ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2010-3333
Stack Buffer Overflow in Microsoft Office RTF Parsing Allows Remote Code Execution

CVE-2010-3333 is a stack-based buffer overflow in the way Microsoft Office parses RTF (Rich Text Format) data. An attacker triggers it by convincing a user to open a specially crafted RTF file, including an RTF email that is handed to Office for rendering, with no authentication required beyond the user's action. Successful exploitation allows remote code execution in the context of the logged-on user, giving the attacker a foothold on the workstation. Any Microsoft Office installation within the affected range identified in the December 2012 Microsoft security bulletin is exposed; the source data does not enumerate specific version numbers. The flaw is actively exploited: it is on the CISA Known Exploited Vulnerabilities catalog (added 2022-03-03, ransomware association unknown) and was used in targeted espionage, notably Kaspersky's 'Red October' campaign, with EPSS estimating an 89.5% probability of exploitation within 30 days (100th percentile).

Do: Apply the Microsoft updates from the December 2012 security bulletin that fixes this RTF parsing flaw across all Office/Word installations, prioritized given the ~90% EPSS score and CISA KEV listing. As interim mitigation, block or inspect inbound RTF attachments at email gateways and configure Outlook to read email in plain text so RTF content does not open automatically in Office. Inventory legacy or unpatched Office installations that may have missed the 2012 update, since these remain the likely current exposure.

89% KEV
  • Microsoft Office
masshundreds of millions of Office users/installations at time of disclosure (current unpatched legacy installs unknown)
CVE-2012-0158
Remote Code Execution in Microsoft MSCOMCTL.OCX (Windows Common Controls)

CVE-2012-0158 is a remote code execution flaw in Microsoft's MSCOMCTL.OCX, the Windows Common Controls ActiveX component, where improper handling of crafted input allows memory corruption and code execution. It is typically triggered when an application that uses the control (most commonly Microsoft Office) processes specially crafted content, such as a malicious document or file, meaning a victim usually has to open attacker-supplied content. Successful exploitation lets an attacker run arbitrary code and take complete control of the affected system with the privileges of the current user. Any Windows system carrying a vulnerable copy of MSCOMCTL.OCX — including systems where the control was redistributed by legacy applications — is affected, which makes the potential population very large. Exploitation is confirmed and ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with known ransomware use, and EPSS assigns it the maximum reported probability of exploitation within 30 days.

Do: Apply the Microsoft security update for MSCOMCTL.OCX (per vendor instructions, per CISA's required action) on all systems, prioritizing endpoints and servers that open Office documents. Because exploitation commonly arrives via malicious documents, treat unsolicited Office/RTF attachments with suspicion and verify that applications that redistribute MSCOMCTL.OCX have installed a patched copy. Scan the estate for the presence and version of MSCOMCTL.OCX, especially on legacy Windows/Office installations that may be missed by routine patching.

100% KEV ransomware
  • Microsoft MSCOMCTL.OCX
masshundreds of millions of Windows systems potentially affected
CVE-2013-1347
Memory corruption RCE in Microsoft Internet Explorer

CVE-2013-1347 is a memory-corruption vulnerability in Microsoft Internet Explorer (listed under CWE-94, code injection) that corrupts memory in a way that allows an attacker to execute arbitrary code in the security context of the logged-on user. The flaw is triggered remotely through Internet Explorer, typically by luring a user to attacker-controlled web content; related threat-intelligence coverage ties it to the LightsOut Exploit Kit used in APT28 (Pawn Storm) campaigns and to Microsoft's Update Tuesday release for IE 8. Successful exploitation yields code execution with the current user's privileges, meaning full system compromise on accounts with administrative rights. Any environment where users browse with the affected Internet Explorer versions is exposed — CISA lists 'Microsoft Internet Explorer' without enumerating a version range, while related vendor coverage highlights an IE 8 update, putting legacy Windows estates still running IE 8-era browsers at highest risk. Exploitation is confirmed in the wild: the CVE was added to CISA KEV on 2022-03-03 and carries a 77.9% EPSS (100th percentile), although ransomware use is unknown and no standalone public PoC is listed.

Do: Apply Microsoft's Internet Explorer updates per vendor instructions (the CISA-required action), prioritizing this KEV-listed vulnerability. Inventory legacy Windows systems still running IE 8-era browsers and either migrate those users to a supported browser or restrict untrusted web browsing from those systems, since this is a drive-by browser exploit that executes with the current user's privileges. Verify patch levels across all IE versions in the estate rather than assuming updates propagated.

