ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-29256
Use-After-Free in Arm Mali GPU Kernel Driver Allows Root Privilege Escalation

The Arm Mali GPU kernel driver (Bifrost, Valhall, and Midgard variants) contains a use-after-free flaw (CWE-416) that allows an unprivileged user to access freed kernel memory. An attacker triggers the bug from a low-privileged process on a device running a vulnerable Mali driver revision, and gains information disclosure and, in many cases, root privilege escalation. Affected ranges are Bifrost r16p0 through r29p0, Valhall r19p0 through r29p0, and Midgard r28p0 through r30p0, which are deployed across a very large base of Android smartphones, tablets, TV boxes, and other embedded devices. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-07-07), indicating observed exploitation in the wild, though ransomware use is unknown and no public proof-of-concept is available. EPSS assigns a 3.0% probability of exploitation in the next 30 days (87th percentile).

Do: Upgrade the Mali GPU kernel driver: Bifrost and Valhall to r30p0 or later, and Midgard to a release later than r30p0, or apply the equivalent patch delivered by your SoC/OS vendor (e.g., Android security bulletin updates, as referenced in recent Google patch releases). Check the Mali driver revision on affected devices and prioritize patching because the flaw is on CISA's KEV list as actively exploited. As an interim mitigation, avoid running untrusted local code on devices that still run vulnerable Mali driver versions.

8.83% KEV
  • Arm Mali Bifrost GPU kernel driver r16p0 through r29p0 (before r30p0)
  • Arm Mali Valhall GPU kernel driver r19p0 through r29p0 (before r30p0)
  • Arm Mali Midgard GPU kernel driver r28p0 through r30p0
masshundreds of millions of devices (Mali GPUs are integrated in a large share of Android and embedded SoCs)
CVE-2023-20862
In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean

In Spring Security, versions 5.7.x prior to 5.7.8, versions 5.8.x prior to 5.8.3, and versions 6.0.x prior to 6.0.3, the logout support does not properly clean the security context if using serialized versions. Additionally, it is not possible to explicitly save an empty security context to the HttpSessionSecurityContextRepository. This vulnerability can keep users authenticated even after they performed logout. Users of affected versions should apply the following mitigation. 5.7.x users should upgrade to 5.7.8. 5.8.x users should upgrade to 5.8.3. 6.0.x users should upgrade to 6.0.3.

NVD description · AI analysis pending
6.3<1%
  • vmware spring security
  • vmware active iq unified manager
CVE-2023-2136
Skia Integer Overflow Sandbox Escape in Google Chrome

An integer overflow (CWE-190) in Skia, the 2D graphics library used by Chrome's renderer, can be triggered by a crafted HTML page whose content drives Skia processing past the limits of its integer math. A remote attacker who has already compromised the Chrome renderer process — for example through a separate renderer flaw or a malicious page — can leverage the overflow to escape Chrome's renderer sandbox and gain broader code execution on the host. All Google Chrome and Chromium users running versions prior to 112.0.5615.137 are affected, including Chromium packages shipped by Debian and Fedora. The flaw is rated Critical (CVSS 3.1: 9.6) and carries Chromium security severity High, with an EPSS probability of 5.7% (93rd percentile) of exploitation within 30 days. It was added to CISA's Known Exploited Vulnerability catalog on 2023-04-21, and news reports describe it as an actively exploited Chrome zero-day for which Google rushed out the 112.0.5615.137 patch.

Do: Update Google Chrome to 112.0.5615.137 or later on all platforms, and install the corresponding Chromium security updates on Debian and Fedora systems. Because exploitation requires user interaction with a crafted page plus a pre-existing renderer compromise, prompt patching is the primary mitigation; verify via CISA KEV required actions that all managed browsers are updated and confirm Chrome versions in endpoint inventory.

