NSA Discovers New Vulnerabilities Affecting Microsoft Exchange Servers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-1732 | Out-of-Bounds Write Local Privilege Escalation in Microsoft Win32k (CVE-2021-1732) CVE-2021-1732 is a local elevation-of-privilege vulnerability (CWE-787, out-of-bounds write) in Microsoft's Win32k kernel driver, publicly characterized as an "offset confusion" in the Win32k ConsoleControl routine. It is triggered locally: a process with only low privileges can invoke the vulnerable Win32k functionality without any user interaction, causing a user-supplied offset/pointer to be mishandled in kernel mode and memory to be written out of bounds. An attacker who successfully exploits the flaw can execute code in the kernel and elevate to SYSTEM, gaining full control of the host — which makes it a valuable second-stage link in malware and ransomware chains. Any system running the affected Windows 10 releases (1803, 1809, 1909, 2004, 20H2) or Windows Server 2019/1909/2004/20H2 is exposed, though exploitation requires the attacker to already run code locally on the target. The flaw was fixed in Microsoft's February 2021 Patch Tuesday updates, was added to CISA's KEV catalog on 2021-11-03 with known ransomware use, and carries a very high EPSS score (78.4%, 100th percentile), indicating sustained exploitation pressure. Do: Apply Microsoft's February 2021 (or later) Windows cumulative security updates to all affected Windows 10 and Windows Server systems, per vendor instructions — CISA's KEV listing requires federal agencies to patch. Prioritize hosts exposed to untrusted local users or already compromised by malware (e.g., ransomware or Raspberry Robin activity, which has used chained Windows LPEs), and hunt on unpatched hosts for signs of post-exploitation privilege escalation to SYSTEM. | 7.8 | 78% | KEV ransomware PoC ×2 |
| mass≈1 billion+ Windows devices (the listed builds spanned the mainstream Windows 10/Server install base) | |
| CVE-2021-27091 | RPC Endpoint Mapper Service Elevation of Privilege Vulnerability RPC Endpoint Mapper Service Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2021-28310 | Out-of-Bounds Write in Microsoft Win32k Allows Local Privilege Escalation on Windows 10 CVE-2021-28310 is an elevation-of-privilege flaw caused by an out-of-bounds write (CWE-787) in the Windows Win32k kernel component. A local attacker who can already execute low-privileged code on a vulnerable system can trigger the memory corruption bug to run arbitrary code in kernel mode, with no user interaction required. Successful exploitation grants SYSTEM/kernel-level control of the host, typically as a follow-on step after an attacker has gained an initial foothold, rather than a remote-entry vector. Windows 10 versions 1803, 1809, 1909, 2004 and 20H2, plus the corresponding Windows Server versions 1909, 2004, 2019 and 20H2, are affected. The flaw was fixed in Microsoft's April 2021 security updates and has been actively exploited in the wild — CISA added it to the KEV catalog on 2021-11-03, and its EPSS of 8.3% (95th percentile) signals elevated exploitation risk. Do: Apply the April 2021 (or later) Windows cumulative security updates to all affected Windows 10 and Windows Server systems, prioritizing hosts where untrusted or low-privileged users can run code, such as terminal/RDS servers, VDI and shared workstations. Because this flaw is in the CISA KEV catalog, applying vendor updates is a required action for federal and regulated environments; verify remediation by confirming the installed OS build includes the April 2021 patch. For systems that cannot be patched promptly, limit local code execution by untrusted users and monitor for post-exploitation privilege-escalation behavior. | 7.8 | 8% | KEV |
| masshundreds of millions of Windows 10 and Windows Server endpoints worldwide | |
| CVE-2021-28444 | Windows Hyper-V Security Feature Bypass Vulnerability Windows Hyper-V Security Feature Bypass Vulnerability NVD description · AI analysis pending | 5.7 group max | 2% |
| — | ||
| CVE-2021-28458 | Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability NVD description · AI analysis pending | 7.8 | 2% |
| — | ||
| CVE-2021-28480 +1 in the same advisory: …28483 | Microsoft Exchange Server Remote Code Execution Vulnerability Microsoft Exchange Server Remote Code Execution Vulnerability NVD description · AI analysis pending | 9.8 group max | 71% |
| — |
Full article695 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 14, 2021
In its April slate of patches, Microsoft rolled out fixes for a total of 114 security flaws, including an actively exploited zero-day and four remote code execution bugs in Exchange Server.