78% KEV
  • Microsoft Internet Explorer
mass≈ hundreds of millions of endpoints/users at the time of disclosure, with residual exposure concentrated in legacy IE 8-era estates today
CVE-2013-3897
Use-After-Free RCE in Microsoft Internet Explorer (CVE-2013-3897)

CVE-2013-3897 is a use-after-free vulnerability in the CDisplayPointer component of Microsoft Internet Explorer that enables remote code execution when a user views attacker-controlled web content. It is triggered by luring a user to a malicious or compromised webpage where Internet Explorer references memory that has already been freed, allowing the attacker to corrupt memory and execute arbitrary code with the rights of the logged-on user. Any user or organization browsing with Internet Explorer on Windows was exposed; the flaw was fixed in Microsoft's October 2013 Patch Tuesday cumulative IE security updates, and because Internet Explorer is now retired, remaining exposure sits on legacy Windows estates and IE-dependent legacy web applications. Exploitation is confirmed: the bug was exploited as a zero-day in targeted attacks when disclosed in late September 2013, it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS estimates a 77.5% probability of exploitation within 30 days (100th percentile). No public proof-of-concept exploit is documented in the source data, but confirmed in-the-wild use makes patching or browser migration urgent.

Do: Apply Microsoft's October 2013 Patch Tuesday cumulative Internet Explorer security update (MS13-080) per vendor/CISA instructions, prioritizing internet-facing and legacy Windows hosts where IE is still used for browsing or legacy web applications. Because IE is retired and no longer receives security fixes, migrate any remaining IE-dependent users to a supported modern browser and hunt for indicators of the historical in-the-wild exploitation. Ransomware use is unknown per the KEV entry and no public PoC is available, so treat patching and migration, not signature detection, as the primary control.

77% KEV
  • Microsoft Internet Explorer
masshundreds of millions of legacy Windows systems with Internet Explorer historically (IE shipped with essentially every Windows PC); current active exposure is…
CVE-2013-3906
Memory Corruption RCE in Microsoft Graphics Component (Actively Exploited)

Microsoft's Graphics Component contains a memory corruption vulnerability that can allow remote code execution when the component processes maliciously crafted graphics content, typically delivered inside documents or other rendered content. An attacker who successfully triggers the flaw gains the ability to execute arbitrary code on the target system in the context of the current user, inheriting that user's privileges. Any Microsoft Windows system running an affected version of the Graphics Component is exposed, since the component is part of the Windows platform and is reachable through normal document and image rendering. The flaw was exploited as a zero-day in targeted attacks — notably by the Sandworm threat group against Ukrainian government and NATO-related targets, per iSight Partners reporting — and was addressed in Microsoft's December 2013 security updates. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-15, and EPSS currently assigns an 85% probability of exploitation within 30 days (100th percentile).

Do: Apply the vendor's December 2013 security updates covering the Graphics Component (MS13-098) to all Windows systems, prioritizing legacy machines that may have never received the patch, and verify KEV remediation compliance if you are a federal agency. Because exploitation vectors historically involved malicious document rendering, reinforce email filtering and Office attack-surface reduction (e.g., blocking untrusted embedded graphics/objects) on any systems that remain unpatched.

85% KEV
  • Microsoft Graphics Component
mass≈1 billion+ Windows installations carried the component at the time of disclosure; residual exposure is limited to systems never patched with the December 2013…
CVE-2014-1776
Use-After-Free Memory Corruption RCE in Microsoft Internet Explorer

CVE-2014-1776 is a use-after-free memory corruption flaw in Microsoft Internet Explorer that can be triggered when the browser processes specially crafted web content, corrupting memory in a manner an attacker controls. A remote attacker can deliver the malicious content from a site they host or inject it into a compromised/legitimate website, causing Internet Explorer to access freed memory under attacker control. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker that user's privileges on the client machine. Any organization or user running an affected version of Internet Explorer is exposed, and the flaw has been associated with highly targeted attack activity, including the FireEye-documented zero-day exploit in the wild and the targeted Pirpi-distributed 0-day. The vulnerability was exploited in the wild as a zero-day, was addressed by Microsoft updates, and was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-01-28; no public proof-of-concept is known.

Do: Apply Microsoft's Internet Explorer security updates per vendor instructions, prioritizing this as a KEV-required remediation, and verify all workstations still launching IE or legacy MSHTML-based content are patched. Reduce residual exposure by steering users away from Internet Explorer for untrusted sites and auditing intranet applications and tooling for lingering IE dependencies. Because the exact affected versions are not in the data, cross-check Microsoft's advisory to confirm your deployed IE versions are covered by the fix.