9.66% KEV
  • Google Chrome all versions prior to 112.0.5615.137
  • Google Chromium Chromium builds with Skia code prior to the fix delivered in 112.0.5615.137
  • Debian Linux (chromium package)
  • +1 more
masson the order of billions of Chrome/Chromium users worldwide (~3+ billion installations; ~65% browser market share)
CVE-2023-26083
Memory Leak Information Disclosure in Arm Mali GPU Kernel Drivers

A memory leak (CWE-401) in Arm's Mali GPU kernel drivers affects Midgard (all versions r6p0-r32p0), Bifrost (all versions r0p0-r42p0), Valhall (all versions r19p0-r42p0), and Avalon (r41p0-r42p0), allowing a non-privileged local user to perform valid GPU processing operations that expose sensitive kernel metadata. A local attacker or app on an affected device gains an information-disclosure primitive that reads otherwise protected kernel memory (CVSS 3.1 base score 3.3, confidentiality impact only), potentially aiding further attacks. Exposure applies to any device whose CPU incorporates an affected Mali GPU and runs the corresponding driver, most commonly Android smartphones and tablets built on licensed Mali designs. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2023-04-07), indicating active exploitation, and Arm has issued patched drivers, with fixes also delivered through vendor/Android update channels; ransomware use is unknown.

Do: Apply Arm's patched Mali kernel driver releases (versions beyond the affected ranges) via your SoC/OEM vendor, and on Android devices install the latest Google/OEM security updates, per CISA's required action. Inventory fleets for devices running affected Mali driver generations (Android phones, tablets, and embedded/edge devices) and confirm they receive the fixed driver; note that patching is mandatory for U.S. federal agencies under the KEV program despite the low severity of this local information-disclosure flaw.

3.31% KEV
  • Arm Midgard GPU Kernel Driver all versions r6p0 through r32p0
  • Arm Bifrost GPU Kernel Driver all versions r0p0 through r42p0
  • Arm Valhall GPU Kernel Driver all versions r19p0 through r42p0
  • +2 more
masshundreds of millions of devices (order of magnitude 10^8-10^9) with licensed Mali GPUs and affected driver versions
CVE-2023-32049
+3 in the same advisory: …36884 …36874 …32046
Windows SmartScreen Security Feature Bypass Exploited in the Wild (CVE-2023-32049)

CVE-2023-32049 is a security feature bypass in Microsoft Windows Defender SmartScreen, the mechanism that warns users before they run downloaded or untrusted content; specially crafted content delivered over the network causes SmartScreen to skip that warning when a user opens it. The flaw requires user interaction (CVSS vector AV:N/AC:L/UI:R), so attackers must lure a victim into clicking or opening the crafted URL or file, and in exchange they gain the ability to run content without the expected SmartScreen prompt, typically as a link in a chain that delivers malware or establishes initial access. All users of Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2016/2019/2022 are affected. The flaw was fixed in Microsoft's July 2023 Patch Tuesday batch (132 vulnerabilities, six under active attack) and was added to CISA's Known Exploited Vulnerabilities catalog on 2023-07-11, confirming in-the-wild exploitation; no public proof-of-concept is known and ransomware use is unknown.

Do: Apply Microsoft's July 2023 (or later) cumulative Windows security updates on every affected Windows 10, Windows 11, and Windows Server release, per the vendor instructions and CISA KEV required action. After patching, verify SmartScreen and Mark-of-the-Web warning behavior remain enabled and intact, and prioritize fleet-wide rollout given confirmed in-the-wild exploitation; treat unpatched users as susceptible to warning-free delivery of malicious files and links.

8.8
group max
4% KEV
  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2
  • Microsoft Windows Server 2016, 2019, 2022
masshundreds of millions of endpoints and servers (the affected Windows 10/11 and Server releases make up the large majority of the supported Windows installed…
CVE-2023-33987
An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, W

An unauthenticated attacker in SAP Web Dispatcher - versions WEBDISP 7.49, WEBDISP 7.53, WEBDISP 7.54, WEBDISP 7.77, WEBDISP 7.81, WEBDISP 7.85, WEBDISP 7.88, WEBDISP 7.89, WEBDISP 7.90, KERNEL 7.49, KERNEL 7.53, KERNEL 7.54 KERNEL 7.77, KERNEL 7.81, KERNEL 7.85, KERNEL 7.88, KERNEL 7.89, KERNEL 7.90, KRNL64NUC 7.49, KRNL64UC 7.49, KRNL64UC 7.53, HDB 2.00, XS_ADVANCED_RUNTIME 1.00, SAP_EXTENDED_APP_SERVICES 1, can submit a malicious crafted request over a network to a front-end server which may, over several attempts, result in a back-end server confusing the boundaries of malicious and legitimate messages. This can result in the back-end server executing a malicious payload which can be used to read or modify information on the server or make it temporarily unavailable.

