Purple Fox Exploit Kit Adds Two Microsoft Vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-1458 | Win32k Object-Handling Flaw Enables Local Privilege Escalation in Microsoft Windows An elevation of privilege vulnerability exists in the Windows kernel's Win32k component, which fails to properly handle objects in memory (an uninitialized-variable condition). A local attacker who can already execute limited code on a target machine can trigger the flaw to gain kernel-level execution and elevate to SYSTEM privileges, giving full control of the host. Affected platforms are Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 1507 and 1607, and Windows Server 2008, 2012 and 2016. The bug was patched in Microsoft's December 2019 Patch Tuesday after being actively exploited as a zero-day, including in the WizardOpium campaign attributed to a North Korea-linked actor. It is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-10, with known ransomware use) and carries a high EPSS of 74.3%. Do: Apply the December 2019 security updates (or later cumulative updates) from Microsoft per CISA's required action. Because Windows 7/8.1 and Server 2008/2012 are past end of support and Server 2016 support is winding down, prioritize migration to supported Windows versions. Hunt for signs of local privilege escalation and follow-on activity, since this bug was used as a zero-day and appears in ransomware attack chains. | 7.8 | 74% | KEV ransomware PoC ×2 |
| masshundreds of millions of devices (Windows 7 alone held roughly a third of desktop market share at disclosure; millions of Server 2008/2012/2016 hosts remain… | |
| CVE-2020-0674 | Use-After-Free RCE in Microsoft Internet Explorer Scripting Engine CVE-2020-0674 is a use-after-free memory corruption flaw (CWE-416) in the way the Internet Explorer scripting engine handles objects in memory, distinct from a series of sibling scripting-engine RCEs fixed at the same time (CVE-2020-0673, 0710, 0711, 0712, 0713, 0767). Triggering it requires user interaction: an attacker must convince a user to view a specially crafted web page (for example via a phishing link or malicious web content) while it renders in Internet Explorer, and the mishandled memory then allows code execution under the high-complexity, network-reachable conditions reflected in the CVSS vector (AV:N/AC:H/UI:R). Successful exploitation gives the attacker remote code execution with the privileges of the logged-in user, so the practical risk is highest for users browsing with Internet Explorer on Windows, including IE 8 through IE 11 targeted by the public exploits. Exploitation is confirmed in the wild: Microsoft warned of the flaw as an unpatched zero-day being used in targeted attacks before its February 2020 Patch Tuesday fix, public PoC/exploit code is available (including a working exploit for IE 8-11), the Magnitude exploit kit referenced in coverage used it as a delivery vector, and CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 alongside a very high EPSS score (86.9% probability of exploitation in 30 days, 100th percentile). The required remediation is to apply the Microsoft security updates from February 2020 that address this CVE. Do: Apply the Microsoft February 2020 Patch Tuesday security updates that fix CVE-2020-0674 on all Windows endpoints and servers, prioritizing per the CISA KEV required action. Until patched, limit Internet Explorer use to trusted sites and consider Microsoft's suggested mitigations (such as restricting active scripting); note that third-party micropatches existed that emulated the vendor workaround without its usability side effects. After patching, verify IE11 remediation status across the estate and, where feasible, retire Internet Explorer usage entirely to reduce exposure to this recurring scripting-engine bug class. | 7.5 | 87% | KEV PoC ×4 |
| masshundreds of millions of Windows endpoints (IE 11 was bundled with every supported Windows release at disclosure) |
Full article406 words · extracted from infosecurity-magazine.com · click to collapse
Security company Proofpoint has identified two new exploits coded into Purple Fox, an exploit kit that has evolved dramatically in the last year. The updates show that cyber-criminals are continuing to invest in infection tools to help get their malware onto victims’ systems even though exploit kits are declining as an attack technique, the company said.
An exploit kit is a tool used to deliver malware onto a victim’s device automatically via a website. It is an automated threat that uses compromised websites to drive up web traffic and scan for vulnerable browsers so that it can deliver its malware-based payload.
Exploit kits are the basis for drive-by downloads that infect a victim as soon as they visit a malicious site. They have often been sold as services to distribute malware, providing cyber-criminals with a conduit to infect victims’ machines, but according to Proofpoint their popularity has declined of late.
“Exploit Kits are not as prevalent as they were a few years ago. However, they are still part of the threat landscape,” explained the company. “One thing that hasn’t changed regarding exploit kits is the way in which exploit kit authors regularly update to include new attacks against newly discovered vulnerabilities.”
Purple Fox started out as a fileless downloader Trojan malware delivered by an exploit kit called Rig. According to a 2018 write-up by Qihoo 360 Technology, it had infected at least 30,000 users at the time. Trend Micro had spotted it downloading and executing cryptomining malware onto victims’ devices. Last year, it switched from the Nullsoft Scriptable Install System to Windows PowerShell as a means of retrieving and delivering various kinds of malware.
Now, according to Proofpoint, it has become an exploit kit in its own right, built to replace Rig. It has added two new exploits, both patched by Microsoft in the last few months.
The first, CVE-2019-1458, is a local privilege elevation mobility that Microsoft fixed in December last year. The second, CVE-2020-0674, is a bug in Internet Explorer that Microsoft fixed in its February 2020 patch Tuesday update.
“The fact that the authors of the Purple Fox malware have stopped using the RIG EK [exploit kit] and moved to build their own EK to distribute their malware reminds us that malware is a business,” Proofpoint said in its analysis. “In essence, the authors behind the Purple Fox malware decided to bring development ‘in-house’ to reduce costs, just like many legitimate businesses do.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/purple-fox-exploit-kit-microsoft/