88% KEV
  • Microsoft Internet Explorer
mass≈ hundreds of millions of users/endpoints (IE held roughly half of global browser market share when exploited in 2014)
CVE-2015-1641
Memory Corruption RCE in Microsoft Office via Malicious RTF Files

Microsoft Office contains a memory corruption flaw (CWE-399) in its handling of Rich Text Format (RTF) files, allowing a crafted RTF document to corrupt memory when the file is parsed. The flaw is triggered by opening a specially crafted RTF file — typically delivered as an email attachment — in an affected version of Microsoft Office. Successful exploitation yields remote code execution in the context of the current user, so attacker privilege is limited to the rights of the logged-in account. Per the CISA data, Microsoft Office is the affected product, with no specific version ranges provided; the flaw was fixed in Microsoft's April 2015 Patch Tuesday security updates (MS15-033), so risk is concentrated on systems that never applied those updates. Exploitation is confirmed in the wild — the CVE was added to the CISA KEV on 2021-11-03 (ransomware use unknown) — it carries a 96.8% EPSS probability of exploitation within 30 days (100th percentile), and related reporting links RTF exploit techniques of this era to targeted APT campaigns (e.g., the T9000 backdoor and DragonOK tooling).

Do: Apply Microsoft's April 2015 Office security updates (MS15-033) on all endpoints, per the CISA KEV required action, prioritizing hosts running older Office editions, and verify installation via installed-updates checks. As interim hardening, treat inbound RTF files with suspicion (block or sandbox RTF email attachments) and monitor for suspicious child processes spawned by Word (e.g., Winword.exe launching cmd.exe or PowerShell) to detect possible prior exploitation. Organizations still on legacy Office versions should upgrade to currently supported editions that receive ongoing security updates.

97% KEV
  • Microsoft Office
masshundreds of millions of Office installations potentially affected (unpatched subset unknown)
CVE-2015-1642
Memory Corruption RCE in Microsoft Office via Crafted Documents

CVE-2015-1642 is a memory corruption flaw in Microsoft Office (CWE-119) that allows remote attackers to execute arbitrary code by convincing a user to open a specially crafted document. Because the corruption can be triggered simply by processing a malicious file, an attacker who succeeds gains code execution in the context of the logged-in user, with the privileges of that user on the workstation. Any organization or individual running an affected version of Microsoft Office is exposed, primarily through email attachments and documents downloaded from the web. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2022-03-03 — notably years after its 2015 disclosure — with a required action to apply vendor updates, and the ~53% EPSS score (99th percentile) indicates a high likelihood of exploitation within 30 days. Related reporting on APT28 attack evolution suggests exploitation has been observed in targeted campaigns; ransomware use is unknown, and no public proof-of-concept is cataloged.

Do: Apply the vendor's security updates for Microsoft Office per CISA's KEV required action, using Microsoft Update or your organization's Office/patch management channel to confirm current, fully patched builds. Prioritize this KEV-listed item in patch cycles, and review endpoint telemetry for suspicious process launches following Office document opens. In the interim, caution users against opening unsolicited Office documents and consider attack-surface-reduction policies that block unsafe file types or Office child processes.

53% KEV
  • Microsoft Office
massplausibly tens to hundreds of millions of Office installations worldwide
CVE-2015-1701
Local Privilege Escalation in Microsoft Windows Win32k.sys Kernel-Mode Driver

CVE-2015-1701 is a local elevation-of-privilege vulnerability in Win32k.sys, the Windows kernel-mode driver, that allows a local attacker to execute arbitrary code with kernel-level (SYSTEM) privileges. It is triggered by running a specially crafted application on an affected Windows system, where mishandled user-mode objects in the kernel let the attacker escape a limited user context. An attacker who already has a normal user foothold can escalate to full system rights, enabling persistence and lateral movement; in documented campaigns it was chained with other exploits to move from remote code execution to complete system compromise. Any unpatched Microsoft Windows installation carrying the vulnerable Win32k.sys is affected; the CISA description explicitly cites Microsoft Windows Server, and this kernel-mode driver ships with Microsoft's Windows server and client releases. Exploitation is confirmed in the wild: CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2022-03-03 with known ransomware use, and the 56.2% EPSS (99th percentile) indicates a high probability of exploitation in the next 30 days; no public PoC is known.

Do: Apply Microsoft's Windows security update for this CVE (bulletin MS15-051, released with the April 2015 Patch Tuesday) on all Windows client and server systems, prioritizing servers, terminal services hosts, and any machine where untrusted users can execute code, and audit the estate for legacy systems still missing the fix. As an interim control where patching is delayed, restrict local code execution to trusted accounts, and hunt for post-compromise indicators given the flaw's use as a 2015 APT28 zero-day and its documented use in ransomware chains per the CISA KEV entry.

