CVE-2017-0022 Windows Zero-Day flaw used by AdGholas hackers and it was included in Neutrino EK
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-3298 | Information Disclosure in Microsoft Internet Explorer Messaging API CVE-2016-3298 is an information disclosure flaw (CWE-200) in the Microsoft Internet Messaging API used by Internet Explorer, in which the API improperly handles objects in memory. Exploitation requires driving Internet Explorer to process attacker-influenced content so the Messaging API mishandles memory, after which the attacker can probe whether specific files exist on the victim's disk. An attacker gains only limited reconnaissance value — confirming file presence for fingerprinting — rather than code execution or direct data theft. Only systems running Microsoft Internet Explorer, as cataloged by CISA, are affected; CISA added the bug to the Known Exploited Vulnerabilities catalog on 2022-05-24, confirming exploitation in the wild, though any ransomware association is unknown. EPSS estimates a 32.8% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and a CVSS score has not yet been published in this dataset. Do: Apply Microsoft's security update for CVE-2016-3298 per vendor instructions, as mandated by the CISA KEV catalog (added 2022-05-24, so remediation deadlines apply to federal agencies and many regulated environments). Audit any Windows hosts where Internet Explorer is still used for interactive browsing and confirm the patch is installed; because the flaw only permits probing for file existence, residual risk after patching is low. | 6.5 | 33% | KEV |
| masshundreds of millions of Windows devices (Internet Explorer shipped as a built-in Windows component for decades) | |
| CVE-2016-3351 | Information Disclosure in Microsoft Internet Explorer and Edge CVE-2016-3351 is an information disclosure flaw in the way Internet Explorer and Microsoft Edge handle objects in memory. An attacker can trigger it by getting the browser to process attacker-controlled content, such as a malicious or compromised web page, and thereby determine the presence of specific files on the user's computer. This file-detection capability is useful for profiling a victim machine and is commonly used as a reconnaissance step in broader attack chains. All users of Internet Explorer and Microsoft Edge on affected Microsoft products are impacted; the flaw carries CWE-200 (information exposure) and no CVSS score is available. It was added to the CISA Known Exploited Vulnerabilities catalog on 2022-05-24 with known ransomware use, and EPSS assigns it a 26.3% probability of exploitation within 30 days (98th percentile). Do: Apply Microsoft security updates per vendor instructions, as required by the CISA KEV catalog entry, prioritizing internet-facing and user workstations given known ransomware use. Because legacy Internet Explorer is end-of-life, retire or restrict IE usage where possible and confirm that both IE and Edge builds on Windows hosts are fully patched. Hunt for exploitation activity involving browser-based file-detection probes on endpoints in your environment. | 6.5 | 26% | KEV ransomware PoC |
| masshundreds of millions of Windows devices (both browsers shipped with Windows) | |
| CVE-2017-0022 | Information Disclosure in Microsoft XML Core Services (MSXML) on Windows Microsoft XML Core Services (MSXML) on supported Windows client and server releases improperly handles objects in memory, allowing a remote attacker to test whether specific files exist on a victim's disk. The flaw is triggered when a user is lured to a crafted website (user interaction is required), typically via browser-delivered web content rather than through a network service. A successful attacker gains only information about file presence on disk, which is useful for reconnaissance in follow-on attacks but does not directly enable code execution. Essentially every Windows version of that era is affected, from Vista SP2 through Windows 10 1607 and Windows Server 2016, so the affected population is the broad Windows installed base at the time. The vulnerability is in CISA's Known Exploited Vulnerabilities catalog (added 2022-05-24) and public analysis documents its use by exploit kits, so in-the-wild exploitation is confirmed. Do: Apply Microsoft's security updates across all affected Windows releases as CISA's KEV required action specifies, prioritizing end-user workstations and multi-user systems where web browsing occurs. For legacy systems that no longer receive patches (Vista SP2, Server 2008), upgrade, restrict users from untrusted web content, or consider micro-patching; when auditing older images, verify the MSXML update is installed. | 6.5 | 18% | KEV PoC |
| masshundreds of millions of Windows devices (MSXML ships with every affected Windows release, Vista through Windows 10 1607) |
Full article484 words · extracted from securityaffairs.com · click to collapse

The recently patched CVE-2017-0022 Windows Zero-Day vulnerability has been exploited by threat actors behind the AdGholas malvertising campaign and Neutrino EK since July 2016.
Microsoft has fixed several security flaws with the March 2017 Patch Tuesday updates. According to security experts at Trend Micro, the list of fixed vulnerabilities includes three flaws that had been exploited in the wild since last summer.
One of the vulnerabilities, is an XML Core Services information disclosure vulnerability, tracked as CVE-2017-0022, that can be exploited by attackers by tricking victims into clicking on a specially crafted link.
“An information vulnerability exists when Microsoft XML Core Services (MSXML) improperly handles objects in memory. Successful exploitation of the vulnerability could allow the attacker to test for the presence of files on disk.” reads the security advisory published by Microsoft.
“To exploit the vulnerability, an attacker could host a specially-crafted website that is designed to invoke MSXML through Internet Explorer. However, an attacker would have no way to force a user to visit such a website. Instead, an attacker would typically have to convince a user to either click a link in an email message or a link in an Instant Messenger request that would then take the user to the website.”
The flaw was discovered by a joint investigation conducted by security researchers at Trend Micro and ProofPoint, it was reported to Microsoft in September 2016.
Who did exploit the CVE-2017-0022 flaw?
According to the security researchers at Trend Micro, the zero-day vulnerability has been exploited in the AdGholas malvertising campaign since July 2016. The exploit code of the flaw was added to the Neutrino exploit kit in September 2016.
The threat actor behind the AdGholas malvertising campaign was notable for its use of steganography and careful targeting of the massive volume of malicious ads and impressions and its ability to avoid detection of researchers.
Initially the attackers leveraged the CVE-2016-3298 and CVE-2016-3351 flaws to avoid detection, now the experts at TrendMicro speculate they used the CVE-2017-0022 flaw for the same purpose.
“This vulnerability was used in the AdGholas malvertising campaign and later integrated into the Neutrino exploit kit. CVE-2017-0022 likely replaced the similar CVE-2016-3298 and CVE-2016-3351 vulnerabilities from the same campaign, which were addressed by previous patches.” reads the analysis published by TrendMicro.

“An attacker exploiting CVE-2017-0022 could use phishing attacks to lure potential targets to malicious websites. Successful exploitation of this vulnerability could allow a cybercriminal access to information on the files found in the user’s system.” explained the experts from TrendMicro. “In particular, the attacker would be able to detect if the system is using specific security solutions—especially ones that analyze malware.”
Trend Micro has published a detailed analysis of the CVE-2017-0022 flaw and of the attack chain that exploits it in a malvertising campaign leveraging the Neutrino exploit kit.
[adrotate banner=”9″]
(Security Affairs – CVE-2017-0022, AdGholas malvertising campaign)
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/57408/malware/cve-2017-0022-flaw-adgholas.html