ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds Sophos firewall bug to Known Exploited Vulnerabilities Catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-6324
Privilege Escalation in Microsoft Kerberos Key Distribution Center (KDC)

CVE-2014-6324 is a privilege escalation flaw in the Kerberos Key Distribution Center (KDC) on Microsoft domain controllers: a remote, authenticated domain user sends specially crafted Kerberos ticket data that the KDC fails to validate correctly, allowing the attacker to obtain domain administrator privileges. An attacker who already holds any valid domain credentials can therefore escalate to full control of the Active Directory domain, which typically means compromise of every domain controller and every account in the forest. Any organization running Active Directory on Windows domain controllers is affected; the provided data does not enumerate specific Windows versions or the fixed release. The vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25, ransomware use unknown), carries a 87.4% EPSS probability of exploitation within 30 days (100th percentile), and is publicly associated in security reporting with the Duqu 2.0 espionage platform.

Do: Apply the Microsoft security update for this vulnerability (MS14-068, November 2014) per vendor instructions on every domain controller, and verify no unpatched DC remains, since one vulnerable domain controller is enough for any domain user to become domain administrator. Prioritize internet-exposed and domain-controller assets in CISA KEV-driven patch tracking, and monitor Kerberos ticket traffic for anomalous or forged ticket/PAC content while patching is pending.

87% KEV
  • Microsoft Kerberos Key Distribution Center (KDC)
massmillions of Active Directory domain controllers / millions of domain users in scope (order-of-magnitude estimate)
CVE-2018-10562
+1 in the same advisory: …10561
Unauthenticated RCE in Dasan GPON Routers (CVE-2018-10562)

CVE-2018-10562 is an OS command injection flaw (CWE-78) in the web management interface of Dasan GPON home routers. When chained with the companion authentication bypass CVE-2018-10561, a remote, unauthenticated attacker can send crafted requests that execute arbitrary commands on the device. Successful exploitation yields full control of the router, enabling device takeover, botnet enrollment, and, per CISA, use in ransomware operations. Anyone operating an affected Dasan GPON router — many of which were deployed by internet service providers — is affected, and CISA notes the impacted products are end-of-life. Exploitation is confirmed in the wild: the flaw is in CISA's KEV (added 2022-03-31) with known ransomware use and a 100% EPSS probability of exploitation within 30 days.

Do: Because the product line is end-of-life and CISA's required action is to disconnect impacted devices if still in use, retire or replace affected routers rather than patching in place. If replacement must wait, block or firewall the web management interface from the internet, check the device for signs of compromise, and ensure the related authentication-bypass path CVE-2018-10561 is also closed.

9.8100% KEV ransomware PoC ×2
  • Dasan Gigabit Passive Optical Network (GPON) routers
mass≈1 million internet-exposed devices (public scan counts around the 2018 disclosure)
CVE-2021-21551
Local Privilege Escalation in Dell dbutil_2_3.sys Driver

CVE-2021-21551 is an insufficient access control flaw (CWE-782) in Dell's dbutil_2_3.sys driver, present on Dell systems for roughly 12 years before being patched. A local, authenticated user can trigger the flaw by sending crafted requests (IOCTLs) to the driver, gaining the ability to read and write arbitrary memory. An attacker who exploits it can escalate privileges (typically to kernel/SYSTEM level), cause a denial of service, or disclose information, making it a useful stepping stone for post-compromise attacks. Any Dell machine that shipped or ran the dbutil driver — used in Dell support and BIOS/BIOS-update tooling — is affected, and public reporting indicates hundreds of millions of Dell PCs are exposed. The flaw is actively exploited: it is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-03-31), public PoCs exist, and the Lazarus APT reportedly used it in attacks to deploy a rootkit; EPSS puts the 30-day exploitation probability at 79.2%.

Do: Apply Dell's updated driver/firmware per vendor instructions, as required by CISA's KEV catalog. Inventory your fleet for the dbutil_2_3.sys driver file (commonly found with Dell support tools and BIOS update utilities) and prioritize patching endpoints, since the bug requires only local user access. Hunt for signs of local privilege-escalation activity consistent with public PoCs, given documented Lazarus APT use to deploy a rootkit.

7.879% KEV PoC ×2
  • Dell dbutil driver (dbutil_2_3.sys) dbutil_2_3.sys as identified in the advisory; source data provides no detailed fixed-version range, so check for the presence of dbutil_2_3.sys on Dell systems
masshundreds of millions of Dell PCs (the driver was broadly distributed with Dell support/update tooling for over a decade)
CVE-2021-28799
Improper Authorization in QNAP HBS 3 Allows Remote Login to NAS Devices

CVE-2021-28799 is a critical improper authorization flaw (CWE-285, CVSS 9.8) in HBS 3 (Hybrid Backup Sync), the backup application bundled with QNAP NAS firmware. Because the weakness is reachable over the network with no privileges and no user interaction, a remote attacker who can reach an affected NAS can bypass authorization and log in to the device. An attacker gaining this unauthorized login obtains remote access to the NAS, which threat actors have leveraged in ransomware campaigns against QNAP devices. Anyone running HBS 3 on QTS 4.3.3, 4.3.4, 4.3.6 or 4.5.2, QuTS hero h4.5.1, or QuTScloud c4.5.1-c4.5.4 at versions below the listed fixes is affected, while HBS 2 and HBS 1.3 are not affected. The flaw is in the wild: it was added to CISA's KEV on 2022-03-31 with known ransomware use, EPSS puts 30-day exploitation probability at 78.3% (top percentile), and public reporting around this period describes ransomware waves (e.g., Qlocker, eCh0raix) infecting hundreds of QNAP NAS devices within days.

