ZeroHour
The Recordpublished ()ingested

CISA adds dozens of vulnerabilities to catalog of exploited bugs

highVulnerability exploited in the wildimportance 60CVE-2020-0638CVE-2017-18362

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-18362
Unauthenticated SQL Injection in Kaseya VSA ConnectWise ManagedITSync Integration

An unauthenticated SQL injection (CWE-89) exists in the ConnectWise ManagedITSync integration (through 2017) for Kaseya Virtual System Administrator (VSA), triggered through the ManagedIT.asmx page of the VSA web interface. Any unauthenticated attacker who can reach that page over the network can submit arbitrary SQL queries, both read and write, gaining full direct access to the VSA database and effectively running remote commands on the server. Because VSA servers centrally manage endpoints for managed service providers, compromise can cascade downstream: in February 2019 attackers actively exploited this flaw to download and execute ransomware payloads on all endpoints managed by affected VSA servers. Organizations are affected if they run Kaseya VSA with the ManagedITSync integration enabled and the ManagedIT.asmx page reachable by untrusted users. Exploitation is confirmed in the wild (CISA KEV, added 2022-05-24; known ransomware use), EPSS estimates an 86.8% probability of exploitation within 30 days, and CISA notes the impacted product is end-of-life.

Do: Because CISA notes the impacted product is end-of-life, disconnect or decommission any Kaseya VSA still running the ConnectWise ManagedITSync integration; otherwise update the integration beyond the 2017 version or disable it and remove public network access to the ManagedIT.asmx page of the VSA web interface. Restrict the VSA web interface to trusted networks and check managed endpoints for signs of the February 2019 ransomware exploitation.

9.887% KEV ransomware PoC
  • ConnectWise ManagedITSync integration for Kaseya VSA through 2017
  • Kaseya Virtual System Administrator (VSA) installations running the ConnectWise ManagedITSync integration (through 2017) with the ManagedIT.asmx page exposed via the VSA web interface
largeroughly 10,000-100,000 exposed Kaseya VSA server installations with the integration enabled (MSP deployments), each managing hundreds to thousands of…
CVE-2020-0638
Local Privilege Escalation in Microsoft Update Notification Manager (Windows 10/Server)

CVE-2020-0638 is a local elevation of privilege flaw in the way Microsoft's Update Notification Manager handles files (CWE-59, a link-following/race-condition class of bug), affecting Windows 10 versions 1709, 1803, 1809, 1903 and 1909, plus Windows Server 1803, 1903, 1909 and 2019. To trigger it, an attacker must first gain code execution on the victim system with limited privileges; no user interaction is required after that initial foothold. Successful exploitation allows the attacker to elevate privileges with high impact on confidentiality, integrity and availability, making it a useful step in ransomware and other intrusion chains to take full control of a host. Microsoft fixed the issue in its January 2020 Patch Tuesday security updates. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-05-23 with known ransomware use, confirming exploitation in the wild; no public proof-of-concept is known.

Do: Apply Microsoft's January 2020 security updates (or any later cumulative update) to all affected Windows 10 and Windows Server systems, prioritizing user workstations and servers where an attacker with an existing foothold would matter; federal agencies must patch per CISA KEV/BOD 22-01 timelines. Inventory endpoints still running Windows 10 builds 1709–1909 and Windows Server 1803/1903/1909/2019 and verify the installed cumulative update level. Because exploitation requires prior code execution, pair patching with EDR and least-privilege controls to disrupt ransomware chains.

7.83% KEV ransomware
  • Microsoft Windows 10 1709, 1803, 1809, 1903, 1909
  • Microsoft Windows Server (Semi-Annual Channel) 1803, 1903, 1909
  • Microsoft Windows Server 2019 2019
mass≈100M+ Windows endpoints and servers (Windows 10 install base; affected builds were mainstream versions at disclosure)
Full article438 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) added 41 vulnerabilities to its catalog of known exploited bugs this week, one of the largest batches of additions to the list since CISA began compiling it in November.

Dozens of the vulnerabilities are years old and federal civilian agencies have been given until June 13 and 14 to apply the patches or disconnect the ones that are end-of-life. 

The list includes bugs in products from Microsoft, Apple, Adobe, Whatsapp, Mozilla, Google, Cisco, Kaseya, Artifex and QNAP. 

CISA puts the list together based on evidence of active exploitation, noting that the vulnerabilities listed are “a frequent attack vector for malicious cyber actors and pose significant risk to the federal enterprise.” Andrew Hay, COO at cybersecurity firm LARES Consulting, said CISA likely received intelligence, or perhaps monitored actual activity, which indicates that the vulnerabilities added need to be patched immediately.

Kevin Breen, director of Cyber Threat Research at Immersive Labs, told The Record that it was not surprising CISA added so many relatively old vulnerabilities — some of the vulnerabilities added this week date as far back as 2016.  Breen said that attackers are well versed at finding vulnerabilities, old and new, to exploit in their campaigns.

“The Windows elevation of privileges vulnerability CVE-2020-0638 was disclosed in 2020 but was still being harnessed by the prolific ransomware gang Conti for their attacks on corporate networks this year,” Breen noted. 

The Kaseya bug – CVE-2017-18362 – was used by hackers to deploy the GandCrab ransomware on companies' customer workstations in 2019. At least one company was successfully attacked at the time using the bug.

— Catalin Cimpanu (@campuscodi) February 14, 2019

While the list includes vulnerabilities from 2016, it also includes more recent ones, namely the Cisco IOS XR bug that was patched last week and two Android vulnerabilities that were discovered in November. 

Other experts, like Viakoo CEO Bud Broomhead, noted that the addition of older vulnerabilities was even more evidence that patching among federal agency offices was severely lacking. 

The nature of the vulnerabilities listed – privilege escalation, remote code injection, memory corruption – suggests that the goal of the threat actors is to use these vulnerabilities to first breach an organization, then use that access to move laterally to more sensitive internal systems, Broomhead explained. 

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-dozens-of-vulnerabilities-to-catalog-of-exploited-bugs