56% KEV ransomware
  • Microsoft Win32k.sys kernel-mode driver (Windows)
massmillions of unpatched legacy Windows systems (subset of the >1 billion Windows devices in use)
CVE-2015-2387
Local Privilege Escalation in Microsoft ATM Font Driver (ATMFD.DLL)

CVE-2015-2387 is a privilege escalation flaw in ATMFD.DLL, the Adobe Type Manager Font Driver that ships with Microsoft Windows Server. A local attacker triggers it by running a crafted application that feeds malicious data to the font driver, causing code to execute outside the user's intended privilege level. Successful exploitation lets an attacker who already has a foothold elevate from ordinary user rights to higher system privileges, enabling full compromise of the host. Affected systems are Windows Server deployments containing the ATM font driver that lack the vendor fix; because the attack requires local code execution, exposure is primarily to hosts where users or processes can run code. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03, confirming exploitation in the wild, and it carries a high EPSS of 35.1% (98th percentile); no public PoC is known and ransomware use is unconfirmed.

Do: Apply Microsoft updates per vendor instructions on all Windows Server systems, prioritizing legacy builds that may have missed the 2015-era font-driver patches, and verify the patched ATMFD.DLL on servers where users or applications can run code. Because exploitation requires local access, pair patching with restricting arbitrary local code execution and monitoring for post-compromise privilege escalation; federal agencies must remediate per the CISA KEV requirement.

35% KEV
  • Microsoft ATM Font Driver (ATMFD.DLL) on Windows Server
masshistorically millions of Windows systems (driver shipped as a default component); current unpatched count unknown
CVE-2015-2590
Remote Code Execution Vulnerability in Oracle Java SE and Java SE Embedded

CVE-2015-2590 is an unspecified vulnerability in Oracle's Java Runtime Environment (Java SE, and Java SE Embedded per CISA's naming) that allows a remote attacker to achieve remote code execution. Oracle did not publish technical details, so the exact trigger is unspecified, but the flaw is exploitable remotely through input processed by the affected Java runtime. Successful exploitation gives an attacker arbitrary code execution in the context of the Java process, typically compromising the affected application and potentially the underlying host. Any organization running affected, unpatched Oracle Java SE builds on desktops, servers, or embedded devices is in scope. The flaw is confirmed exploited in the wild (added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-03; ransomware use unknown), carries a 25.5% EPSS probability of exploitation within 30 days, and has no known public proof-of-concept.

Do: Inventory all Oracle Java SE and Java SE Embedded installations and update them to a patched release per Oracle's Critical Patch Update instructions, as CISA's required action directs. Remove or upgrade legacy Java runtimes that no longer receive updates, and uninstall or restrict browser/plugin-based Java where it is not needed. Prioritize internet-facing services and embedded Java deployments given confirmed in-the-wild exploitation.

25% KEV
  • Oracle Java SE
  • Oracle Java SE Embedded
masshundreds of millions of installations worldwide (Java SE is one of the most widely deployed software runtimes)
CVE-2015-3043
Memory Corruption RCE in Adobe Flash Player

CVE-2015-3043 is an out-of-bounds write (memory corruption) flaw in Adobe Flash Player that is triggered when the player processes specially crafted Flash content, such as a malicious SWF file delivered through a web browser or an embedded application. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running Flash, typically the logged-on desktop user. Any system running Adobe Flash Player, across browsers and operating systems at the time of disclosure, was affected; CISA notes the product is now end-of-life and should be disconnected if still in use. The vulnerability is known to be exploited in the wild: CISA added it to the KEV catalog on 2022-03-03, EPSS assigns it a 73.9% probability of exploitation within 30 days (99th percentile), and public reporting associates the technique with APT28 operations.

Do: No further patch will be issued since Flash Player is end-of-life: locate and fully uninstall Flash from systems in your inventory, and block or remove SWF content in legacy internal applications. Check for browsers or business applications that still load Flash via bundled or embedded runtimes and disable that functionality. Given its KEV listing, prioritize complete removal over compensating controls.

74% KEV
  • Adobe Flash Player
mass≈1 billion+ devices at the time of disclosure (Flash ran on ~99% of internet-connected PCs in 2015); far fewer end-of-life installs remain today
CVE-2015-4902
Oracle Java SE Deployment Integrity Vulnerability Exploited in the Wild

CVE-2015-4902 is an unspecified vulnerability in Oracle Java SE, tied to the Java Deployment component, that allows a remote attacker to affect the integrity of affected Java installations; Oracle published limited technical detail and no CVSS score has been assigned. It is triggered through Java's deployment machinery — historically the browser plugin and Java Web Start paths used to launch applets and Web Start content — so exploitation typically requires a user to run attacker-influenced Java content in an unpatched runtime. A successful attacker gains integrity impact (the ability to tamper with data or the deployment process), with the description indicating no confidentiality or availability impact. Anyone running Oracle Java SE builds predating the October 2015 Critical Patch Update is affected, particularly legacy desktop environments that still permit browser applets or Java Web Start. No public proof-of-concept is known, but CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2022-03-03 based on evidence of active exploitation, and EPSS currently estimates a 13.4% probability of exploitation activity within 30 days (96th percentile).