Do: Update HBS 3 to the fix for your OS: v16.0.0415 on QTS 4.5.2, v3.0.210412 on QTS 4.3.6, v3.0.210411 on QTS 4.3.4/4.3.3, and v16.0.0419 on QuTS hero h4.5.1 and QuTScloud c4.5.1~c4.5.4. Until patched, keep the NAS and its web services off the direct internet (disable router port forwarding/UPnP to the NAS) and review devices for signs of compromise. Given the KEV listing and known ransomware use, prioritize internet-reachable NAS devices.

9.878% KEV ransomware
  • QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) on QTS prior to v16.0.0415 on QTS 4.5.2; prior to v3.0.210412 on QTS 4.3.6; prior to v3.0.210411 on QTS 4.3.4; prior to v3.0.210411 on QTS 4.3.3
  • QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) on QuTS hero prior to v16.0.0419 on QuTS hero h4.5.1
  • QNAP Systems Inc. HBS 3 (Hybrid Backup Sync) on QuTScloud prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4
  • +1 more
mass≈1M+ QNAP NAS devices plausibly run an affected HBS 3 build (the app ships bundled with the affected QTS/QuTS releases), with hundreds of thousands of QNAP NAS…
CVE-2021-34484
Privilege Escalation in Microsoft Windows User Profile Service (CWE-269)

CVE-2021-34484 is a privilege escalation flaw in the Microsoft Windows User Profile Service in which the service improperly handles user profiles, allowing an attacker who can already run code on a local machine to gain elevated privileges. The flaw is triggered by local execution, meaning an attacker must first obtain a foothold on the target system — for example via malware, a compromised account, or a chained remote code execution bug — and then exploit the User Profile Service to elevate. By escalating privileges, an attacker can typically gain SYSTEM-level access, take full control of the host, disable security tooling, and move laterally across a network, which makes this bug a common step in ransomware and broader intrusion chains. All Microsoft Windows deployments are in scope per CISA, though only unpatched systems are practically at risk. Exploitation is confirmed in the wild: CISA added the CVE to its Known Exploited Vulnerabilities catalog on 2022-03-31 with a required action to apply vendor updates, and EPSS assigns a 21.8% probability of exploitation within 30 days (97th percentile), indicating elevated near-term risk.

Do: Apply Microsoft's security updates for the User Profile Service privilege escalation per vendor instructions, as required by CISA's KEV catalog entry. Because this is a local privilege escalation often chained with initial-access or malware infections, prioritize hosts where untrusted users can execute code — workstations, RDP/session hosts, and VDI — and confirm the applicable August 2021 (or later) cumulative update is installed. Use EDR telemetry and Windows Event Logs (User Profile Service activity) to check for signs of prior exploitation on systems that were unpatched since before the fix was released.

7.822% KEV
  • Microsoft Windows
masshundreds of millions of Windows devices and installations worldwide; effectively every unpatched Windows endpoint and server
CVE-2022-1040
Authentication Bypass Leading to Unauthenticated RCE in Sophos Firewall (SFOS)

CVE-2022-1040 is a critical authentication bypass in the User Portal and Webadmin of Sophos Firewall (SFOS) version v18.5 MR3 and older. A remote, unauthenticated attacker who can reach either web-facing service bypasses authentication and executes code on the firewall appliance. Successful exploitation yields full device compromise (CVSS 9.8 with high confidentiality, integrity, and availability impact), enabling traffic interception, persistence, and pivoting into the protected network. Any organization running an affected Sophos Firewall version where the User Portal or Webadmin is reachable, especially from the internet, is exposed. Exploitation is confirmed in the wild: it was exploited as a zero-day in March 2022, added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-31, and used in campaigns attributed to Chinese actors, including a U.S. indictment of a Chinese hacker for exploiting the flaw.

Do: Upgrade Sophos Firewall to a fixed release (v18.5 MR4 or later, per Sophos' patch instructions). Until patched, restrict access to the User Portal and Webadmin to trusted management networks or VPN clients and remove any direct internet exposure to these services. Review device and authentication logs for signs of exploitation, including unexpected or modified administrator accounts and configuration changes, and follow the vendor/CISA required action to apply updates.

