ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

CISA Warns of Active Exploitation of JetBrains and Windows Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-31462
+4 in the same advisory: …31460 …31463 …31461 …31459
Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth bro

Owl Labs Meeting Owl 5.2.0.15 allows attackers to control the device via a backdoor password (derived from the serial number) that can be found in Bluetooth broadcast data.

NVD description · AI analysis pending
8.8
group max
<1% PoC
  • owllabs meeting owl pro firmware
CVE-2023-28229
Windows CNG Key Isolation Service Local Privilege Escalation (CVE-2023-28229)

CVE-2023-28229 is an elevation-of-privilege vulnerability in the Windows CNG Key Isolation Service (KeyIso), the component that isolates and protects private keys used for cryptographic operations on Windows. A local attacker with low privileges can trigger the flaw inside the service under specific conditions (CVSS attack complexity is high); no user interaction is required. Successful exploitation grants elevated privileges with high impact on confidentiality, integrity, and availability, effectively full control of the affected host, and is typically used to strengthen a low-privileged foothold already gained via another flaw. All supported Windows 10 releases (1507 through 22H2), Windows 11 21H2 and 22H2, and Windows Server 2008, 2012, 2016, and 2019 are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-10-04, indicating active exploitation; no public proof-of-concept is known and ransomware use is listed as unknown.

Do: Apply Microsoft's October 2023 security updates (or later cumulative updates) on all affected Windows 10, Windows 11, and Windows Server systems, prioritizing multi-user hosts such as RDS/VDI servers and endpoints used by potentially compromised accounts, since exploitation requires local access. Verify patch status via your patch-management inventory and hunt for signs of local privilege escalation on hosts missing the fix. Note that the related KEV batch also flagged JetBrains TeamCity (CVE-2023-42793), which should be patched separately if deployed.

7.02% KEV
  • microsoft Windows 10 1507, 1607, 1809, 20H2, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2
  • microsoft Windows Server 2008, 2012, 2016, 2019
mass1 billion+ Windows devices (essentially the entire supported Windows 10/11 client base plus Windows Server 2008-2019)
CVE-2023-42793
Authentication bypass in JetBrains TeamCity enables unauthenticated RCE

JetBrains TeamCity Server, a widely used CI/CD build server, contains an authentication bypass vulnerability (CWE-288) that lets a remote, unauthenticated attacker gain administrative access without valid credentials. By sending crafted requests to the TeamCity server over the network, the attacker bypasses authentication and can then execute arbitrary code on the server via administrative and build features, achieving full remote code execution. An attacker gains control of the build server and, with it, access to source code, build artifacts, stored secrets and credentials, and a foothold for lateral movement or ransomware deployment. Any organization running an affected TeamCity Server is affected, especially instances reachable from the internet. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2023-10-04 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days.

Do: Upgrade TeamCity Server to 2023.05.4 or later per JetBrains' instructions, or apply vendor mitigations or discontinue use if patching is not possible (per the CISA KEV required action). Also take unpatched instances off the public internet, and hunt for signs of compromise such as unauthorized administrator accounts, unexpected changes in audit logs and build configurations, and stored secrets or tokens that may have been stolen, given known ransomware exploitation.

9.8100% KEV ransomware PoC ×2
  • JetBrains TeamCity (TeamCity Server) On-premises TeamCity Server prior to the fixed release (2023.05.4 per the vendor advisory); the CISA entry lists the affected product without a version range
largeTens of thousands of TeamCity Server deployments, of which several thousand are internet-exposed
Full article306 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 05, 2023Vulnerability / Cyber Attack

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation, while removing five bugs from the list due to lack of adequate evidence.

The vulnerabilities newly added are below -

  • CVE-2023-42793 (CVSS score: 9.8) - JetBrains TeamCity Authentication Bypass Vulnerability
  • CVE-2023-28229 (CVSS score: 7.0) - Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

CVE-2023-42793 relates to a critical authentication bypass vulnerability that allows for remote code execution on TeamCity Server. Data gathered by GreyNoise has revealed exploitation attempts targeting the flaw from 74 unique IP addresses to date.

On the other hand, CVE-2023-28229 is a high-severity flaw in the Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service that allows an attacker to gain specific limited SYSTEM privileges.

There are currently no public reports documenting in-the-wild exploitation of the bug, and CISA has not disclosed any further details about the attacks or exploitation scenarios. A proof-of-concept (PoC) was made available early last month.

Microsoft, for its part, tagged CVE-2023-28229 with an "Exploitation Less Likely" assessment. It was patched by the tech giant as part of Patch Tuesday updates released in April 2023.

The cybersecurity agency has also removed five flaws affecting Owl Labs Meeting Owl from the KEV catalog, citing "insufficient evidence."

While CVE-2022-31460 was added in June 2022, four other vulnerabilities (CVE-2022-31459, CVE-2022-31461, CVE-2022-31462, and CVE-2022-31463) were added on September 18, 2023.

In light of the active exploitation of the two flaws, Federal Civilian Executive Branch (FCEB) agencies are required to apply the vendor-provided patches by October 25, 2023, to secure their networks against potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/10/cisa-warns-of-active-exploitation-of.html