NVD description · AI analysis pending
9.4<1%
  • sap web dispatcher
CVE-2023-33989
An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to ov

An attacker with non-administrative authorizations in SAP NetWeaver (BI CONT ADD ON) - versions 707, 737, 747, 757, can exploit a directory traversal flaw to over-write system files. Data from confidential files cannot be read but potentially some OS files can be over-written leading to system compromise.

NVD description · AI analysis pending
8.1<1%
  • sap netweaver bi content
CVE-2023-3519
Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway

CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations.

Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise.

9.8100% KEV ransomware PoC
  • Citrix NetScaler ADC Supported releases before the July 2023 fixes, per Citrix advisory: 14.1 before 14.1-8.50; 13.1 before 13.1-49.13; 13.0 before 13.0-82.45; 12.1 before 12.1-55.3
  • Citrix NetScaler Gateway Same affected builds as NetScaler ADC (before 14.1-8.50, 13.1-49.13, 13.0-82.45, 12.1-55.300, and FIPS/NDcPP equivalents); affected when the appliance serves as
largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream…
CVE-2023-36922
Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary oper

Due to programming error in function module and report, IS-OIL component in SAP ECC and SAP S/4HANA allows an authenticated attacker to inject an arbitrary operating system command into an unprotected parameter in a common (default) extension. On successful exploitation, the attacker can read or modify the system data as well as shut down the system.

NVD description · AI analysis pending
8.8<1%
  • sap netweaver
CVE-2023-37201
+3 in the same advisory: …37202 …37211 …37212
An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS.

An attacker could have triggered a use-after-free condition when creating a WebRTC connection over HTTPS. This vulnerability affects Firefox < 115, Firefox ESR < 102.13, and Thunderbird < 102.13.

NVD description · AI analysis pending
8.8<1%
  • mozilla firefox
  • mozilla firefox esr
  • mozilla thunderbird
  • +1 more
CVE-2023-3732
+3 in the same advisory: …3730 …3728 …3727
Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially ex

Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer process to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

NVD description · AI analysis pending
8.81%
  • google chrome
CVE-2023-37450
Arbitrary Code Execution in Apple WebKit (iOS, iPadOS, macOS, Safari, tvOS, watchOS)

CVE-2023-37450 is a high-severity (CVSS 8.8) arbitrary code execution vulnerability in Apple's WebKit browser engine, affecting iOS, iPadOS, Safari, macOS Ventura, tvOS, watchOS, and WebKitGTK. It is triggered when an affected device processes maliciously crafted web content — for example, when a user is lured into visiting an attacker-controlled webpage (user interaction is required, hence the UI:R CVSS vector). Successful exploitation grants the attacker arbitrary code execution within the web-content/browser context, the typical entry point for full iPhone, iPad, or Mac compromise chains. Anyone running iPhone OS/iPadOS earlier than 16.6, Safari earlier than 16.5.2, macOS Ventura earlier than 13.5, tvOS earlier than 16.6, watchOS earlier than 9.6, or unpatched WebKitGTK builds is affected. Apple reports the issue may have been actively exploited before it was patched, CISA added it to the KEV catalog on 2023-07-13, and EPSS assigns an 18.9% probability (97th percentile) of exploitation over the next 30 days.