Do: Upgrade every Java SE installation to a build from the October 2015 Critical Patch Update or later (Java 8u65+, 7u91+, 6u105+); any currently supported Java release already contains this fix. Inventory endpoints and servers for legacy Java, and disable the Java browser plugin and Java Web Start where they are not needed, since the flaw resides in Java's deployment paths. Because this is CISA KEV-listed, federal agencies must apply vendor updates by the required action deadline — verify installed Java versions via software inventory or endpoint management tooling.

13% KEV
  • Oracle Java SE Prior releases of Java SE 6, 7 and 8, fixed in the October 2015 Critical Patch Update (6u105, 7u91, 8u65); all Java releases from that update onward include the
mass≈hundreds of millions of Java installations worldwide at disclosure; the currently unpatched legacy population is unknown but plausibly in the millions or fewer
CVE-2015-5119
Use-After-Free RCE in Adobe Flash Player (ActionScript 3 ByteArray)

CVE-2015-5119 is a use-after-free memory-corruption vulnerability (CWE-119) in the ActionScript 3 ByteArray class of Adobe Flash Player. It is triggered when Flash processes crafted ActionScript/SWF content — typically a malicious .swf loaded from a web page, advertisement, email attachment, or document — causing Flash to access already-freed memory in an attacker-controllable way. A successful attack gives the adversary remote code execution in the context of the user running Flash. Anyone with Adobe Flash Player installed was exposed; at disclosure Flash was on the vast majority of internet-connected desktops, and today risk is concentrated in legacy browsers, office/document tooling, industrial or enterprise applications, and other systems where Flash was never removed. Exploitation status: this flaw has long-standing in-the-wild use (related headlines tie the leaked Hacking Team Flash exploit to APT campaigns against Japanese, East Asian, and US Government targets and to top 2016 exploit kits), it is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03; ransomware use unknown), and EPSS assigns a 99.3% probability of exploitation within 30 days.

Do: Because Flash Player is end-of-life, CISA's required action is to disconnect it rather than patch: audit browsers, document/office tooling, and legacy or industrial applications for Flash dependencies and fully uninstall or disable Flash and any embedded SWF players. If a system must keep Flash temporarily, verify it runs a patched build from 2015 or later (Adobe's July 2015 emergency update, APSB15-16, addressed this flaw) and block untrusted SWF content via browser settings, email gateway, and web filtering. Prioritize cleanup on internet-facing endpoints and users who browse the web or open untrusted email attachments, the typical delivery route for this exploit.

99% KEV
  • Adobe Flash Player
mass≈ millions of legacy desktop installations
CVE-2015-7645
Arbitrary Code Execution in Adobe Flash Player via Crafted SWF Files

CVE-2015-7645 is a code execution vulnerability in Adobe Flash Player in which a remote attacker can execute arbitrary code by having the player process a maliciously crafted SWF (Flash) file. Triggering requires only that a user load attacker-supplied Flash content, for example by visiting a compromised or malicious website, opening a document that embeds Flash content, or receiving an SWF payload delivered through an exploit kit. Successful exploitation lets the attacker run arbitrary code in the context of the Flash process, typically enabling malware or ransomware installation and compromise of the user's account and data. Anyone running Adobe Flash Player when the flaw was disclosed in 2015 was affected, and because Flash has since reached end-of-life, any installations that remain in use are unpatched. Exploitation is confirmed in the wild: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-03) with known ransomware use, and its EPSS score of 65.6% (99th percentile) indicates a high probability of exploitation.

Do: Remove or disable Adobe Flash Player entirely, consistent with CISA's required action, which notes the product is end-of-life and should be disconnected if still in use; audit for legacy Flash instances in intranet applications, bundled enterprise software, and older browser configurations. If Flash cannot be removed, install the latest patched release available from Adobe for this vulnerability and ensure browsers block or sandbox SWF content. Given the confirmed ransomware use, prioritize hunting for exploitation on any systems where Flash remains installed.

