ZeroHour
Recorded Futurepublished ()ingested Levi Gundert and David Carver

Beyond the Code: Unearthing the Subtle Business Ramifications of Six Months in Vulnerabilities

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-41082
Authenticated RCE in Microsoft Exchange Server (ProxyNotShell)

CVE-2022-41082, dubbed "ProxyNotShell," is an authenticated remote code execution vulnerability in Microsoft Exchange Server; the associated CWE-502 indicates deserialization of untrusted data. It is exploited in a chain with CVE-2022-41040, a server-side request forgery in Exchange that lets an unauthenticated attacker reach the vulnerable endpoint via crafted web requests and trigger the remote code execution. Successful exploitation gives an attacker the ability to run code on the Exchange server, and CISA notes known ransomware use. Any organization running an on-premises Microsoft Exchange Server deployment is potentially affected, with the specific version ranges per Microsoft's advisory. The flaw is actively exploited in the wild: it was added to CISA KEV on 2022-09-30 with ransomware use known, and EPSS assigns a 100% probability of exploitation within 30 days, even though no public proof-of-concept is known.

Do: Apply Microsoft's Exchange security updates immediately per vendor instructions, as required by CISA's KEV listing (added 2022-09-30). If patching is delayed, apply Microsoft's interim mitigations that restrict access to the Autodiscover endpoint used in the CVE-2022-41040 SSRF chain, and review web and PowerShell logs for signs of compromise given the known ransomware use.

8.0100% KEV ransomware PoC
  • Microsoft Exchange Server
massorder of 10^5
CVE-2023-0669
Pre-Authentication Deserialization RCE in Fortra GoAnywhere MFT

Fortra (formerly HelpSystems) GoAnywhere MFT is vulnerable to pre-authentication remote code execution (CWE-502) in the License Response Servlet, which deserializes an attacker-controlled object without validating it. An unauthenticated attacker who can reach the exposed administrative interface can send a crafted serialized object to the servlet and trigger code execution on the server. Successful exploitation gives the attacker the ability to run arbitrary code in the context of the application, which has been leveraged for ransomware operations. All organizations running GoAnywhere MFT with the affected component reachable by untrusted networks are in scope. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-10, ransomware use is confirmed, and EPSS puts the 30-day exploitation probability at 100%.

Do: Apply the vendor's updates for GoAnywhere MFT immediately, per Fortra's instructions, as required by the CISA KEV catalog. Until patched, restrict or block untrusted/internet access to the administrative interface hosting the License Response Servlet, and review logs for signs of exploitation given confirmed in-the-wild and ransomware use.

7.2100% KEV ransomware PoC ×3
  • Fortra GoAnywhere MFT
moderate≈1,000–10,000 internet-exposed GoAnywhere MFT instances (public internet scans of the exposed administrative interface)
CVE-2023-2868
Unauthenticated Command Injection in Barracuda Email Security Gateway Appliances via .tar Files

CVE-2023-2868 is a critical (CVSS 9.8) remote command injection vulnerability in the Barracuda Email Security Gateway (ESG) appliance form factor (models 300, 400, 600, 800 and 900), caused by incomplete input validation of user-supplied .tar archives, specifically the names of the files contained within them. An attacker can deliver a specially crafted .tar file whose internal file names are formatted so that, when the ESG processes the archive, commands are executed through Perl's qx operator. Successful exploitation yields remote command execution with the privileges of the ESG product, and in the observed campaign attackers deployed a backdoor (reported as "SUBMARINE") and persisted on compromised appliances. Only customers running ESG appliances on versions 5.1.3.001 through 9.2.0.006 are affected. Exploitation is confirmed in the wild — CISA added it to the KEV on 2023-05-26, EPSS puts 30-day exploitation probability at 87.7%, and public reporting attributes active exploitation to a Chinese-nexus espionage group (associated in headlines with Salt Typhoon) targeting government, military, and telecom victims; Barracuda's BNSF-36456 patch was applied automatically to customer appliances.

Do: Verify that each ESG appliance received the automatic BNSF-36456 patch (running fixed firmware at or above 9.2.0.006's successor per vendor instructions), and check appliances for indicators of compromise, including unauthorized command activity and the "SUBMARINE" backdoor, using Barracuda's IOC guidance. Because the espionage campaign established persistence, Barracuda urged full replacement rather than patching of compromised appliances; replace any ESG showing signs of compromise and review email logs for malicious .tar attachments. Limit or monitor internet exposure of ESG management interfaces while remediation proceeds.

