Sophisticated hacking campaign uses Windows and Android zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-1020 | Out-of-Bounds Write RCE in Microsoft Windows Adobe Font Manager Library CVE-2020-1020 is a remote code execution vulnerability (out-of-bounds write, CWE-787) in the Adobe Font Manager Library shipped with Microsoft Windows, caused by improper handling of a specially crafted multi-master font in Adobe Type 1 PostScript format. Triggering it requires user interaction: an attacker delivers a malicious document or font, and the vulnerable code runs when the content is previewed or opened (no authentication is needed on the network path, but the user must interact). On all systems except Windows 10, successful exploitation allows the attacker to execute arbitrary code remotely in the context of the current user; on Windows 10 the flaw is present as well, with the full remote-code-execution impact described for non-Windows-10 systems. Affected software spans Windows 10 versions 1507 through 1909, Windows 7, Windows 8.1, Windows RT 8.1, and Windows Server 1903/1909. The bug was exploited in the wild as a zero-day by a sophisticated threat actor prior to patching (CISA KEV, added 2021-11-03), and EPSS assigns a 65% probability of exploitation within 30 days (99th percentile). Do: Apply Microsoft's security update for CVE-2020-1020 via Windows Update (April 2020 Patch Tuesday cycle) on all Windows 7, 8.1, RT 8.1, Windows 10 1507-1909, and Windows Server 1903/1909 hosts, per CISA's required action. As interim mitigation, disable the Explorer preview and details panes and avoid opening or previewing untrusted documents and fonts. Verify the fix is deployed, prioritizing non-Windows-10 systems where successful exploitation yields full remote code execution. | 8.8 group max | 65% | KEV |
| masshundreds of millions of Windows client/server devices (OS component shipped in all listed Windows releases) | |
| CVE-2020-6418 | Type Confusion in Google Chrome's V8 Engine Enables Heap Corruption CVE-2020-6418 is a type confusion vulnerability (CWE-843) in V8, the JavaScript engine used in Google Chrome and Chromium, affecting versions prior to 80.0.3987.122. A remote attacker triggers it by persuading a user to open a crafted HTML page whose JavaScript causes V8 to mishandle object types (public PoCs reference a JSCreate side-effect issue), potentially leading to heap corruption. Successful exploitation can yield arbitrary code execution in the browser, a common stepping stone for further compromise on the victim's system. Any Chrome/Chromium deployment with the vulnerable V8 was affected, including Chromium packages shipped by Fedora, Red Hat Enterprise Linux, and Debian. The flaw was a zero-day exploited in the wild when patched in February 2020; it is listed in CISA KEV (added 2021-11-03) and carries a very high EPSS of 78.8%, making it a priority patch. Do: Update Google Chrome to 80.0.3987.122 or later and confirm the running version via chrome://settings/help or chrome://version. Apply the updated Chromium packages from Fedora, Red Hat, and Debian on managed Linux endpoints and check whether any hosts still run pre-fix Chromium. Given the KEV listing and 78.8% EPSS, treat patching as urgent; as an interim mitigation on unpatched systems, limit untrusted web browsing or restrict JavaScript from untrusted sites. | 8.8 | 79% | KEV PoC ×2 |
| massbillions of users/installations (Chrome's global install base runs to billions, and at disclosure in February 2020 every Chrome user on a pre-80.0.3987.122… |
Full article533 words · extracted from securityaffairs.com · click to collapse

Google Project Zero researchers uncovered a sophisticated hacking campaign that targeted Windows and Android users.
The Google Project Zero team has recently launched an initiative aimed at devising new techniques to detect 0-day exploits employed in attacks in the wild. While partnering with the Google Threat Analysis Group (TAG), the experts discovered a watering hole attack in Q1 2020 that was carried out by a highly sophisticated actor.
Wew. Google P0 found some (very) high-end actor's Chrome exploitation servers. Those previously described 0days are cool and all, but that complex target assessment functionality is 🔥. And who puts "informational" event logging in their Android downloader malware? https://t.co/x5sXVeAAr0 pic.twitter.com/EDf4hqz4Ob
— Brian in Pittsburgh (@arekfurt) January 12, 2021
The campaign spotted by Project Zero experts targeted Windows and Android systems. Threat actors behind the attacks exploited multiple vulnerabilities in Android, Windows, and chained them with Chrome flaws. The attackers exploited both zero-days and n-days exploits.
“We discovered two exploit servers delivering different exploit chains via watering hole attacks. One server targeted Windows users, the other targeted Android. Both the Windows and the Android servers used Chrome exploits for the initial remote code execution.” reads the analysis published by Project Zero. “The exploits for Chrome and Windows included 0-days. For Android, the exploit chains used publicly known n-day exploits. Based on the actor’s sophistication, we think it’s likely that they had access to Android 0-days, but we didn’t discover any in our analysis.”

The attacks employed two exploit servers that were triggering multiple vulnerabilities through different exploit chains in watering hole attacks,
The two servers were hosting exploits to trigger Google Chrome vulnerabilities to gain an initial foothold on the visitors’ devices. The attackers exploited Windows and Android exploit to take over the victim’s devices.
The experts were able to extract the following code from the exploit servers:
- Renderer exploits for four bugs in Chrome, one of which was still a 0-day at the time of the discovery.
- Two sandbox escape exploits abusing three 0-day vulnerabilities in Windows.
- A “privilege escalation kit” composed of publicly known n-day exploits for older versions of Android.
The chains used by the attackers included the following 0-days flaws:
- CVE-2020-6418 – Chrome Vulnerability in TurboFan (fixed February 2020)
- CVE-2020-0938 – Font Vulnerability on Windows (fixed April 2020)
- CVE-2020-1020 – Font Vulnerability on Windows (fixed April 2020)
- CVE-2020-1027 – Windows CSRSS Vulnerability (fixed April 2020)
The Project Zero team spent many months analyzing in detail each part of the attack chain employed in this campaign, they detailed their findings in 6 separate reports:
- Introduction (this post)
- Chrome: Infinity Bug
- Chrome Exploits
- Android Exploits
- Android Post-Exploitation
- Windows Exploits
Google highlighted the level of sophistication of this campaign, the threat actors appears to be well resourced and the overall operations well-engineered.
“They are well-engineered, complex code with a variety of novel exploitation methods, mature logging, sophisticated and calculated post-exploitation techniques, and high volumes of anti-analysis and targeting checks,” Google concludes.
“We believe that teams of experts have designed and developed these exploit chains,”
If you want to receive the weekly Security Affairs Newsletter for free subscribe here.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Project Zero)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/113342/hacking/project-zero-watering-hole-attack.html