Of the 114 flaws, 19 are rated as Critical, 88 are rated Important, and one is rated Moderate in severity.
Chief among them is CVE-2021-28310, a privilege escalation vulnerability in Win32k that's said to be under active exploitation, allowing attackers to elevate privileges by running malicious code on a target system.
Cybersecurity firm Kaspersky, which discovered and reported the flaw to Microsoft in February, linked the zero-day exploit to a threat actor named Bitter APT, which was found exploiting a similar flaw (CVE-2021-1732) in attacks late last year.
"It is an escalation of privilege (EoP) exploit that is likely used together with other browser exploits to escape sandboxes or get system privileges for further access," Kaspersky researcher Boris Larin said.
NSA Found New Bugs Affecting Exchange Server
Also fixed by Microsoft are four remote code execution (RCE) flaws (CVE-2021-28480 through CVE-2021-28483) affecting on-premises Exchange Servers 2013, 2016, and 2019 that were reported to the company by the U.S. National Security Agency (NSA). Two of the code execution bugs are unauthenticated and require no user interaction, and carry a CVSS score of 9.8 out of a maximum of 10.
While the Windows maker said it had found no evidence of any active exploits in the wild, it's recommended that customers install these updates as soon as possible to secure the environment, particularly in light of the widespread Exchange Server hacks last month and new findings that attackers are attempting to leverage the ProxyLogon exploit to deploy malicious cryptominers onto Exchange Servers, with the payload being hosted on a compromised Exchange Server.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has also revised the emergency directive it issued last month, stating "these vulnerabilities pose an unacceptable risk to the Federal enterprise and require an immediate and emergency action," while cautioning that the underlying flaws can be weaponized by reverse-engineering the patch to create an exploit.
Cybersecurity firm Check Point, which has been tracking ongoing cyber threats exploiting the Exchange Server flaws, said a total of 110,407 attacks have been prevented targeting government, manufacturing, finance, healthcare, legal, and insurance industries in the U.S., U.K., Germany, Netherlands, and Brazil.
FBI Removed Backdoors From Hacked MS Exchange servers
What's more, the U.S. Federal Bureau of Investigation (FBI) carried out a "successful action" to "copy and remove" web shells planted by adversaries on hundreds of victim computers using the ProxyLogon flaws. The FBI is said to have wiped the web shells that were installed by Hafnium that could have been used to maintain and escalate persistent, unauthorized access to U.S. networks.
"The FBI conducted the removal by issuing a command through the web shell to the server, which was designed to cause the server to delete only the web shell (identified by its unique file path)," the Justice Department said in a statement detailing the court-authorized operation.
27 RCE Flaws in Windows RPC and Other Fixes
Microsoft also said four additional vulnerabilities were publicly known at the time of release but not exploited —
- CVE-2021-28458 - Azure ms-rest-nodeauth Library Elevation of Privilege Vulnerability
- CVE-2021-27091 - RPC Endpoint Mapper Service Elevation of Privilege Vulnerability
- CVE-2021-28437 - Windows Installer Information Disclosure Vulnerability
- CVE-2021-28312 - Windows NTFS Denial of Service Vulnerability
In addition, April's Patch Tuesday update also addresses a whopping 27 RCE flaws in Remote Procedure Call (RPC) runtime, a Hyper-V security feature bypass vulnerability (CVE-2021-28444), and multiple privilege escalation flaws in Windows Speech Runtime, Windows Services and Controller App, Windows Secure Kernel Mode, Windows Event Tracing, and Windows Installer.
Software Patches From Other Vendors
Besides Microsoft, a number of other vendors have also released a slew of patches on Tuesday —
- Adobe (security updates for Photoshop, Digital Editions, RoboHelp, and Bridge)
- DELL
- Linux distributions SUSE, Oracle Linux, and Red Hat
- SAP
- Schneider Electric, and
- Siemens
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/04/nsa-discovers-new-vulnerabilities.html