ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

Microsoft Uncovers Austrian Company Exploiting Windows and Adobe Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-28550
Use-After-Free RCE in Adobe Acrobat and Reader

CVE-2021-28550 is a use-after-free memory corruption flaw in Adobe Acrobat DC and Acrobat Reader DC that an unauthenticated attacker can trigger by getting a victim to open a malicious PDF file. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker the privileges of that user on the affected machine. Anyone running Acrobat or Acrobat Reader DC at or below versions 2021.001.20150, 2020.001.30020, or 2017.011.30194 is affected. The flaw was exploited as a zero-day in targeted attacks — Microsoft reported it being chained with Windows zero-days by an Austrian company's operators — and it is listed in CISA's Known Exploited Vulnerabilities catalog as of November 3, 2021. CISA's required action is to apply vendor updates, and defenders should treat exploited, user-targeted PDF attacks as the primary risk.

Do: Upgrade Acrobat and Acrobat Reader DC to versions later than 2021.001.20150, 2020.001.30020, and 2017.011.30194 on the respective tracks, per Adobe's May 2021 update and the CISA KEV required action. Until patched, avoid opening PDFs from untrusted sources and consider email-gateway filtering or sandboxing of PDF attachments. Check endpoint inventory for the affected version ranges and prioritize systems of users who handle unsolicited documents.

8.852% KEV
  • adobe Acrobat Reader DC 2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
  • adobe Acrobat DC 2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
  • adobe Acrobat affected per CISA (see DC ranges above)
  • +1 more
masshundreds of millions of installations (Acrobat Reader is the world's most widely deployed PDF viewer)
CVE-2021-31199
+1 in the same advisory: …31201
Elevation of Privilege in Microsoft Enhanced Cryptographic Provider (Windows)

CVE-2021-31199 is an elevation-of-privilege vulnerability in the Microsoft Enhanced Cryptographic Provider, a core Windows component that provides cryptographic services to applications. It carries a CVSS 3.1 score of 5.2 (AV:L/AC:L/PR:L/UI:N/S:C), meaning it is triggered by an attacker who already runs low-privileged code locally on a vulnerable Windows system, with no user interaction required, and lets the attacker break out of the intended security scope to gain elevated privileges. The gain is higher privileges on the compromised host, typically used as a stepping stone in a broader intrusion or malware delivery chain. Exposure is broad: any unpatched Windows 7, 8.1, RT 8.1, Windows 10 (versions 1507 through 21H1), Windows Server 2008, or Windows Server 2004 system is affected, since the provider ships with Windows itself. Exploitation is confirmed in the wild: it was one of the actively exploited Windows zero-days fixed in Microsoft's mid-2021 Patch Tuesday release (part of the six/seven-zero-day coverage), Microsoft attributed targeted attacks to the Austrian firm DSIRF using its Subzero surveillance malware, and the flaw was added to CISA's KEV on 2021-11-03; EPSS estimates a 3.0% chance of exploitation in the next 30 days (86th percentile) and no public PoC is known.

Do: Apply Microsoft's security updates (the monthly Patch Tuesday cumulative updates covering this CVE) per vendor instructions for every in-scope Windows version — the flaw is in CISA KEV, so patching is mandatory for federal agencies and there is no documented workaround. Verify hosts have received the updated cumulative update, prioritizing multi-user endpoints, RDP/terminal servers, and workstations where untrusted code runs; if patching is delayed, hunt for signs of targeted intrusion consistent with DSIRF/Subzero activity.

