ZeroHour
The Recordpublished ()ingested

Organizations patch CISA KEV list bugs 3.5 times faster than others, researchers find

highExploit / PoC exploited in the wildimportance 60CVE-2024-29988CVE-2024-21412CVE-2023-7028

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-7028
Unauthenticated Account Takeover via Password Reset Flaw in GitLab CE/EE

GitLab Community and Enterprise Editions contain a critical improper access control flaw (CWE-640) in which password reset emails for a user account could be delivered to an unverified email address. Because the password reset flow is reachable over the network without authentication or user interaction (CVSS 3.1: AV:N/AC:L/PR:N/UI:N), an unauthenticated remote attacker could trigger a password reset for a victim's account such that the reset link lands on an attacker-controlled, unverified email address, then set a new password and hijack the account. Taking over an account gives the attacker that account's privileges, so compromise of an administrator account could expose the instance's code repositories, settings, and any secrets or CI/CD credentials they can reach. All GitLab CE/EE versions from 16.1 through 16.7 prior to the patched releases (16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, and 16.7.2) are affected. The flaw is under active exploitation: it carries an EPSS of 94.6% (100th percentile), was added to CISA's Known Exploited Vulnerabilities catalog on 2024-05-01, and news coverage confirms attackers are hijacking accounts in the wild.

Do: Upgrade affected GitLab CE/EE instances immediately to the patched release for your track — 16.1.6, 16.2.9, 16.3.7, 16.4.5, 16.5.6, 16.6.4, or 16.7.2 (or later) — prioritizing internet-facing instances given active exploitation and the KEV listing. Audit user accounts for unverified or unexpected email addresses and review logs for password reset activity to identify possible takeovers, and rotate credentials for any high-privilege accounts you suspect were compromised.

9.895% KEV PoC ×2
  • GitLab CE/EE All versions from 16.1 prior to 16.1.6, 16.2 prior to 16.2.9, 16.3 prior to 16.3.7, 16.4 prior to 16.4.5, 16.5 prior to 16.5.6, 16.6 prior to 16.6.4, and 16.7 p
largetens of thousands of internet-exposed GitLab instances (public internet-wide scan data)
CVE-2024-21412
CVE-2024-21412: Security Feature Bypass in Microsoft Windows Internet Shortcut Files

CVE-2024-21412 is a security feature bypass (CWE-693) in how Microsoft Windows handles Internet Shortcut files: a crafted shortcut can make Windows skip the security warning prompt that normally appears before untrusted internet content is opened or downloaded. Triggering it requires user interaction — an attacker must deliver a malicious shortcut file, typically via email or a malicious website, and convince the user to open it, which is reflected in the CVSS vector's UI:R component. An attacker who succeeds gains a bypass of those prompts, making it easier to retrieve and execute malicious remote content with fewer warnings; the DarkGate malware operators used exactly this technique in zero-day campaigns to distribute their loader. Anyone running the affected Windows 10 (1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), Windows Server 2019, or Windows Server 2022 (including 23H2) builds was exposed. The flaw was patched in Microsoft's February 2024 Patch Tuesday release (2024-02-13), the same day CISA added it to the KEV catalog, and it is under active exploitation with known ransomware association and a 95.4% EPSS score.

Do: Apply the February 2024 Windows cumulative security update (released 2024-02-13) or any later monthly cumulative update to every affected Windows 10, Windows 11, Windows Server 2019, and Windows Server 2022 build, and verify patch levels through your endpoint inventory. Because exploitation requires user interaction, as an interim control flag or block .url/Internet Shortcut attachments at email gateways and remind users not to open shortcuts from untrusted sources. Prioritize internet-facing and shared endpoints given the KEV listing and known ransomware use.

8.195% KEV ransomware
  • microsoft Windows 10 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2, 23H2
  • microsoft Windows Server 2019 all supported editions
  • +1 more
mass≈1 billion Windows 10/11/Server installations potentially affected worldwide (pre-patch installed base)
CVE-2024-29988
Mark of the Web Security Feature Bypass in Microsoft SmartScreen Prompt

CVE-2024-29988 is a security feature bypass in Microsoft SmartScreen Prompt that allows an attacker to defeat the Mark of the Web (MotW) mechanism, which normally flags internet-downloaded files so SmartScreen shows a warning before they run. An attacker triggers it by delivering a crafted file that Windows processes without the expected SmartScreen prompt, often as part of an exploit chain with CVE-2023-38831 (WinRAR) or the related SmartScreen bypass CVE-2024-21412. Successful exploitation strips away a key browser/download defense layer, letting a malicious file execute with no user warning. Any Windows system that relies on SmartScreen to vet internet-delivered content is affected; the available data does not specify affected version ranges. The flaw is confirmed to be exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-04-30 — and EPSS estimates a 45.2% chance of exploitation in the next 30 days (99th percentile), though no public PoC is known.

Do: Apply Microsoft's update for CVE-2024-29988 as soon as possible via Windows Update, per CISA's KEV required action to apply vendor mitigations; verify patch status across Windows endpoints. Until patched, scrutinize internet-delivered archives and installers, and ensure the chain components are also remediated — update WinRAR for CVE-2023-38831 and patch the related SmartScreen bypass CVE-2024-21412.

8.845% KEV
  • Microsoft SmartScreen Prompt
masshundreds of millions of Windows devices (SmartScreen is built into and enabled by default on Windows 10/11)
Full article1,068 words · extracted from therecord.media · click to collapse

Researchers have found that a catalog of exploited vulnerabilities maintained by the federal government  is having a tangibly positive effect on organizations both within and outside of the federal government.

