ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft says it has fixed exploits leaked by Shadow Brokers in March

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-0146
Remote Code Execution in Microsoft Windows SMBv1 Server (MS17-010)

CVE-2017-0146 is a remote code execution flaw in the Microsoft Windows SMBv1 server that is triggered when the vulnerable service processes specially crafted SMB packets, one of a family of related SMBv1 bugs (CVE-2017-0143/0144/0145/0148) publicly leaked by the Shadow Brokers and fixed by Microsoft in the MS17-010 April 2017 bulletin. An attacker with limited privileges who can reach the SMB service over the network can execute arbitrary code in kernel context, gaining a foothold for lateral movement and follow-on payloads such as ransomware or cryptocurrency miners. Affected systems span Windows Vista SP2 through Windows Server 2016, as well as Siemens medical and laboratory products (Acuson ultrasound, syngo, Versant kPCR systems) that run on affected Windows platforms. Public exploit code exists, including Metasploit ports of the NSA EternalRomance/EternalSynergy/EternalChampion exploits, and the vulnerability is in CISA's Known Exploited Vulnerabilities catalog with documented ransomware use. Exploitation probability is extremely high (EPSS 89.9%, top percentile), so unpatched systems remain at immediate risk.

Do: Apply Microsoft's MS17-010 (April 2017) security updates on all affected Windows versions, and apply Siemens' published firmware/security updates for Acuson, syngo, Tissue Preparation System, and Versant kPCR products. As an interim mitigation, disable SMBv1 where possible and restrict inbound access to TCP/445; check hosts for signs of compromise such as the DOUBLEPULSAR implant. This CVE is in CISA's KEV catalog with known ransomware use, so prioritize internet-facing and clinical/network-segmented but unpatched systems immediately.

8.890% KEV ransomware PoC ×5
  • Microsoft Windows SMBv1 server Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; Windows 10 Gold, 1511, and 1
  • Siemens Acuson P300 firmware
  • Siemens Acuson P500 firmware
  • +6 more
masshundreds of millions of Windows installations worldwide; on the order of hundreds of thousands to millions of SMB endpoints exposed to scanning networks, plus…
CVE-2017-0147
Information Disclosure in Microsoft Windows SMBv1 Server (CVE-2017-0147)

CVE-2017-0147 is an information disclosure flaw in the SMBv1 server component of Windows: an unauthenticated remote attacker sends specially crafted SMBv1 packets that cause the server to leak sensitive contents of process memory. It belongs to the SMBv1 'Eternal' family of flaws patched in Microsoft's March 2017 MS17-010 bulletin, whose exploit tooling later surfaced in the Shadow Brokers leak and is associated with DOUBLEPULSAR implant activity on TCP 445. The attacker gains read access to process memory (confidentiality-only impact reflected in the CVSS 7.5 score), which can expose sensitive data or assist follow-on attacks, though this CVE alone does not grant code execution. Anyone running the affected Windows releases with the SMBv1 server enabled is exposed, including legacy desktops and servers and Siemens ACUSON P300/P500 ultrasound systems, particularly hosts with TCP 445 reachable from untrusted networks. Exploitation is in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-05-24 with known ransomware use, and EPSS assigns a ~99.7% probability of exploitation activity in any 30-day window.

Do: Apply Microsoft's MS17-010 security update (March 2017) or later cumulative updates on every affected Windows host, per the vendor's instructions, and update Siemens ACUSON P300/P500 firmware per Siemens' guidance. Where patching is impractical, disable SMBv1 (e.g., via Group Policy or Set-SmbServerConfiguration -EnableSMB1Protocol $false) and restrict inbound TCP 445 to trusted networks only. Audit exposed and legacy hosts for DOUBLEPULSAR-style SMB implants and unnecessary SMBv1 exposure.

7.5100% KEV ransomware PoC ×5
  • microsoft Windows Vista SP2
  • microsoft Windows Server 2008 SP2; Windows Server 2008 R2 SP1
  • microsoft Windows 7 SP1
  • +7 more
mass≈1M+ internet-exposed Windows SMB servers (public port-445 scans), plus hundreds of millions of legacy Windows endpoints with SMBv1 enabled by default; Siemens…
Full article718 words · extracted from securityaffairs.com · click to collapse

Microsoft determined that most of the flaws exploited by the tools in the dump released by Shadow Brokers yesterday were patched in March.

