ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Google warns of actively exploited Windows zero-day

criticalExploit / PoC exploited in the wildimportance 60CVE-2016-7255CVE-2016-7855

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-7255
Win32k Local Privilege Escalation in Windows Vista Through Windows 10 and Server 2016

CVE-2016-7255 is an elevation-of-privilege flaw in the Windows kernel-mode drivers (win32k), affecting Windows Vista SP2 through Windows 10 1607 and the corresponding Windows Server releases. A local attacker who can run a crafted application can leverage the bug — public exploits target the win32k NtSetWindowLongPtr code path — to execute code with elevated kernel privileges. Successful exploitation yields SYSTEM-level privileges, typically used to escape a restricted context or to chain with a separate code-execution bug for full system compromise, including ransomware deployment. Anyone running the affected Windows versions is exposed; the flaw was a zero-day actively exploited at the time of its November 2016 disclosure, with reporting tying use to the Sofacy/'Pawn Storm' APT and Google warning of active exploitation. It was added to CISA KEV on 2021-11-03 with known ransomware use, and EPSS currently puts the 30-day exploitation probability at 81%, so defenders should treat it as actively targeted.

Do: Apply Microsoft's security update for CVE-2016-7255 (issued in the November 2016 Patch Tuesday cycle, bulletin MS16-135); on Windows 10 1507/1511/1607 this arrives via the corresponding monthly cumulative update. Prioritize patching internet-reachable servers and any system where unprivileged users can run code, since the flaw is used in the wild for post-exploitation privilege escalation (including ransomware chains per CISA KEV). After patching, hunt for suspicious local-to-SYSTEM activity around the disclosure window on legacy Windows Vista/2008/7/2012 estate that may still be running unpatched builds.

7.881% KEV ransomware PoC ×5
  • microsoft Windows Vista SP2
  • microsoft Windows Server 2008 SP2 and R2 SP1
  • microsoft Windows 7 SP1
  • +5 more
masshundreds of millions of Windows PCs and servers (the listed versions dominated the global installed base at disclosure)
CVE-2016-7855
Use-After-Free RCE in Adobe Flash Player (Windows, macOS, Linux)

Adobe Flash Player for Windows, macOS/OS X, and Linux contains a use-after-free memory flaw (CWE-416) in which memory that has been freed is referenced again, corrupting memory when the player processes attacker-controlled Flash content remotely, typically via a malicious SWF delivered through a browser or another host application. A successful attack allows arbitrary code execution with the privileges of the user running Flash, commonly leading to full workstation compromise in browsing contexts. Anyone still running an affected Adobe Flash Player build is exposed, although the product has been end-of-life since early 2021 and CISA explicitly advises disconnecting or removing it rather than continuing to patch. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added March 3, 2022), confirming known in-the-wild exploitation, and EPSS assigns a 25.2% probability of exploitation within 30 days (98th percentile); no public proof-of-concept is known and ransomware use is unknown.

Do: Because Flash Player is end-of-life and no longer receives security updates, follow CISA's required action: uninstall or disable Flash everywhere it remains, including browser plugins, standalone installs, and legacy applications that invoke it. If removal must be delayed, ensure the latest patched release from Adobe's security advisories is in place and block or sandbox untrusted Flash content. On systems where Flash is still active, hunt for indicators of compromise given the KEV listing and high EPSS score.

8.825% KEV
  • Adobe Flash Player
mass≈1 billion+ installs historically (Flash was near-ubiquitous; residual post-EOL installs unknown)
Full article253 words · extracted from helpnetsecurity.com · click to collapse

Google has disclosed to the public the existence of a Windows zero-day vulnerability (CVE-2016-7255) that is being actively exploited in the wild.

actively exploited Windows zero-day

According to Neel Mehta and Billy Leonard, of the Google Threat Analysis Group, it’s a local privilege escalation in the Windows kernel that can be used as a security sandbox escape, and can be triggered “via the win32k.sys system call NtSetWindowLongPtr() for the index GWLP_ID on a window handle with GWL_STYLE set to WS_CHILD.”

The existence of this vulnerability and another zero-day affecting Flash Player (CVE-2016-7855) has been shared with Microsoft and Adobe on October 21st. But while Adobe has already pushed out an update with the patch, Microsoft has not been so quick.

“Adobe is aware of a report that an exploit for CVE-2016-7855 exists in the wild, and is being used in limited, targeted attacks against users running Windows versions 7, 8.1 and 10,” Adobe said in the security bulletin accompanying the release.

Google has made public the flaw before Microsoft has had the chance to fix it because it is a critical vulnerability that could lead to system compromise, and it is being actively exploited.

They have advised users to update Flash and implement the Microsoft patch as soon as it is made available.

In the meantime, Windows 10 users can use Google Chrome to protect themselves against possible attacks leveraging the flaw.

“Chrome’s sandbox blocks win32k.sys system calls using the Win32k lockdown mitigation on Windows 10, which prevents exploitation of this sandbox escape vulnerability,” they explained.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2016/11/01/google-warns-actively-exploited-windows-zero-day/