ZeroHour
Security Affairspublished ()ingested @securityaffairs

Lazarus employed an exploit in a Dell firmware driver in recent attacks

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-21551
Local Privilege Escalation in Dell dbutil_2_3.sys Driver

CVE-2021-21551 is an insufficient access control flaw (CWE-782) in Dell's dbutil_2_3.sys driver, present on Dell systems for roughly 12 years before being patched. A local, authenticated user can trigger the flaw by sending crafted requests (IOCTLs) to the driver, gaining the ability to read and write arbitrary memory. An attacker who exploits it can escalate privileges (typically to kernel/SYSTEM level), cause a denial of service, or disclose information, making it a useful stepping stone for post-compromise attacks. Any Dell machine that shipped or ran the dbutil driver — used in Dell support and BIOS/BIOS-update tooling — is affected, and public reporting indicates hundreds of millions of Dell PCs are exposed. The flaw is actively exploited: it is listed in CISA's Known Exploited Vulnerabilities Catalog (added 2022-03-31), public PoCs exist, and the Lazarus APT reportedly used it in attacks to deploy a rootkit; EPSS puts the 30-day exploitation probability at 79.2%.

Do: Apply Dell's updated driver/firmware per vendor instructions, as required by CISA's KEV catalog. Inventory your fleet for the dbutil_2_3.sys driver file (commonly found with Dell support tools and BIOS update utilities) and prioritize patching endpoints, since the bug requires only local user access. Hunt for signs of local privilege-escalation activity consistent with public PoCs, given documented Lazarus APT use to deploy a rootkit.

7.879% KEV PoC ×2
  • Dell dbutil driver (dbutil_2_3.sys) dbutil_2_3.sys as identified in the advisory; source data provides no detailed fixed-version range, so check for the presence of dbutil_2_3.sys on Dell systems
masshundreds of millions of Dell PCs (the driver was broadly distributed with Dell support/update tooling for over a decade)
Full article531 words · extracted from securityaffairs.com · click to collapse

North Korea-linked Lazarus APT has been spotted deploying a Windows rootkit by taking advantage of an exploit in a Dell firmware driver.

The North Korea-backed Lazarus Group has been observed deploying a Windows rootkit by relying on exploit in a Dell firmware driver dbutil_2_3.sys, ESET researchers warn.

The discovery was made by ESET researchers while investigating attacks conducted by the APT group against an employee of an aerospace company in the Netherlands, and a political journalist in Belgium during the autumn of 2021. Threat actors sent spear-phishing emails using malicious Amazon-themed documents as lures.

The attacks outstand for the use of a tool that represents the first recorded abuse of the CVE-2021-21551 vulnerability in Dell DBUtil drivers, which Dell addressed in May 2021.

ESET experts presented their findings at this year’s Virus Bulletin conference highlighting the use of vulnerable drivers in the attack chain, defining the technique as Bring Your Own Vulnerable Driver (BYOVD).

The experts spotted a dynamically linked library, codenamed FudModule.dll, that tries to disable various Windows monitoring features. The library modify kernel variables and remove kernel callbacks in the attempt to disable the features.

The experts pointed out that the attackers used the tool, in combination with the vulnerability, to disable the monitoring of all security solutions on compromised machines. It uses techniques against Windows kernel mechanisms that have never been observed in malware before.

“The attackers then used their kernel memory write access to disable seven mechanisms the Windows operating system offers to monitor its actions, like registry, file system, process creation, event tracing etc., basically blinding security solutions in a very generic and robust way.” reads the post published by the experts.

Threat actors sent job offers to the targets, the employee of the aerospace company in the Netherlands received an attachment via LinkedIn Messaging, while the journalists in Belgium received a document via email. Upon opening the documents that attack chain started, threat actors were able to deploy multiple malicious tools on each system, including droppers, loaders, fully featured HTTP(S) backdoors, HTTP(S) uploaders and downloaders. The droppers were trojanized open-source projects that decrypt the embedded payload, in many cases the attackers side-loaded binaries to run the malicious code.

ESET also reported that the Lazarus group was dropping weaponized versions of FingerText and sslSniffer, a component of the wolfSSL project.

The attackers also employed known malware like BLINDINGCAN that was used to establish a backdoor into the compromised infrastructure.

“In this attack, as well as in many others attributed to Lazarus, we saw that many tools were distributed even on a single targeted endpoint in a network of interest. Without a doubt, the team behind the attack is quite large, systematically organized, and well prepared. For the first time in the wild, the attackers were able to leverage CVE-2021-21551 for turning off the monitoring of all security solutions.” concludes the report. “It was not just done in kernel space, but also in a robust way, using a series of little- or undocumented Windows internals. Undoubtedly this required deep research, development, and testing skills.”

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Lazarus)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/136623/apt/lazarus-exploit-dell-firmware-driver.html