66% KEV ransomware
  • Adobe Flash Player
mass≈1 billion+ users/devices at the time of disclosure (Flash then ran on nearly all desktops); the number of leftover unpatched installs today is unknown
CVE-2017-0144
Remote Code Execution in Microsoft SMBv1 (EternalBlue) affecting Windows and Siemens devices

CVE-2017-0144 is a remote code execution flaw in the SMBv1 server component of Microsoft Windows, commonly known as EternalBlue, and one of the SMB flaws fixed by Microsoft in the March 2017 MS17-010 bulletin. An attacker who can reach the SMB service over the network sends specially crafted packets that trigger memory corruption in the SMBv1 implementation, gaining the ability to execute arbitrary code on the target without user interaction. Successful exploitation yields full system compromise and has been heavily weaponized for wormable spread and ransomware delivery, notably via the leaked NSA exploit and in the WannaCry/NotPetya-era outbreaks, and the flaw has repeatedly been bundled into botnets and ransomware tooling since. Anyone running unpatched Windows Vista SP2 through Windows 10 1607 / Windows Server 2016 with SMBv1 enabled is affected, as are Siemens medical and laboratory devices (ACUSON ultrasound, syngo SC2000, Tissue Preparation System, VERSANT kPCR systems) whose firmware depends on SMBv1. Exploitation is actively ongoing: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-02-10) with known ransomware use, carries a 99.2% EPSS exploitation probability (100th percentile), and multiple public exploits and PoCs are available.

Do: Apply the Microsoft MS17-010 (March 2017) security updates on every listed Windows version and the corresponding Siemens firmware updates for ACUSON, syngo SC2000, Tissue Preparation System, and VERSANT kPCR devices, per CISA's required action to apply vendor updates. Where patching is not yet possible, disable SMBv1 or block inbound TCP 445 (and UDP 137/138) at network boundaries and isolate legacy/medical systems from the internet. Sweep exposed and legacy hosts for compromise indicators, including DOUBLEPULSAR implants delivered over SMB, as public tooling for detecting and neutralizing this implant is available.

8.899% KEV ransomware PoC ×6
  • microsoft Windows SMBv1 server (Server Message Block) Windows Vista SP2; Windows Server 2008 SP2; Windows Server 2008 R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012; Windows Server 2012 R2; Windows RT 8.1;
  • siemens ACUSON P300 firmware
  • siemens ACUSON P500 firmware
  • +6 more
massorder of hundreds of thousands of internet-exposed SMB endpoints, and millions of unpatched Windows systems when internal enterprise and medical-device…
CVE-2017-0262
Memory Corruption RCE in Microsoft Office 2010, 2013, and 2016

Microsoft Office 2010 SP2, Office 2013 SP1, and Office 2016 fail to properly handle objects in memory, creating a remote code execution condition when the software processes a specially crafted file. Triggering the flaw requires user interaction - the CVSS vector (AV:L, UI:R) indicates an attacker must get a user to open a malicious document, typically via a phishing email or similar file-delivery channel. Successful exploitation runs arbitrary code in the context of the current user, exposing the confidentiality, integrity, and availability of everything that account can access on the endpoint (CVSS 3.1: 7.8, High). Any organization running the affected Office versions is affected; the flaw was one of several Office zero-days fixed in Microsoft's May 2017 Patch Tuesday (distinct from CVE-2017-0261 and CVE-2017-0281) and was reportedly exploited by Russian APT actors (APT28/Sofacy) around that time. Exploitation is confirmed: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-02-10, and EPSS currently rates the 30-day exploitation probability at 81% (100th percentile), so unpatched endpoints should be treated as actively targeted.

Do: Apply Microsoft's May 2017 security updates for Office 2010 SP2, Office 2013 SP1, and Office 2016, per the CISA KEV required action, and verify through asset inventory that no endpoint is running an unpatched Office build. Because exploitation requires user interaction with a crafted file, harden email and attachment handling (block or detonate Office files from untrusted sources) and brief users on unsolicited documents. Office 2010 and 2013 have since reached end of support, so migrate any remaining deployments to a currently supported Office release.