Do: Upgrade immediately to iOS 16.6 / iPadOS 16.6, Safari 16.5.2, macOS Ventura 13.5, tvOS 16.6, and watchOS 9.6, or apply the latest available patch for older OS branches on devices that cannot take the 16.x/Ventura updates; this is a CISA KEV entry with a federal remediation requirement. Because exploitation occurs through normal web browsing, patching is the only reliable mitigation — avoid untrusted websites as an interim measure. WebKitGTK users should update to the latest patched WebKitGTK release and verify that dependent applications have been rebuilt against the fixed library.

8.819% KEV
  • Apple iOS (iPhone OS) All versions prior to iOS 16.6
  • Apple iPadOS All versions prior to iPadOS 16.6
  • Apple Safari All versions prior to Safari 16.5.2
  • +4 more
mass≈2 billion active Apple devices (WebKit is the web engine for iOS/iPadOS, Safari, tvOS and watchOS); no public counts of exploited devices are known
Full article1,248 words · extracted from arstechnica.com · click to collapse

fixing flaws

July saw two high-severity bugs in Firefox, while Oracle patched over 500 vulnerabilities.

The summer patch cycle shows no signs of slowing down, with tech giants Apple, Google, and Microsoft releasing multiple updates to fix flaws being used in real-life attacks. July also saw serious bugs squashed by enterprise software firms SAP, Citrix, and Oracle.

Here’s everything you need to know about the major patches released during the month.

Apple iOS and iPadOS 16.6

Apple had a busy July after issuing two separate security updates during the month. The iPhone maker’s first update came in the form of a security-only Rapid Security Response patch.

Wired logo

It was only the second time Apple had issued a Rapid Security Response, and the process was not as smooth as the first. On July 10, Apple released iOS 16.5.1 9 (a) to fix a single WebKit flaw already being used in attacks, but the iPhone maker quickly retracted it after discovering that the patch broke several websites for users. Apple reissued the update as iOS 16.5.1 (c) a few days later, at last fixing the WebKit issue without breaking anything else.

Later in the month, Apple’s major point upgrade iOS 16.6 appeared with 25 security fixes, including the already exploited WebKit bug patched in iOS 16.5.1 (c), tracked as CVE-2023-37450.

Among the other bugs squashed in iOS 16.6 are 11 in the Kernel at the core of the iOS operating system, one of which Apple said is already being used in attacks. The Kernel flaw is the third iOS issue discovered by security outfit Kaspersky as part of the zero-click “Triangulation spyware” attacks.

Apple also released iOS 15.7.8 for users of older devices, as well as iPadOS 16.6, Safari 16.6, macOS Ventura 13.5, macOS Monterey 12.6.8, macOS Big Sur 11.7.9, tvOS 16.6, and watchOS 9.6.

Microsoft

Microsoft’s July Patch Tuesday is an update to look out for because it fixes 132 vulnerabilities, including multiple zero-day flaws. First things first: One of the bugs detailed in the patch update, tracked as CVE-2023-36884, has not yet been fixed. In the meantime, the tech giant has offered steps to mitigate the already exploited flaw, which has apparently been used in attacks by a Russian cybercrime gang.

Other zero-day flaws included in Microsoft’s Patch Tuesday are CVE-2023-32046, a platform elevation of privilege bug in the MSHTML core Windows component, and CVE-2023-36874, a vulnerability in the Windows Error Reporting service that could allow an attacker to gain admin rights. Meanwhile, CVE-2023-32049 is an already exploited vulnerability in the Windows SmartScreen feature.

It goes without saying that you should update as soon as possible while keeping an eye out for the fix for CVE-2023-36884.

Google Android

Google has updated its Android operating system, fixing dozens of security vulnerabilities, including three it says “may be under limited, targeted exploitation.”

The first of the already exploited vulnerabilities is CVE-2023-2136, a remote code execution (RCE) bug in the System with a CVSS score of 9.6. The critical security vulnerability could lead to RCE with no additional privileges needed, according to the tech firm. “User interaction is not needed for exploitation,” Google warned.

CVE-2023-26083 is an issue in Arm Mali GPU driver for Bifrost, Avalon, and Valhall chips, rated as having a moderate impact. The vulnerability was used to deliver spyware to Samsung devices in December 2022.