9.8100% KEV PoC ×2
  • Sophos Firewall (SFOS) v18.5 MR3 and older
largetens of thousands of internet-exposed User Portal/Webadmin instances among hundreds of thousands of deployed Sophos Firewall appliances
CVE-2022-26871
Unauthenticated Arbitrary File Upload RCE in Trend Micro Apex Central

CVE-2022-26871 is a critical (CVSS 9.8) arbitrary file upload flaw (CWE-345, insufficient verification of data authenticity) in Trend Micro Apex Central, the central management console for Trend Micro's endpoint protection. An unauthenticated remote attacker can send an upload request to a network-accessible interface without any credentials or user interaction, uploading an arbitrary file that can lead to remote code execution on the server. Successful exploitation gives the attacker code execution with high impact to confidentiality, integrity and availability on the affected management server, potentially providing a foothold into the wider network it manages. Organizations running Trend Micro Apex Central on-premise are affected; CISA also lists Apex One in the product CPE data, while CISA's affected-product entry names Apex Central. The flaw was added to the CISA Known Exploited Vulnerabilities Catalog on 2022-03-31, indicating observed exploitation in the wild, with EPSS estimating a 19.6% probability of exploitation within 30 days; no public PoC is known.

Do: Apply the updated Apex Central release per Trend Micro's security advisory and the CISA KEV required action (apply updates per vendor instructions); confirm with the vendor which build addresses CVE-2022-26871 for your deployment. Until patched, restrict internet exposure of the Apex Central management console to trusted networks and review the server for unexpected uploaded files or web/server processes launching children, given confirmed in-the-wild exploitation. Organizations managing Apex One endpoints via Apex Central should ensure the management server is prioritized, since compromise could expose endpoint fleet management functions.

9.820% KEV
  • Trend Micro Apex Central
  • Trend Micro Apex One
moderate≈1,000–10,000 on-premise management servers worldwide (estimated)
Full article537 words · extracted from securityaffairs.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical Sophos firewall flaw and seven other issues to its Known Exploited Vulnerabilities Catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the recently disclosed CVE-2022-1040 flaw in the Sophos firewall, along with seven other issues, to its Known Exploited Vulnerabilities Catalog.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

The new vulnerabilities added to the catalog have to be addressed by federal agencies by April 21, 2022.

The CVE-2022-1040 is an authentication bypass vulnerability that resides in the User Portal and Webadmin areas of Sophos Firewall.

The vulnerability received a CVSS score of 9.8 and impacts Sophos Firewall versions 18.5 MR3 (18.5.3) and earlier. The vulnerability was reported to the security firm by an unnamed security researcher via its bug bounty program.

“An authentication bypass vulnerability allowing remote code execution was discovered in the User Portal and Webadmin of Sophos Firewall and responsibly disclosed to Sophos. It was reported via the Sophos bug bounty program by an external security researcher. The vulnerability has been fixed.” reads the advisory published by the company.

A remote attacker with access to the Firewall’s User Portal or Webadmin interface can exploit the flaw to bypass authentication and execute arbitrary code.

Sophos Firewall User Portal interface
Source Sophos community

The security vendor pointed out that the hotfixes will be automatically installed on its devices by default.

The company also recommends customers avoid exposing their User Portal and Webadmin to WAN.

Sophos is also warning that the CVE-2022-1040 flaw in Sophos Firewall is actively exploited in attacks aimed at a small set of Asian organizations.

CISA also ordered federal agencies to patch a high severity arbitrary file upload vulnerability (CVE-2022-26871) in the Trend Micro Apex Central product management console that can be abused in remote code execution attacks.

On Tuesday, Trend Micro said it has observed “at least one active attempt of potential exploitation” of this vulnerability in the wild.

CISA added six more vulnerabilities to its Known Exploited Vulnerabilities Catalog today, all of them also exploited in ongoing attacks.

CISA also ordered federal agencies to patch an arbitrary file upload vulnerability in Trend Micro Apex Central (CVE-2022-26871) and a privilege escalation in Microsoft Windows (CVE-2021-34484).

Below is the list of recently added vulnerabilities:

CVEVulnerability NameDue Date
CVE-2022-26871Trend Micro Apex Central Arbitrary File Upload Vulnerability2022-04-21
CVE-2022-1040Sophos Firewall Authentication Bypass Vulnerability2022-04-21
CVE-2021-34484Microsoft Windows User Profile Service Privilege Escalation2022-04-21
CVE-2021-28799QNAP NAS Improper Authorization Vulnerability2022-04-21
CVE-2021-21551Dell dbutil Driver Insufficient Access Control Vulnerability2022-04-21
CVE-2018-10562Dasan GPON Routers Command Injection Vulnerability2022-04-21
CVE-2018-10561Dasan GPON Routers Authentication Bypass Vulnerability2022-04-21
CVE-2014-6324Microsoft Windows Kerberos KDC Privilege Escalation2022-04-21

The CISA Catalog has reached a total of 609 entries with the latest added vulnerabilities.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, BazarLoader)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/129686/security/known-exploited-vulnerabilities-catalog.html