ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Issues Warning on Active Exploitation of UnRAR Software for Linux Systems

criticalRansomware exploited in the wildimportance 60CVE-2022-30333CVE-2022-34713

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-30333
Directory Traversal in RARLAB UnRAR (Linux/UNIX) Enables Arbitrary File Writes

RARLAB's UnRAR command-line decompression tool on Linux and UNIX, in versions before 6.12, contains a directory traversal flaw (CWE-22, with symlink-based path confusion per CWE-59) that lets a crafted RAR archive write files to arbitrary filesystem locations during an extract/unpack operation. It is triggered whenever an application passes an attacker-supplied archive to unrar, most prominently Zimbra Collaboration Suite, which unpacked RAR attachments from incoming email, enabling pre-authentication attacks against webmail tracked separately as CVE-2022-41352. By planting files at chosen paths — for example writing an SSH key to ~/.ssh/authorized_keys or dropping a web shell under a web root — an attacker can escalate an arbitrary file write into code execution on the server, requiring no privileges or user interaction per the CVSS vector. Only the Linux/UNIX UnRAR utility is affected; WinRAR and RAR for Android are not. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2022-08-09 with known ransomware use, public PoCs exist, and EPSS estimates a ~99% probability of exploitation within 30 days.

Do: Upgrade UnRAR to 6.12 or later on all Linux and UNIX systems and apply Debian's patched unrar package; Zimbra administrators should apply Zimbra's released security patches, which ship the fixed UnRAR. As an interim mitigation, restrict or monitor services that automatically extract RAR archives from untrusted sources, and hunt for indicators such as unexpected ~/.ssh/authorized_keys entries, planted symlinks, or web shells under web roots. Because the flaw is on CISA's KEV list with known ransomware use, treat patching as time-critical.

7.599% KEV ransomware PoC ×2
  • RARLAB UnRAR all versions before 6.12 on Linux and UNIX (fixed in 6.12)
  • Debian Linux (unrar package) Debian builds shipping UnRAR prior to 6.12
largetens of thousands of internet-exposed servers (dominated by Zimbra mail servers that auto-extract RAR attachments), with the total UnRAR installed base on…
CVE-2022-34713
Remote Code Execution in Microsoft Windows Support Diagnostic Tool (MSDT) (DogWalk)

CVE-2022-34713, commonly referred to as 'DogWalk,' is a remote code execution vulnerability in the Microsoft Windows Support Diagnostic Tool (MSDT), patched in Microsoft's August 2022 Patch Tuesday release. The flaw requires user interaction: a user who engages with attacker-supplied content that invokes MSDT can allow the attacker's file operations to run in the context of the logged-on user, yielding high-impact code execution (confidentiality, integrity, and availability all rated high in the CVSS vector). Affected products span essentially the entire supported Windows installed base at the time: Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H2), Windows 11 21H2, and Windows Server 2008 and 2012. The vulnerability was confirmed by Microsoft as an actively exploited zero-day in August 2022 and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-08-09, with a required action to apply vendor updates. EPSS assigns it a 67.8% probability of exploitation within 30 days (99th percentile), consistent with in-the-wild use.

Do: Apply the August 2022 (or later) Windows security updates on all affected Windows 7, 8.1, RT 8.1, 10 (1507–21H2), 11 21H2, Server 2008, and Server 2012 systems per vendor instructions, prioritizing user-facing workstations where exploitation depends on user interaction. Given the KEV listing, federal and high-value environments should verify patch status immediately and hunt for suspicious MSDT/diagnostic-tool invocations. No public PoC is known, but treat any unpatched system as exposed given confirmed in-the-wild exploitation.

7.868% KEV
  • microsoft Windows 10 1507, 1607, 1809, 20H2, 21H1, 21H2
  • microsoft Windows 11 21H2
  • microsoft Windows 7 all supported editions as listed (no SP range specified in source data)
  • +4 more
masshundreds of millions of devices
Full article430 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananAug 10, 2022

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a recently disclosed security flaw in the UnRAR utility to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

Tracked as CVE-2022-30333 (CVSS score: 7.5), the issue concerns a path traversal vulnerability in the Unix versions of UnRAR that can be triggered upon extracting a maliciously crafted RAR archive.

This means that an adversary could exploit the flaw to drop arbitrary files on a target system that has the utility installed simply by decompressing the file. The vulnerability was revealed by SonarSource researcher Simon Scannell in late June.

"RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation," the agency said in an advisory.

Although the flaw affects any Linux application that uses UnRAR to extract an archive file, a successful exploitation of the flaw can have a significant impact against Zimbra, granting an attacker complete access to the email server.

In a follow-up analysis published last month, Rapid7 said a vulnerable Zimbra host can be exploited by an adversary by sending an email containing a rogue RAR file and without requiring any user interaction, since the service automatically extracts archives attached to incoming emails to inspect them for spam and malware.

The security hole was patched by WinRAR developer Rarlab on May 6. Zimbra addressed the issue on June 14 in 9.0.0 patch 25 and 8.5.15 patch 32 by replacing UnRAR with 7z.

Not much is known about the nature of the attacks, but the disclosure is evidence of a growing trend wherein threat actors are quick to scan for vulnerable systems after flaws are publicly disclosed and take the opportunity to launch malware and ransomware campaigns.

On top of that, CISA has also added CVE-2022-34713 to the catalog after Microsoft, as part of its Patch Tuesday updates on August 9, revealed that it has seen indications that the vulnerability has been exploited in the wild.

Said to be a variant of the vulnerability publicly known as DogWalk, the shortcoming in the Microsoft Windows Support Diagnostic Tool (MSDT) component could be leveraged by a rogue actor to execute arbitrary code on susceptible systems by tricking a victim into opening a decoy file.

Federal agencies in the U.S. are mandated to apply the updates for both flaws by August 30 to reduce their exposure to cyberattacks.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/08/cisa-issues-warning-on-active.html