CVE-2021-29256 is a high-severity flaw that also impacts Bifrost and Midgard Arm Mali GPU kernel drivers.

The Android updates have already reached Google’s Pixel devices and some of Samsung’s Galaxy range. Given the severity of this month’s bugs, it’s a good idea to check whether the update is available and install it now.

Google Chrome 115

Google has issued the Chrome 115 update for its popular browser, fixing 20 security vulnerabilities, four of which are rated as having a high impact. CVE-2023-3727 and CVE-2023-3728 are use-after-free bugs in WebRTC. The third flaw rated as having a high severity is CVE-2023-3730, a use-after-free vulnerability in Tab Groups, while CVE-2023-3732 is an out-of-bounds memory access bug in Mojo.

Six of the flaws are listed as having a medium severity, and none of the vulnerabilities are known to have been used in real-life attacks. Even so, Chrome is a highly targeted platform, so check your system for updates.

Firefox 115

Hot on the heels of Chrome 115, rival browser Mozilla has released Firefox 115, fixing several flaws it rates as having high severity. Among these are two use-after-free bugs tracked as CVE-2023-37201 and CVE-2023-37202.

The privacy-conscious browser maker also fixed two memory safety bugs tracked as CVE-2023-37212 and CVE-2023-37211. The memory safety flaws are present in Firefox 114, Firefox ESR 102.12, and Thunderbird 102.12, Mozilla said in an advisory, adding: “Some of these bugs showed evidence of memory corruption, and we presume that with enough effort some of these could have been exploited to run arbitrary code.”

Citrix

Enterprise software giant Citrix has issued an update warning after fixing multiple flaws in its NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) tools, one of which has already been used in attacks.

Tracked as CVE-2023-3519, the already exploited flaw is an unauthenticated remote code execution vulnerability in NetScaler ADC and NetScaler Gateway that’s so severe it’s been given a CVSS score of 9.8. “Exploits of CVE-2023-3519 on unmitigated appliances have been observed,” Citrix said. “Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible.”

The flaw was also the subject of an advisory from the US Cybersecurity and Infrastructure Security Agency (CISA), which warned that the bug was used in attacks on a critical infrastructure organization in June.

SAP

SAP, another enterprise software firm, has issued its July Security Patch Day, including 16 security fixes. The most severe flaw is CVE-2023-36922, an OS command injection vulnerability with a CVSS score of 9.1.

The bug allows an authenticated attacker to “inject an arbitrary operating system command into a vulnerable transaction and program,” security firm Onapsis said. “Patching is strongly recommended, since a successful exploit of this vulnerability has a high impact on confidentiality, integrity, and availability of the affected SAP system,” it warned.

Meanwhile, CVE-2023-33989 is a directory traversal vulnerability in SAP NetWeaver with a CVSS score of 8.7, and CVE-2023-33987 is a request smuggling and request concatenation vulnerability in SAP Web Dispatcher with a CVSS score of 8.6.

Oracle

Software company Oracle has released its July Critical Patch Update Advisory, fixing 508 vulnerabilities in its products. Among the fixes are 77 new security patches for Oracle Communications. Oracle warned that 57 of these vulnerabilities could be remotely exploited over a network without user credentials. One of the worst flaws is CVE-2023-20862, which has been given a CVSS score of 9.8.

Meanwhile, 147 of the Oracle patches were for Financial Services, and Fusion Middleware received 60 fixes.

Oracle said it continues to receive reports of attempts to exploit vulnerabilities it has already patched. In some cases, attackers were successful because targeted customers had failed to apply available Oracle patches, it said. “Oracle, therefore, strongly recommends that customers remain on actively supported versions and apply Critical Patch Update security patches without delay.”

This story originally appeared on wired.com

Wired.com is your essential daily guide to what's next, delivering the most original and complete take you'll find anywhere on innovation's impact on technology, science, business and culture.

12 Comments

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/08/bug-squashing-summer-a-months-worth-of-0-day-fixes-among-tech-giants/