Yesterday the Shadow Brokers hacker group has released a new portion of the alleged archive of the NSA containing hacking tools and exploits. The group released a 117.9 MB encrypted dump containing documents that suggest NSA hacker SWIFT system in the Middle East.

Some of the codenames for the hacking tools in the dump are OddJob, EasyBee, EternalRomance, FuzzBunch, EducatedScholar, EskimoRoll, EclipsedWing, EsteemAudit, EnglishMansDentist, MofConfig, ErraticGopher, EmphasisMine, EmeraldThread, EternalSynergy, EwokFrenzy, ZippyBeer, ExplodingCan, DoublePulsar.

The tools work against almost all versions of Windows, from Windows 2000 and XP to Windows 7 and 8, and Server 2000, 2003, 2008, 2008 R2 and 2012, except Windows 10 and Windows Server 2016.

Security experts at Microsoft explained most of the Windows vulnerabilities exploited by the above hacking tools have been already patched in the last month’s Patch Tuesday update.

“Most of the exploits that were disclosed fall into vulnerabilities that are already patched in our supported products. Customers still running prior versions of these products are encouraged to upgrade to a supported offering,” Microsoft Security Team said in a blog post published today.

date.

Code Name Solution
EternalBlue Addressed by MS17-010
EmeraldThread Addressed by MS10-061
EternalChampion Addressed by CVE-2017-0146 & CVE-2017-0147
“ErraticGopher” Addressed prior to the release of Windows Vista
EsikmoRoll Addressed by MS14-068
EternalRomance Addressed by MS17-010
EducatedScholar Addressed by MS09-050
EternalSynergy Addressed by MS17-010
EclipsedWing Addressed by MS08-067

The availability of such exploits and hacking tools represents a serious problem, an attacker with technical knowledge can exploit them to compromise millions of Windows systems across the world.

“Of the three remaining exploits, “EnglishmanDentist”, “EsteemAudit”, and “ExplodingCan”, none reproduces on supported platforms, which means that customers running Windows 7 and more recent versions of Windows or Exchange 2010 and newer versions of Exchange are not at risk.” continues Microsoft.

The SWIFT folder in the dump contains a PowerPoint document that contains credentials and data on the internal architecture of EastNets, one of the largest SWIFT Service Bureau in the Middle East.

Shadow Brokers Windows exploits

The folder includes SQL scripts that could be used to query Oracle Database to obtain a wide range of information, including the list of users and the SWIFT message queries.Giving a look at the list of exploits in the archive we can find

Giving a look at the list of exploits in the archive we can find

  • Eternalromance that implements a Weaponized #0day Metasploit with an efficient GUI interfaces.
  • Eternalblue — an SMBv1 (Server Message Block 1.0) exploit that could trigger a RCE in older versions of Windows. The security expert Matthew Hickey published a video that demonstrates how to use the Eternalblue exploit against a server running Windows Server 2008 R2 SP1 and chaining the hack with the FuzzBunch exploit, which is being used to compromise a virtual machine running Windows Server 2008.

The experts noticed that the attack also works against Windows PCs without installing the latest updates.

“The patches were released in last month’s update, I tested on a fully patched Windows 2008 R2 SP1 (x64), so many hosts will be vulnerable – if you apply MS17-010 it should protect hosts against the attacks,” Matthew added.

According to The Intercept, Microsoft had not been contacted by the US Government in relation to the Shadow Brokers data leak.

“A Microsoft spokesperson told The Intercept “We are reviewing the report and will take the necessary actions to protect our customers.” We asked Microsoft if the NSA at any point offered to provide information that would help protect Windows users from these attacks, given that the leak has been threatened since August 2016, to which they replied “our focus at this time is reviewing the current report.” The company later clarified that “At this time, other than reporters, no individual or organization has contacted us in relation to the materials released by Shadow Brokers.” reported The Intercept.

If you want to stay safe from attacks exploiting the above hacking tools keep your Windows machines and servers up-to-date.

Pierluigi Paganini talk to RT International

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Shadow Brokers, Windows)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/58025/hacking/shadow-brokers-windows-exploits.html