7.881% KEV
  • Microsoft Office 2010 Service Pack 2
  • Microsoft Office 2013 Service Pack 1
  • Microsoft Office 2016
masstens to hundreds of millions of endpoints (Office 2010 SP2/2013 SP1/2016 dominated desktop deployments at disclosure; current unpatched count unknown)
CVE-2017-0263
Win32k Use-After-Free Local Privilege Escalation in Windows 7 through Server 2016

CVE-2017-0263 is a use-after-free flaw (CWE-416) in the Windows kernel-mode drivers (Win32k) that allows a locally authenticated user to elevate privileges. It is triggered by running a specially crafted application that mishandles kernel memory on Windows 7 SP1, Windows 8.1, Windows RT 8.1, Windows 10 1507/1511/1607/1703, and Windows Server 2008 SP2/R2 SP1, Server 2012 Gold/R2, and Server 2016. Successful exploitation yields kernel-level privileges, effectively giving an attacker full control of the host and making it a common link in chained attacks alongside other bugs; related 2017 reporting associated the flaw with Sofacy (APT28) activity. Any unpatched Windows installation of the affected releases is affected, including long-lived legacy desktops and servers. The flaw is confirmed exploited in the wild — it is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-02-10) — with two public PoC/exploit references and a ~10% EPSS probability of exploitation in the next 30 days (95th percentile).

Do: Apply Microsoft security updates per vendor instructions - this Win32k bug was fixed in the April 2017 Patch Tuesday release - prioritizing hosts where untrusted or low-privileged users can execute code (terminal/VDI servers, shared workstations, jump hosts). Windows 7/8.1 and Server 2008/2012 are past end of extended support, so use Extended Security Updates or migrate where patching in place is not possible. Verify installed builds against the affected version list above and close out the CISA KEV remediation requirement promptly.

7.810% KEV PoC ×2
  • microsoft windows 10 1507 (Gold), 1511, 1607, 1703
  • microsoft windows 7 SP1
  • microsoft windows 8.1 all versions at disclosure
  • +4 more
masshundreds of millions of devices (all unpatched Windows 7/8.1/RT 8.1 and Windows 10 1507-1703 PCs, plus the dominant Windows Server releases of that era)
Full article1,441 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 05, 2019

Analyzing how tactics, techniques and procedures of the Russia-linked APT28 cyberespionage group evolve over the time.

APT28 is a well known Russian cyber espionage group attributed, with a medium level of confidence, to Russian military intelligence agency GRU (by CrowdStrike). It is also known as Sofacy Group (by Kaspersky) or STRONTIUM (by Microsoft) and it’s used to target Aereospace, Defence, Governmente Agencies, International Organizations and Media.

Today I’d like to share some personal notes after a few years of collected evidence and readings on that topic.

Attack Timeline

The following timeline tracks APT28 back to 2008 and gives us a quick view on how big and organized is the threat group over the past decade.

APT28 Timeline

According to the many analyses made by Unit42 (available HERE), FireEye (HEREHERE) and TALOS (HEREHERE ) we might agree that APT28 has been very active (or at least very “spotted”) during the time frame between 2012 to 2019. However most of the new attacks, qualitative speaking, happened during the time frame between 2018 to 2019. For that reason it would be interesting to analyze how they’ve evolved over such a time frame in order to understand their change and their principal characteristics. From what I’ve tracked and from what I’ve read over the past few years it looks like APT28 changed in many areas, but today I’d like to focus mostly on the following three main areas: WeaponizationDeliveryInstallation. Let’s discuss one to one those areas.

Weaponization

Weaponization is a PRE-ATT&CK technique. It is classified as the operations needed to build and/or to prepare a complex attack. In other words all the infrastructures, the samples, the command and controls, the domains and IPs, the certificate, the libraries and, general speaking, all the operations that come before the attack phase in term of environments. Intelligence, humanInt, information gathering, informal test and so on, are not included in Weaponization since coming directly into the ATT&CK framework.

Weaponization Timeline

Observing the weaponization timeline it turns out there are three main blocks with few shared characteristics. For example from 2017 to early 2018 APT28 used specific techniques such as: T1251T1329T1336 and T1319. Those techniques are mainly focused on external – outsourcing (except for T1319) skills-set. Indeed acquiring 3rd parties infrastructures or Installing and configure hardware networks-systems and the usage of third party obfuscation libraries would definitely highlight a human resource depletion or the clear intent of false flag. On the other hand during early 2018 to mid-2018 the weaponization chain changed a lot moving to T1314T1322 and to T1328. Those techniques enforced the idea the group moved from external professional resources and from hardware localized techniques to internal professional resources (indeed they started buy own domain for propagation and C2) . Finally from October 2018 to late march 2019 APT28 introduced a totally different weaponization technique: the T1345. It is not a direct consequence to the previous observed techniques, actually we might think they improved or forked an internal dev team. Those self-developing capabilities (implemented by T1345) were not observed during the past years and highlight a slightly significant change. We might think they enrolled a dedicated dev-team or they forked the actual one by running on two different paths.

