ZeroHour
The Recordpublished ()ingested

CISA adds recently-announced Microsoft zero

criticalAdvisory exploited in the wildimportance 60CVE-2023-21674CVE-2022-41080CVE-2023-21743CVE-2023-21763

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-41080
Microsoft Exchange Server Privilege Escalation Exploited in Ransomware Campaigns

CVE-2022-41080 is an elevation-of-privilege flaw in Microsoft Exchange Server that stems from improper handling of requests to the server's Autodiscover component, allowing an attacker with any valid authenticated mailbox account to escalate privileges on the server. It is triggered by sending crafted authenticated HTTP requests to the Autodiscover endpoint, and it lets attackers bypass the URL-rewrite mitigations defenders had deployed against the earlier ProxyNotShell SSRF. When chained with the related PowerShell remote-code-execution bug CVE-2022-41082, privilege escalation becomes full remote code execution on the Exchange server. Any organization running on-premises Exchange Server with the Autodiscover component reachable — especially internet-exposed OWA/Autodiscover endpoints — is affected. The flaw is actively exploited: it was added to CISA's KEV catalog on 2023-01-10, is known to be used by ransomware operators, and has been tied to the Play ransomware gang, including the attack that took Rackspace's hosted Exchange environment offline.

Do: Apply Microsoft Exchange Server security updates per vendor instructions (this CVE was fixed in Microsoft's November 2022 Exchange security updates — verify your servers are fully patched through the January 2023 rollups and that no Exchange builds predate the fix). Until patched, apply and verify the Autodiscover URL-rewrite/allow-list mitigation, knowing this flaw is a known bypass vector, and restrict Autodiscover/OWA exposure where feasible. Hunt for compromise in IIS logs for unusual requests to /autodiscover/autodiscover.json followed by PowerShell (CVE-2022-41082) activity, and treat any suspicious authenticated sessions as potential ransomware precursor activity.

8.877% KEV ransomware
  • microsoft exchange server
large≈10,000–100,000 internet-exposed on-premises Exchange servers
CVE-2023-21674
Use-After-Free Privilege Escalation in Microsoft Windows ALPC

CVE-2023-21674 is a use-after-free flaw (CWE-416) in the Windows Advanced Local Procedure Call (ALPC) facility, the kernel-level mechanism Windows uses for fast communication between processes and system services. An attacker who can already run code on a Windows machine can trigger the bug by sending crafted ALPC requests, corrupting memory in a privileged process. Successful exploitation allows a local, low-privileged attacker to elevate to SYSTEM/administrator privileges, typically to gain full control of the host or to complete an exploit chain after an initial compromise. Essentially all supported Windows client and server installations from Microsoft are affected; the source data does not list specific versions, and the fix shipped with Microsoft's January 2023 Patch Tuesday, which addressed a record 974 vulnerabilities including this and one other actively exploited Windows zero-day. CISA added the CVE to the Known Exploited Vulnerabilities catalog on 2023-01-10, confirming exploitation in the wild; no public proof-of-concept is known, ransomware use is undetermined, and EPSS estimates a 41.8% probability of exploitation in the next 30 days (99th percentile).

Do: Apply Microsoft's January 2023 (released 2023-01-10) or later Windows cumulative security updates to all Windows clients and servers, per CISA's required action to 'apply updates per vendor instructions.' Because this is a local privilege escalation, prioritize hosts where low-privileged users or untrusted code execute, such as endpoints, RDS/VDI servers, and multi-user systems, and verify installation via your update-management inventory. Treat this as actively exploited; with no public PoC or documented workaround, timely patching is the primary mitigation.

8.842% KEV
  • Microsoft Windows
mass≈1 billion+ Windows installations (Windows active installed base, nearly all unpatched-at-time systems in scope)
CVE-2023-21743
Microsoft SharePoint Server Security Feature Bypass Vulnerability

Microsoft SharePoint Server Security Feature Bypass Vulnerability

NVD description · AI analysis pending
5.31%
  • microsoft sharepoint server
CVE-2023-21763
Microsoft Exchange Server Elevation of Privilege Vulnerability

Microsoft Exchange Server Elevation of Privilege Vulnerability

NVD description · AI analysis pending
7.8<1%
  • microsoft exchange server
Full article610 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency added a recently revealed bug to its known exploited vulnerability list this week after Microsoft confirmed it was being used in attacks. 

CISA ordered all federal civilian agencies to patch CVE-2023-21674 by January 31. The bug –  first unveiled in Microsoft’s initial Patch Tuesday release of 2023 – affects the Windows Advanced Local Procedure Call (ALPC) and has a CVSS score of 8.8 out of a possible 10.

“An attacker who successfully exploited this vulnerability could gain SYSTEM privileges,” Microsoft said. 

The Zero Day Initiative’s Dustin Child said bugs like this are “often paired with some form of code exaction to deliver malware or ransomware” and added that because it was reported to Microsoft by researchers from Avast, “that scenario seems likely here.”

Qualys’ Saeed Abbasi agreed that the bugs are “are frequently leveraged in tandem with malware or ransomware delivery” while others noted that there is a working proof of concept for the vulnerability.

Several cybersecurity experts spotlighted the vulnerability as the most concerning of the nearly 100 vulnerabilities revealed on Tuesday. 

Automox’s Gina Geisel warned that because it has both a low attack complexity and low privileges required, the vulnerability requires no user interaction to be exploited. 

“To exploit this vulnerability, an attacker would first have to log on to the system, run a specially crafted application, and then take control of the affected system," Geisel said. "A successful attacker could then run arbitrary code in the security context of the local system and install programs enabling them to view, change, or delete data, or, worse case, create new accounts with full user rights. With an official fix for the zero day released from Microsoft for Windows 10, Windows 11, 8.1, through Windows Server 2022, Automox recommends patching within 24 hours.”

Mike Walters, VP of Vulnerability and Threat Research at Action1, said the vulnerability is significant because it affects millions of organizations.

In addition to CVE-2023-21674, CISA added another Microsoft bug from November – CVE-2022-41080 – to its catalog of exploited vulnerabilities.

Among the 11 critical bugs announced on Tuesday by Microsoft, Abbasi spotlighted CVE-2023-21743 – an issue affecting the security features of Microsoft SharePoint Server – and CVE-2023-21763, a Microsoft Exchange Server vulnerability. 

“Both Sharepoint and Exchange are critical tools that many organizations use to collaborate and complete daily tasks – making these vulnerabilities extremely attractive in the eyes of an attacker,” Abbasi said. 

The Patch Tuesday was also notable, according to N-able’s Lewis Pope, because it included the final security update for the widely used Windows 7 Professional and Enterprise. 

Windows 8.1 has reached end of support, and Microsoft 365 applications will no longer be receiving security updates for Windows 7 or Windows 8 versions, Pope said. 

“This now firmly cements the idea of using Windows 7 or 8.1 in production environments as an unacceptable risk in any environment following basic cybersecurity best practices,” Pope said. 

“According to Microsoft, the proper action is to upgrade systems with compatible hardware to Windows 10 or decommission those systems in favor of modern, supported operating systems. While there are always caveats and special use cases, budgets for 2023 should include appropriate funding to migrate all operations from any unsupported operating system.”

The first Patch Tuesday of the year also included security releases from Adobe, SAP and more.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-recently-announced-microsoft-zero-day-to-exploited-vulnerability-catalog