ZeroHour
Security Affairspublished ()ingested @securityaffairs

Google discloses Windows zero-day actively exploited in targeted attacks

criticalExploit / PoC exploited in the wildimportance 60CVE-2019-5786

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-5786
Actively Exploited Use-After-Free in Google Chrome Blink

CVE-2019-5786 is a use-after-free (object lifetime) flaw in Blink, the rendering engine of Google Chrome, fixed in Chrome 72.0.3626.121. A remote attacker triggers it by luring a user to a crafted HTML page, where the stale object allows an out-of-bounds memory access within the renderer process. Successful exploitation produces memory corruption in the browser renderer — scored in the CVSS vector primarily as high availability impact — and Google disclosed the flaw being actively exploited in targeted attacks, reportedly chained with a separate Windows zero-day that Microsoft patched out of band in March 2019. Anyone running Chrome older than 72.0.3626.121 was affected, which at disclosure time meant a large share of Chrome's billion-plus desktop user base. Exploitation is confirmed in the wild: the issue was a zero-day before the patch, it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-23, and EPSS assigns a ~61.5% probability of exploitation within 30 days (99th percentile).

Do: Update Chrome to 72.0.3626.121 or later — verify via the browser's About/Settings help page and relaunch any pending auto-update, since Chrome self-updates but requires a relaunch. Treat as a KEV priority and patch per vendor instructions, and apply Microsoft's March 2019 updates, including the out-of-band Windows fix, because the Chrome flaw was used in combination with a Windows zero-day in the observed targeted attacks.

6.562% KEV PoC
  • Google Chrome all versions prior to 72.0.3626.121 (Blink rendering engine)
mass≈1 billion+ Chrome users/installations at the time (all Chrome deployments on versions before 72.0.3626.121)
Full article355 words · extracted from securityaffairs.com · click to collapse

Google this week revealed a Windows zero-day that is being actively exploited in targeted attacks alongside a recently fixed Chrome flaw.

Google this week disclosed a Windows zero-day vulnerability that is being actively exploited in targeted attacks alongside a recently addressed flaw in Chrome flaw (CVE-2019-5786).

The Windows zero-day vulnerability is a local privilege escalation issue in the win32k.sys kernel driver and it can be exploited for security sandbox escape.

“It is a local privilege escalation in the Windows win32k.sys kernel driver that can be used as a security sandbox escape.” reads the post published by Google.

“The vulnerability is a NULL pointer dereference in win32k!MNGetpItemFromIndex when NtUserMNDragOver() system call is called under specific circumstances,”

Experts argue the Windows zero-day could be exploited only on Windows 7 due to recent exploit mitigations added in newer versions of Microsoft OS. To date, experts only observed active exploitation against Windows 7 32-bit systems.

This time, Google decided immediately disclose the issue because the Windows zero-day is being actively exploited in targeted attacks.

The tech giant reported the bug to Microsoft last week and a patch isn’t available yet.

“Pursuant to Google’s vulnerability disclosure policy, when we discovered the vulnerability we reported it to Microsoft. Today, also in compliance with our policy, we are publicly disclosing its existence, because it is a serious vulnerability in Windows that we know was being actively exploited in targeted attacks.” continues the post.

“The unpatched Windows vulnerability can still be used to elevate privileges or combined with another browser vulnerability to evade security sandboxes. Microsoft have told us they are working on a fix,”

At the time, the only way to mitigate the flaw is to upgrade their systems to Windows 10, of course, the experts recommend to apply patches as soon as they become available.

According to Google, targeted attacks involving the Windows zero-day also exploited the Chrome vulnerability recently fixes by Google.

Google addressed the issue by rolling out a stable Chrome update 72.0.3626.121 for Windows, Mac, and Linux operating systems.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – Windows zero-day, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/82159/breaking-news/windows-zero-day-3.html