ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Hackers Actively Exploiting Cisco AnyConnect and GIGABYTE Drivers Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-19323
+3 in the same advisory: …19321 …19320 …19322
Privilege Escalation in GIGABYTE GDrv Driver (APP Center, AORUS, OC GURU II, XTREME)

The GDrv low-level kernel driver bundled with GIGABYTE's APP Center (1.05.21 and earlier), AORUS GRAPHICS ENGINE (before 1.57), XTREME GAMING ENGINE (before 1.26), and OC GURU II (2.08) exposes functionality that allows reading and writing Machine Specific Registers (MSRs) without sufficient access control. An attacker who reaches this exposed driver functionality can send crafted requests to write arbitrary MSRs, gaining kernel (ring-0) privileges and thereby escalating from limited access to full control of the host. The flaw is rated critical (CVSS 9.8) with no privileges or user interaction required per the published vector. It affects Windows systems where the GIGABYTE utility software that installs the GDrv driver is present, typically enthusiast overclocking and monitoring tools bundled with GIGABYTE motherboards and graphics cards. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, and recent reporting indicates active exploitation alongside other driver vulnerabilities.

Do: Apply vendor updates per CISA guidance: APP Center later than 1.05.21, AORUS GRAPHICS ENGINE 1.57 or later, XTREME GAMING ENGINE 1.26 or later, and OC GURU II later than 2.08, which ship a corrected GDrv driver. Audit Windows endpoints for the GDrv (gdrv.sys) low-level driver and uninstall unused GIGABYTE utility software to close the exposed interface. Because CISA lists this with known ransomware use, prioritize remediation on workstations and user endpoints rather than assuming only servers are affected.

9.8
group max
8% KEV ransomware PoC ×2
  • GIGABYTE APP Center 1.05.21 and earlier
  • GIGABYTE AORUS GRAPHICS ENGINE before 1.57
  • GIGABYTE XTREME GAMING ENGINE before 1.26
  • +1 more
mass~millions of Windows systems (GIGABYTE utility bundles install the vulnerable GDrv driver)
CVE-2020-3153
DLL Search Path Hijacking LPE in Cisco AnyConnect Secure Mobility Client for Windows

CVE-2020-3153 is an uncontrolled search path vulnerability (CWE-427) in the Windows client of Cisco AnyConnect Secure Mobility Client, which mishandles directory paths when running with elevated privileges. An attacker or malware that already has valid credentials and local access on a Windows endpoint can copy malicious files, such as DLLs, into locations loaded by the elevated AnyConnect process. Successful exploitation yields system-level (SYSTEM) privilege execution on the endpoint via DLL preloading or DLL hijacking, making it an effective local privilege escalation step in broader intrusion chains. Any organization running the AnyConnect VPN client on Windows endpoints is potentially affected. The flaw was added to CISA KEV on 2022-10-24 with known ransomware use, and its EPSS of 28.3% (98th percentile) indicates an elevated probability of near-term exploitation, though no public PoC is known.

Do: Apply the fixed AnyConnect release per Cisco's instructions, as required by CISA's KEV listing, prioritizing Windows endpoints where the client is installed. Inventory your estate for AnyConnect installations and verify client builds are current. Given the known ransomware use, hunt for signs of local DLL planting in writable directories and review privilege-escalation activity on Windows hosts.

6.528% KEV ransomware PoC ×4
  • Cisco AnyConnect Secure Mobility Client for Windows
massmillions of enterprise Windows endpoints (AnyConnect is among the most widely deployed corporate VPN clients)
CVE-2020-3433
DLL Hijacking LPE in Cisco AnyConnect Secure Mobility Client for Windows

Cisco AnyConnect Secure Mobility Client for Windows contains a DLL hijacking flaw (CWE-427) in its interprocess communication (IPC) channel, caused by insufficient validation of resources loaded at run time. An attacker who already has valid credentials on the Windows machine can send a crafted IPC message to the AnyConnect process and coerce it into loading a malicious DLL. Successful exploitation allows arbitrary code execution with SYSTEM privileges, turning a low-privileged local foothold into full administrative control of the endpoint. Any organization running AnyConnect on Windows endpoints is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, a public proof-of-concept is available, and news reports confirm active exploitation alongside another AnyConnect Windows flaw.

Do: Upgrade Cisco AnyConnect for Windows to a fixed release per Cisco's security advisory, as required by the CISA KEV required action (apply updates per vendor instructions). Since exploitation requires valid local credentials, limit local logon privileges on endpoints and prioritize patching given known ransomware use. Inventory Windows endpoints for AnyConnect installs and monitor for suspicious DLL loads in the AnyConnect process path.

7.810% KEV ransomware PoC
  • Cisco AnyConnect Secure Mobility Client for Windows
masstens of millions of Windows endpoints running AnyConnect (dominant enterprise VPN client installed base; no precise public count in this data)
Full article302 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 26, 2022

Cisco has warned of active exploitation attempts targeting a pair of two-year-old security flaws in the Cisco AnyConnect Secure Mobility Client for Windows.

Tracked as CVE-2020-3153 (CVSS score: 6.5) and CVE-2020-3433 (CVSS score: 7.8), the vulnerabilities could enable local authenticated attackers to perform DLL hijacking and copy arbitrary files to system directories with elevated privileges.

While CVE-2020-3153 was addressed by Cisco in February 2020, a fix for CVE-2020-3433 was shipped in August 2020.

"In October 2022, the Cisco Product Security Incident Response Team became aware of additional attempted exploitation of this vulnerability in the wild," the networking equipment maker said in an updated advisory.

"Cisco continues to strongly recommend that customers upgrade to a fixed software release to remediate this vulnerability."

The alert comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) moved to add the two flaws to its Known Exploited Vulnerabilities (KEV) catalog, alongside four bugs in GIGABYTE drivers, citing evidence of active abuse in the wild.

The vulnerabilities -- assigned the identifiers CVE-2018-19320, CVE-2018-19321, CVE-2018-19322, and CVE-2018-19323, and patched in May 2020 -- could permit an attacker to escalate privileges and run malicious code to take complete control of an affected system.

The development also follows a comprehensive report released by Singapore-based Group-IB last week detailing the tactics adopted by a Russian-speaking ransomware group dubbed OldGremlin in its attacks aimed at entities operating in the country.

Chief among its methods for gaining initial access is the exploitation of the above-stated Cisco AnyConnect flaws, with the GIGABYTE driver weaknesses employed to disarm security software, the latter of which has also been put to use by the BlackByte ransomware group.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/10/hackers-actively-exploiting-cisco.html