ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Microsoft Patches Three Zero

criticalVulnerability exploited in the wildimportance 60CVE-2023-23376CVE-2023-21823CVE-2023-21715

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-21715
Actively Exploited Security Feature Bypass in Microsoft Office Publisher

Microsoft Office Publisher contains a security feature bypass (CWE-863, incorrect authorization) in which a specially crafted Publisher document can circumvent an Office security mechanism, widely reported as a bypass of the Mark-of-the-Web/Protected View protections applied to files from untrusted sources. The flaw is triggered locally when a user opens the malicious document, consistent with the CVSS vector (local attack, low privileges, user interaction required). Successful bypassing yields high impact on the victim system, with high ratings for confidentiality, integrity, and availability. Anyone running Microsoft 365 Apps or Microsoft Office editions that include Publisher is affected, and no specific affected version numbers are published in this data beyond the requirement to apply the February 2023 fixes. The vulnerability is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-02-14 and was patched as one of three exploited zero-days in Microsoft's February 2023 Patch Tuesday.

Do: Apply Microsoft's February 2023 Patch Tuesday security updates to Microsoft 365 Apps and any Office edition that includes Publisher, per vendor instructions as required by the CISA KEV entry; because affected builds differ by update channel, confirm the installed build after updating rather than relying on the date alone. Until patched, exercise caution with Publisher documents from untrusted sources. No public PoC or workaround is documented, so patching is the primary mitigation.

7.312% KEV
  • Microsoft 365 Apps
  • Microsoft Office (Publisher)
mass≈hundreds of millions of Office/365 installations worldwide
CVE-2023-23376
+1 in the same advisory: …21823
Out-of-Bounds Write Privilege Escalation in Microsoft Windows CLFS Driver

CVE-2023-23376 is a heap-based buffer overflow (out-of-bounds write, CWE-122/CWE-787) in the Windows Common Log File System (CLFS) kernel driver. A local attacker with low privileges can trigger the flaw when the driver mishandles CLFS log-file data, with no user interaction required. Successful exploitation elevates the attacker from a low-privileged user to SYSTEM/kernel-level privileges, which is why ransomware operators chain it with other bugs after gaining an initial foothold. All supported Windows 10 (1507, 1607, 1809, 20H2, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2008, 2012, 2016, and 2019 releases as of February 2023 are affected. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on February 14, 2023 with known ransomware use, Microsoft shipped the fix in the February 2023 Patch Tuesday release, and EPSS estimates roughly an 11% probability of exploitation within the next 30 days (96th percentile).

Do: Apply the Microsoft security updates released on February 14, 2023 (February Patch Tuesday) to every Windows 10, Windows 11, and Windows Server system in the affected version list, prioritizing servers and endpoints exposed to ransomware-prone environments. Verify patch status via update history or vulnerability scanning, since exploitation requires only local low-privileged access and there is no substitution for patching. Given confirmed ransomware chaining, also hunt for signs of post-compromise privilege escalation on hosts that were unpatched before mid-February 2023.

7.811% KEV ransomware
  • Microsoft Windows 10 1507 (all builds prior to the February 2023 security updates)
  • Microsoft Windows 10 1607 (all builds prior to the February 2023 security updates)
  • Microsoft Windows 10 1809 (all builds prior to the February 2023 security updates)
  • +9 more
mass~1 billion+ Windows devices (the CLFS driver ships in every listed Windows 10/11 client and Windows Server 2008-2019 release)
Full article338 words · extracted from infosecurity-magazine.com · click to collapse

Microsoft released patches for over 70 CVEs this month, including three zero-day vulnerabilities currently being exploited in the wild.

The first of these is CVE-2023-23376, an elevation of privilege flaw in the Common Log File System (CLFS) Driver. Tenable senior staff research engineer, Satnam Narang, explained that Redmond patched two similar flaws in the CLFS Driver in April and September 2022.

The second zero-day is CVE-2023-21823, a remote code execution (RCE) bug in the Microsoft Windows Graphics Component that enables attackers to execute commands with system privileges.

“Being able to elevate privileges once on a target system is important for attackers seeking to do more damage,” said Narang.

“These flaws are useful in various contexts, whether an attacker launches an attack exploiting known vulnerabilities or through spear-phishing and malware payloads, which is why we often see elevation of privilege flaws routinely appear in Patch Tuesday releases as being exploited in the wild.”

The final zero-day, CVE-2023-21715, is a security feature bypass in Microsoft Office.

“A local, authenticated attacker could exploit this vulnerability by utilizing social engineering techniques to convince a potential victim to execute a specially crafted file on their system, which would result in the bypass of Microsoft Office security features that would normally block macros from being executed,” said Narang.

In total, the number of CVEs addressed in February’s Patch Tuesday yesterday is less than January’s haul, but the presence of the zero-day bugs will add extra urgency for sysadmins, as will the nine critical RCE flaws listed.

“A more varied selection than last month, February 2023 includes critical RCEs in an SQL Server ODBC driver, the iSCSI Discovery Service, .NET/Visual Studio, three in network authentication framework PEAP, one in Word and two in Visual Studio only,” said Rapid7 lead software engineer, Adam Barnett.

“Microsoft has not observed in-the-wild exploitation for any of these vulnerabilities, nor are any of them marked as publicly disclosed. Microsoft predicts that most of these are less likely to be exploited, with the exception of the PEAP vulnerabilities.”

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/microsoft-patches-three-zeroday/