The Cybersecurity and Infrastructure Security Agency (CISA) has run its Known Exploited Vulnerabilities (KEV) catalog for nearly three years and it has quickly become the go-to repository for software and hardware bugs actively being exploited by hackers around the world.

Experts at cybersecurity scanning company Bitsight posed the question, “do organizations remediate KEVs faster than vulnerabilities not in the KEV catalog?”

“The answer is a clear ‘yes,’” they said. Their data shows that the median time to patch vulnerabilities listed on the catalog is 3.5 times faster than non-KEV bugs.

Put another way, the median time for remediation of KEV-listed bugs is 174 days, while the time for non-KEV-list vulnerabilities is 621 days. 

Those numbers come from Bitsight scanning for vulnerabilities within more than 1 million entities — companies, schools, local governments and more. 

The researchers also tracked a new feature within the KEV list, in which CISA says whether ransomware gangs are specifically targeting a certain vulnerability. 

“If we average out the relative drops, ransomware KEVs are fixed 2.5x faster (on average) than KEVs not known to be used in ransomware,” Bitsight said. 

Bitsight researchers also confirmed that the KEV list was having a tangible effect by helping companies and local governments sort through the deluge of vulnerabilities to address the bugs that truly matter.  

Thirty-five percent of all organizations observed by Bitsight dealt with a KEV in 2023, with the vast majority having more than one.  

Time to patch

Every vulnerability added to the KEV list comes with a deadline that varies based on the severity of the bug and the urgency of the targeting. The deadline officially applies to federal agencies, but for organizations outside of the U.S. government, it can serve as a guideline for the severity of a bug.

Bitsight found that federal civilian agencies accountable to CISA’s binding directive are 63% more likely to remediate KEVs by the deadline than other organizations. About 40% of all organizations — those outside of the federal government that do not have to abide by CISA rules — are able to resolve bugs by the CISA’s deadline.

The report notes that throughout the existence of the KEV list, the deadlines given to patch have changed drastically. When it was first created, CISA typically gave federal civilian agencies either one week, two weeks or six months to patch a bug. But by the spring of 2022, they shifted to three week deadlines. 

It is only in the last few months that one week deadlines have been reintroduced. 

“Why the shift? Those early vulnerabilities tended to be older when they were added to the KEV catalog. Given that they may have been around for a while, it seems logical to give organizations time to address issues,” the researchers said. 

“Deadlines seem to be influenced by whether a vulnerability is used in ransomware: 1 week deadline vulnerabilities are nearly twice as likely to have been used in ransomware. This likely is because these vulnerabilities are particularly urgent and likely to cause significant damage if exploited on an agency system.”

Technology firms were the fastest to remediate vulnerabilities — in part because they topped Bitsight’s list of sectors that had the most exposure. Educational organizations and local governments were the worst off among the sectors tracked by Bitsight, with both having a high exposure to KEV list bugs and a slow remediation time.  

Insurance companies, credit unions and engineering firms had relatively low exposure to KEV list vulnerabilities and typically fixed issues quickly. 

New on the list

CISA added two vulnerabilities to the KEV list this week. On Tuesday, the agency added CVE-2024-29988 to the list. 

The vulnerability was unveiled by Microsoft as part of the Patch Tuesday releases in April and affects Microsoft SmartScreen — a cloud-based anti-phishing and anti-malware component included in several Microsoft products.

Ben McCarthy, lead cyber security engineer at Immersive Labs, said the SmartScreen is a large popup that warns the user about running an unknown file and is often the endpoint of phishing attacks as it scares the user enough to not continue opening it.

He added that the bug is popular among attackers that use a file download as part of their attack techniques for gaining initial access because they “want to find ways to bypass the security features such as SmartScreen.”

CISA noted that the vulnerability can be chained with CVE-2024-21412 during attacks. Tenable’s Satnam Narang explained that the same Zero Day Initiative researcher that discovered CVE-2024-21412 also found CVE-2024-29988. 

“Social engineering through direct means (email and direct messages) that requires some type of user interaction is a typical route for exploitation for this type of flaw,” he said. 

“CVE-2024-21412 was used as part of a DarkGate campaign that leveraged fake software installers impersonating Apple’s iTunes, Notion, NVIDIA and more. Microsoft Defender SmartScreen is supposed to provide additional protections for end users against phishing and malicious websites. However, as the name implies, these flaws bypass these security features, which leads to end users being infected with malware.”

Bleeping Computer reported last month that the bug was used by a financially-motivated hacking group to target forex trading forums and stock trading Telegram channels.

CISA also added CVE-2023-7028 to the KEV list on Wednesday. It affects Gitlab — a popular open source code repository and collaborative software development platform.

The bug, found in GitLab Community and Enterprise Editions, allows an attacker to “trigger password reset emails to be sent to an unverified email address to ultimately facilitate an account takeover.”

Debrup Ghosh, senior staff product manager at Synopsys Software Integrity Group, warned that the ability to compromise platforms like GitLab that are inherently trusted would allow attackers to “launch attacks that are difficult to detect and can have rippling effects downstream.” 

“Additionally, it appears that although the patch was issued in January, more than 40% of GitLab instances are not patched almost four months later,” Ghosh said.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/kev-list-vulnerabilities-patched-significantly-faster