Delivery

Delivery is the way attackers deploy the initial content to the victim. In other words how the adversary reach his victim by starting the infection chain. On one hand the delivery vector is often the only (or the first) artifact (such as: a Malware, a Link or exploit kit usage) that the cybersecurity analyst could observe. Unfortunately very often analysts don’t have the possibility to track every single attack phase but they can just observe a small “portion” of it, and very often that “portion” is the “delivered artifact”. Tracking the changes on Delivery would help cybersecurity analysts to build up the idea about threat actors by comparing likeness and differences in coding, styling and techniques. Indeed the delivery phase is a special key point to distinguish threat actors which usually tend to specialize their crafting capabilities over time rather than pivoting their capabilities on new delivery vectors. The following timeline shows how the delivery changed over the analyzed time frames.

Delivery Timeline

While in the previous section (weaponization section), three were the main macro blocks, in the delivery section everything looks like uniform and quite flat based on technique T1193: Spearphishing with a malicious attachment. But if we focus on the beginning of 2018 it looks like APT28 was using a more consolidated intelligence technique (T1376) by focusing on Human Intelligence in order to grab precious information used to deliver a well-crafted email campaign (government institutions related to foreign affairs). The delivery phase, at such time, was implementing a quite sophisticated dropper technology by exploiting vulnerabilities to “save and run” the payload in the desired place. The most exploited vulnerabilities by APT28 have been tracked as follows:

CVE-2017-0144 , CVE-2013-3897, CVE-2014-1776, CVE-2012-0158, CVE-2015-5119, CVE-2013-3906, CVE-2015-7645, CVE-2015-2387, CVE-2010-3333, CVE-2015-1641, CVE-2013-1347, CVE-2015-3043, CVE-2015-1642, CVE-2015-2590, CVE-2015-1701, CVE-2015-4902, CVE-2017-0262, CVE-2017-0263
CVE-2014-4076, CVE-2014-0515

The most used tracked vulnerabilities are mainly focused on: “Windows”, “Adobe Flash” and “Oracle” Technologies. During the past few months (almost one year from time writing) it was possible to observe a quick increment over Microsoft Office Vulnerabilities in order to drop second stages of payloads. This perfectly fits the new trend and the current infection chains.

Installation

While system persistence could be guaranteed in many different ways, for example by periodically exploiting a RCE vulnerability, persistence in case of Malware attacks is typically named: “Installation”. Since the main findings that I had analyzed for this post are Malware based, it makes sense to talk about Installation rather than talking about persistence. Moreover the installation procedure runs a key role into the infection chain. Observing the installation KPI would be meaningful to understand the developer team behind software, since developer teams do not like to change installation procedures over time because they used to focus on new features and/or to improve existing modules rather than change installation frameworks. The following timeline shows how Installation procedures changed over time on APT28 folks.

Installation Timeline

The observed time frame is focused on the past year since where the most interesting changes happened, at least in my personal opinion. Let’s start by observing that in early 2018 the most used techniques were: T1055T1045T1064T1158 and T1037. Most of the used techniques belong to the “Scripting” world. In other words the most influential capabilities were based on Logon Scripts and JS/WB scripintg. From ~mid 2018 they group moves mostly on PowerShell scripting language (T1086 and T1140) widely used over the past two years (rif. HERE) ending up in early 2019 to advanced development techniques such as: T1221T1204T1045T1047T1112, which underline a quite interesting new develpment skillset.

Conclusions

As many groups are, APT28 is evolving over time. The group evolution is changing many TTPs (Tactics, Techniques and Procedures) but this time I decided to focus on: InstallationDelivery and Weaponization. Most of the tracked evolution indexes happened during the last one/two years showing a quick skill-sets enhancement on development, obfuscation and evasion techniques.

The original post is available on Marco Ramilli’s blog:

https://marcoramilli.com/2019/12/05/apt28-attacks-evolution/

About the author: Marco Ramilli, Founder of Yoroi

I am a computer security scientist with an intensive hacking background. I do have a MD in computer engineering and a PhD on computer security from University of Bologna. During my PhD program I worked for US Government (@ National Institute of Standards and Technology, Security Division) where I did intensive researches in Malware evasion techniques and penetration testing of electronic voting systems.

I do have experience on security testing since I have been performing penetration testing on several US electronic voting systems. I’ve also been encharged of testing uVote voting system from the Italian Minister of homeland security. I met Palantir Technologies where I was introduced to the Intelligence Ecosystem. I decided to amplify my cyber security experiences by diving into SCADA security issues with some of the most biggest industrial aglomerates in Italy. I finally decided to found Yoroi: an innovative Managed Cyber Security Service Provider developing some of the most amazing cyber security defence center I’ve ever experienced ! Now I technically lead Yoroi defending our customers strongly believing in: Defence Belongs To Humans.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – ATP28, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/94747/apt/evolutions-apt28-attacks.html