ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

3CX compromise: More details about the breach, new PWA app released

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2013-3900
Authenticode Signature Verification Flaw in Microsoft WinVerifyTrust (RCE)

Microsoft's WinVerifyTrust function improperly validates Windows Authenticode signatures on portable executable (PE) files, allowing crafted modifications to a signed binary — such as altered sections or checksum-table manipulation — to still pass signature verification. An attacker who tampers with a legitimately signed executable can distribute modified files that Windows and dependent security controls treat as authentic, gaining the trust of a valid digital signature and, ultimately, remote code execution in contexts that rely on signature checks. Any Microsoft Windows platform performing Authenticode verification through WinVerifyTrust is affected; the source data does not list specific Windows version ranges, but because WinVerifyTrust is core Windows functionality the exposure is very broad. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-01-10, indicating confirmed in-the-wild exploitation, and EPSS puts its 30-day exploitation probability at about 44.6% (99th percentile), though no public PoC is known.

Do: Apply Microsoft's updates for CVE-2013-3900 across all Windows systems per vendor instructions, as required for CISA KEV entries. Where supported, enable Microsoft's stricter certificate padding check (EnableCertPaddingCheck) per Microsoft guidance to harden signature verification against this bypass. Prioritize patching endpoints and servers that execute or validate downloaded, emailed, or otherwise externally sourced signed binaries, given confirmed exploitation and high EPSS.

45% KEV
  • Microsoft WinVerifyTrust function (Windows Authenticode signature verification for PE files)
masshundreds of millions of Windows devices (near-universal across the Windows installed base)
CVE-2021-45491
3CX System through 2022-03-17 stores cleartext passwords in a database.

3CX System through 2022-03-17 stores cleartext passwords in a database.

NVD description · AI analysis pending
6.5<1%
  • 3cx 3cx
Full article412 words · extracted from helpnetsecurity.com · click to collapse

3CX has released an interim report about Mandiant’s findings related to the compromise the company suffered last month, which resulted in a supply chain attack targeting cryptocurrency companies.

They discovered that:

  • The attackers infected targeted 3CX systems with TAXHAUL (aka “TxRLoader”) malware, which decrypts and executes shellcode containee in a file with a name and location aimed to make it to blend into standard Windows installations
  • The executed shellcode is the COLDCAT downloader
  • They also found SIMPLESEA – a macOS backdoor – with command execution, file transfer, file execution, file management, and configuration updating capabilities

“On Windows, the attacker used DLL side-loading to achieve persistence for TAXHAUL malware. DLL side-loading triggered infected systems to execute the attacker’s malware within the context of legitimate Microsoft Windows binaries, reducing the likelihood of malware detection. The persistence mechanism also ensures the attacker malware is loaded at system start-up, enabling the attacker to retain remote access to the infected system over the internet,” Pierre Jourdan, the company’s CISO, explained.

“The malware was named C:\Windows\system32\wlbsctrl.dll to mimic the legitimate Windows binary of the same name. The DLL was loaded by the legitimate Windows service IKEEXT through the legitimate Windows binary svchost.exe.”

Mandiant still attributes the activity to a threat actor with a North Korean nexus.

As noted before, the DLL file used for sideloading was signed by Microsoft and the signature was not invalidated once the file was modified because the attackers exploited CVE-2013-3900. (Microsoft republished the vulnerability on Tuesday, but the fix is still optional.)

A new 3CX PWA version

CEO Nick Galea has announced a security update of the progressive web app (PWA) version of the 3CX software, which allows users to use 3CX from any browser.

The new version will hash all web passwords in the system.

“It doesn’t mean [the passwords] were completely insecure before. You still needed admin rights to access them. But it’s not good practice and it’s been the subject of CVE-2021-45491,” he said.

“Although we’ll be releasing a new version of the DesktopApp soon, we still believe for network management reasons it’s good to use the PWA app where possible. All users that use a deskphone or an Android/iOS app for the actual calling should use the PWA client.”

The company will also be removing the password for the web client and the configuration file from welcome emails, and will provide the option of restricting access to the Admin section in the web client by IP address.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/04/12/3cx-compromise-more-details-about-the-breach-new-pwa-app-released/