5.23% KEV
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all supported builds at time of disclosure
  • microsoft Windows 8.1 all supported builds
  • +3 more
mass≈1 billion+ Windows devices (Windows 10 alone had over 1 billion active devices, and the affected set also includes Windows 7/8.1/RT 8.1 and Windows Server…
CVE-2021-36948
Privilege Escalation in Microsoft Windows Update Medic Service

CVE-2021-36948 is an elevation-of-privilege flaw in the Microsoft Windows Update Medic Service (WaaSMedicSvc), the built-in service that keeps Windows Update functioning; Microsoft has not publicly detailed the underlying bug. A local attacker who can execute code on a target machine can abuse the service to elevate their privileges to higher integrity levels, typically SYSTEM, enabling full control of the host such as installing software, modifying accounts, and disabling defenses. Any Windows system running the Windows Update Medic Service is affected; CISA lists the impacted product simply as 'Microsoft Windows' without version detail, and the service ships with Windows 10 and later. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03, indicating confirmed exploitation in the wild, with no public proof-of-concept code known and ransomware use undetermined. Microsoft's EPSS model assigns a 26.7% probability of exploitation within 30 days (98th percentile), so patching urgency is high.

Do: Apply Microsoft's November 2021 Patch Tuesday cumulative updates (per the vendor's advisory) via Windows Update or your patch management platform, prioritizing servers, workstations, and multi-user hosts where local privilege escalation is most damaging. Since CISA lists this in KEV, federal and regulated environments must patch by the catalog deadline; as an interim mitigation, restrict untrusted local code execution and review whether any local accounts show unexpected SYSTEM-level activity.

7.823% KEV
  • Microsoft Windows (systems running the Windows Update Medic Service; Windows 10 and later) CISA lists affected product as 'Microsoft Windows' without version detail; remediated in Microsoft's November 2021 security updates
mass≈1 billion+ Windows devices (the Medic Service ships on effectively every Windows 10/11 machine)
CVE-2022-22047
Local Privilege Escalation in Windows CSRSS Affects Nearly All Windows Versions

CVE-2022-22047 is an elevation-of-privilege vulnerability in the Windows Client Server Run-time Subsystem (CSRSS), a core user-mode process that handles console and system tasks, caused by an untrusted search path (CWE-426). An attacker who already has a low-privileged foothold on a Windows machine can trigger the flaw locally, with no user interaction, to elevate to SYSTEM/administrator-level privileges. Because CSRSS is present on essentially every Windows installation, the affected population spans Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012, meaning virtually every Windows desktop, laptop, and server in active use is potentially affected. The vulnerability is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on July 12, 2022 with an August 2 patch deadline for federal agencies, and EPSS assigns it an 18.8% probability of exploitation within 30 days (97th percentile).

Do: Apply Microsoft's July 12, 2022 (Patch Tuesday) security updates immediately across all affected releases, including Windows 7, 8.1, RT 8.1, and Server 2008/2012, where fixes arrive through the same July update servicing; CISA's KEV deadline for federal agencies is August 2, 2022. Treat any host where a local attacker has executed code as potentially compromised to SYSTEM level, and hunt for post-exploitation activity. Keep monitoring vendor guidance, as recent reporting suggests some patched Windows attack surfaces may still be exploitable, so continue applying follow-on Windows updates as they ship.

7.819% KEV
  • microsoft Windows 10 1507
  • microsoft Windows 10 1607
  • microsoft Windows 10 1809
  • +9 more
mass≈1 billion+ Windows devices and servers (the affected list spans Windows 7 through Windows 11 and legacy server releases)
Full article836 words · extracted from thehackernews.com · click to collapse

A cyber mercenary that "ostensibly sells general security and information analysis services to commercial customers" used several Windows and Adobe zero-day exploits in limited and highly-targeted attacks against European and Central American entities.

The company, which Microsoft describes as a private-sector offensive actor (PSOA), is an Austria-based outfit called DSIRF that's linked to the development and attempted sale of a piece of cyberweapon referred to as Subzero, which can be used to hack targets' phones, computers, and internet-connected devices.

"Observed victims to date include law firms, banks, and strategic consultancies in countries such as Austria, the United Kingdom, and Panama," the tech giant's cybersecurity teams said in a Wednesday report.

Microsoft is tracking the actor under the moniker KNOTWEED, continuing its trend of terming PSOAs using names given to trees and shrubs. The company previously designated the name SOURGUM to Israeli spyware vendor Candiru.

