain utilizes a Chrome vulnerability patched in April (CVE-2021-21224) to escape the browser's security sandbox and a Windows elevation of privilege patched in June (CVE-2021-31956) to attack the underlying operating system.

While proof-of-concept code has been available for the Chrome exploit since April, code for the Windows bug was never publicly released.

But Avast also points out that this exact same combination of a Chrome and Windows exploit chain was also seen before, earlier this year, in a cyber-espionage campaign discovered by Kaspersky.

Called PuzzleMaker, Kaspersky said the exploit chain didn't have any connections to any previously known threat actor, was hidden inside a legitimate-looking geopolitical news portal, and described the entire operation as "a wave of highly targeted attacks against multiple companies."

Although Avast's discovery is important because of a rare sighting of an exploit kit going after Chrome and Chromium-related browsers, other questions still remain, such as how did a quasi-dead EK group get its hands on such a high-grade exploit chain and how effective is the exploit chain to begin with.

But there's also good news, in the sense that the Windows exploit is not universal and will only work against a small number of Windows 10 versions.

"The attacks we have seen so far are targeting only Windows builds 18362, 18363, 19041, and 19042 (19H1–20H2). Build 19043 (21H1) is not targeted," Avast researchers said.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/exploit-kit-adds-rare-chrome-browser-attack-chain