ZeroHour
The Recordpublished ()ingested

CISA tells agencies to patch recent Windows 10 zero

criticalVulnerability exploited in the wildimportance 60CVE-2021-4102CVE-2021-43890

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-4102
Use-After-Free Zero-Day in Google Chrome's V8 JavaScript Engine

CVE-2021-4102 is a use-after-free (CWE-416) in the V8 JavaScript engine of Google Chrome, fixed in Chrome 96.0.4664.110. It is triggered remotely when a user is lured to a crafted HTML page (per the CVSS vector, network attack vector with required user interaction), allowing the attacker to trigger heap corruption in the browser process. Successful exploitation could give the attacker control over corrupted heap memory with high confidentiality, integrity, and availability impact, though no public proof-of-concept is known. Anyone running Google Chrome prior to 96.0.4664.110 is affected, and because CISA frames the flaw in Chromium's V8, Chromium-based browsers that had not yet merged the equivalent fix were also potentially exposed. The bug is a confirmed zero-day: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-12-15, and press coverage counts it as the 17th Chrome zero-day fixed in 2021.

Do: Update Google Chrome to 96.0.4664.110 or later on all systems and restart the browser to load the patched engine; this satisfies CISA's required action to apply updates per vendor instructions. Inventory enterprise endpoints to confirm no clients remain below 96.0.4664.110, and users of Chromium-derived browsers should apply the corresponding vendor update as soon as it is released. Until patched, exercise caution with untrusted web links, as exploitation requires visiting attacker-controlled HTML content.

8.88% KEV
  • Google Chrome prior to 96.0.4664.110
  • Google Chromium (V8 engine) V8 component as designated by CISA; Chromium version range not specified in source data (fix shipped in Chrome 96.0.4664.110)
mass≈3 billion Chrome users/installs (Chrome is the world's dominant desktop browser)
CVE-2021-43890
Spoofing Vulnerability in Microsoft Windows AppX Installer Actively Exploited

CVE-2021-43890 is a spoofing vulnerability in the AppX Installer (App Installer) component of Microsoft Windows that allows a specially crafted package to masquerade as a trusted application. Triggering it requires user interaction: an attacker distributes a malicious installer package or ms-appinstaller link, typically via phishing, and must convince the user to open it, with impact limited to the privileges of the affected account. Successful exploitation delivers malware — Microsoft observed the Emotet, Trickbot and BazaLoader families in these attacks — and the flaw has also been used in ransomware campaigns, with users operating with administrative rights facing greater impact than low-privileged users. Essentially any Windows system relying on App Installer is affected; the exact affected build ranges are not enumerated in the advisory data, though contemporaneous headlines characterized it as an actively exploited Windows 10 zero-day addressed in the December 2021 Patch Tuesday. Exploitation is confirmed in the wild: CISA added it to KEV on 2021-12-15 with known ransomware use (EPSS 10.3% / 95th percentile), and in late 2023 Microsoft Threat Intelligence reported renewed abuse of the ms-appinstaller URI scheme and disabled that protocol by default in the updated App Installer.

Do: Apply Microsoft's security updates per the vendor advisory (December 2021 Windows updates) and install the updated App Installer using the Microsoft Store links in the advisory. Verify the updated App Installer is in place and that the ms-appinstaller protocol handler is disabled — it is disabled by default in the December 27, 2023 App Installer update. Because exploitation depends on users opening crafted packages, prioritize patching systems where users run with administrative rights and remind users to treat app-installer links and attachments arriving via email or chat with caution.

7.110% KEV ransomware PoC
  • microsoft App Installer (AppX Installer)
  • microsoft Windows
mass~1 billion+ Windows devices (App Installer ships as a built-in Windows component)
Full article237 words · extracted from therecord.media · click to collapse

CISA has ordered federal civilian agencies to patch two zero-days disclosed this week in products like Google Chrome and Windows 10.

The urgency comes as the two vulnerabilities have already been exploited even before Google and Microsoft released patches on Monday and Tuesday, respectively.

While details about the attacks against Chrome users are not available, Microsoft said the Windows 10 zero-day was under large-scale abuse by several malware botnets.

In these attacks, users would receive a malicious AppX installer via email that, when executed, would grant attackers access to run code on their systems.

Microsoft said it observed phishing campaigns abuse this vulnerability to install malware strains like Emotet, TrickBot and BazarLoader, all of which have been seen over the past year as staging steps for deploying ransomware.

"These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise," CISA said on Wednesday.

As a result, CISA added the two zero-days to a database of known actively exploited vulnerabilities it launched last month and has given federal agencies until December 29 to patch the two bugs.

The Chrome zero-day is tracked as CVE-2021-4102, while the Windows 10 AppX zero-day is tracked as CVE-2021-43890.

This is the second update to CISA's known-exploited vulnerabilities database this week after CISA told federal agencies on Monday to patch the Log4Shell vulnerability by December 24 as well.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-tells-agencies-to-patch-recent-windows-10-zero-day-abused-by-emotet-botnet