KNOTWEED is known to dabble in both access-as-a-service and hack-for-hire operations, offering its toolset to third parties as well as directly associating itself in certain attacks.

While the former entails the sales of end-to-end hacking tools that can be used by the purchaser in their own operations without the involvement of the offensive actor, hack-for-hire groups run the targeted operations on behalf of their clients.

The deployment of Subzero is said to have transpired through the exploitation of numerous issues, including an attack chain that abused an unknown Adobe Reader remote code execution (RCE) flaw and a zero-day privilege escalation bug (CVE-2022-22047), the latter of which was addressed by Microsoft as part of its July Patch Tuesday updates.

"The exploits were packaged into a PDF document that was sent to the victim via email," Microsoft explained. "CVE-2022-22047 was used in KNOTWEED related attacks for privilege escalation. The vulnerability also provided the ability to escape sandboxes and achieve system-level code execution."

Similar attack chains observed in 2021 leveraged a combination of two Windows privilege escalation exploits (CVE-2021-31199 and CVE-2021-31201) in conjunction with an Adobe reader flaw (CVE-2021-28550). The three vulnerabilities were resolved in June 2021.

The deployment of Subzero subsequently occurred through a fourth exploit, this time taking advantage of a privilege escalation vulnerability in the Windows Update Medic Service (CVE-2021-36948), which was closed by Microsoft in August 2021.

Beyond these exploit chains, Excel files masquerading as real estate documents have been used as a conduit to deliver the malware, with the files containing Excel 4.0 macros designed to kick-start the infection process.

Regardless of the method employed, the intrusions culminate in the execution of shellcode, which is used to retrieve a second-stage payload called Corelump from a remote server in the form of a JPEG image that also embeds a loader named Jumplump that, in turn, loads Corelump into memory.

The evasive implant comes with a wide range of capabilities, including keylogging, capturing screenshots, exfiltrating files, running a remote shell, and running arbitrary plugins downloaded from the remote server.

Also deployed during the attacks were bespoke utilities like Mex, a command-line tool to run open source security software like Chisel, and PassLib, a tool to dump credentials from web browsers, email clients, and the Windows credential manager.

Microsoft said it uncovered KNOTWEED actively serving malware since February 2020 through infrastructure hosted on DigitalOcean and Choopa, alongside identifying subdomains that are used for malware development, debugging Mex, and staging the Subzero payload.

Multiple links have also been unearthed between DSIRF and the malicious tools used in KNOTWEED's attacks.

"These include command-and-control infrastructure used by the malware directly linking to DSIRF, a DSIRF-associated GitHub account being used in one attack, a code signing certificate issued to DSIRF being used to sign an exploit, and other open-source news reports attributing Subzero to DSIRF," Redmond noted.

Subzero is no different from off-the-shelf malware such as Pegasus, Predator, Hermit, and DevilsTongue, which are capable of infiltrating phones and Windows machines to remotely control the devices and siphon off data, sometimes without requiring the user to click on a malicious link.

If anything, the latest findings highlight a burgeoning international market for such sophisticated surveillance technologies to carry out targeted attacks aimed at members of civil society.

Although companies that sell commercial spyware advertise their wares as a means to tackle serious crimes, evidence gathered so far has found several instances of these tools being misused by authoritarian governments and private organizations to snoop on human rights advocates, journalists, dissidents, and politicians.

Google's Threat Analysis Group (TAG), which is tracking over 30 vendors that hawk exploits or surveillance capabilities to state-sponsored actors, said the booming ecosystem underscores "the extent to which commercial surveillance vendors have proliferated capabilities historically only used by governments."

"These vendors operate with deep technical expertise to develop and operationalize exploits," TAG's Shane Huntley said in a testimony to the U.S. House Intelligence Committee on Wednesday, adding, "its use is growing, fueled by demand from governments."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/07/microsoft-uncover-austrian-company.html