9.888% KEV
  • Barracuda Networks Email Security Gateway (ESG) 300 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 400 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • Barracuda Networks Email Security Gateway (ESG) 600 firmware (appliance form factor) 5.1.3.001 – 9.2.0.006
  • +2 more
largetens of thousands of deployed ESG appliances (public scans show Barracuda ESGs among commonly internet-exposed email security devices); Barracuda's incident…
Full article767 words · extracted from recordedfuture.com · click to collapse

Editor's note: The following blog post originally appeared on Levi Gundert's Substack page.

Image provided by authors

At Recorded Future, we’re determined to iteratively answer the “So What? Now What?” (SW/NW) questions, which some intelligence professionals colloquially characterize as “actionability.” Insikt Group often engages in a “non-obvious second-order implications” (NOSOI) exercise to derive quality SWNW answers from geopolitical and cyber intelligence for business executives. NOSOI results vary (GPT-4 is good at “second-order” but less adept at “non-obvious”), and of course, “non-obvious” is a subjective label. Still, it’s a reasonable articulation of our goal, and we know it when we see it.

Toward an expanded SWNW for business, David Carver and I recently discussed his team’s excellent 2023 H1 vulnerabilities trends report. We focused explicitly on potential NOSOI. First, a few takeaways from the report for the security practitioners:

Image provided by authors

Regarding this report’s NOSOI, we focused the business risk impact conversation on cost, specifically with one vulnerability example: CVE-2023-2868 zero-day vulnerability in Barracuda Networks’s Email Security Gateway (ESG).

From the report:

CVE-2023-2868, a zero-day vulnerability in Barracuda Networks’s Email Security Gateway (ESG) appliance, very likely qualifies as the most costly vulnerability in terms of cost to product vendors for H1. Researchers assess that the vulnerability was exploited by a China-nexus group known as UNC4841. According to several online resources, Barracuda likely generates between $300 and $500 million in annual revenue. Per a Reddit thread, Barracuda was willing to replace relevant Barracuda hardware above the 300 models of its Email Security Gateway (ESG) at no cost, but clients would need to pay to replace any version below that model… — a fallout that could cost Barracuda up to 50% of the company’s annual revenue.

Replacing hardware as a remediation option is at the far end of the severity spectrum. Barracuda was the unfortunate victim of UNC4841’s efforts in this example, but no vendor is immune to focused and well-resourced efforts to find new vulnerabilities. The broader question for executives is whether this data presents a compelling picture for technology diversification.

Going back 30+ years, at one time, good “Defense in Depth” security meant multiple redundant vendors (e.g., firewalls) to minimize the impact of any one vulnerability. Today, businesses put a premium on a bias for action, and security groups are tasked with riding shotgun (hopefully) as chief digital officers roll out digitalization strategies to improve competitiveness, win market share, and increase profitability. Technological complexity and cyberattack surfaces naturally grow together as data and computing migrate beyond traditional perimeters.

Should security and information technology (IT) more carefully consider redundant vendors balanced against the cost of exploited vulnerabilities? Obviously, “cost” includes multiple resources - money, time, and humans.

We can hear the IT departments howling from here - “These impractical security people! How could we possibly support multiple vendors for a single function?!”. But! This vulnerability report makes a compelling case for considering the merits of a different approach. And by a different approach, we are not arguing for a hard pendulum swing against budget reduction or solution unification. Rather, redundancy and consolidation are two ends of an axis wherein different businesses, with different appetites or exposures to risk, should be thoughtful in pursuing the most appropriate position.

Even the most prominent technology vendors aren’t immune to cyberattacks, which create risk impact ripples across vendor clients and the global economy. Microsoft recently revoked a digital signing key after attackers obtained and used the key to launch broader attacks against third-party targets. Are enterprises reducing operational risk by, in this case, using multiple cloud platforms (Microsoft, Amazon, Oracle, Google, etc.)? What’s the trade-off between security, speed, and cost (a twist on the Iron Triangle)?

It’s a nuanced conversation, and the equities require careful deliberation, but it’s a relevant topic for executives. The time from vulnerability to exploit has never been shorter. Among major software vendors, zero-day vulnerabilities account for over half of newly exploited vulnerabilities for the past several years. Thus, while vendor diversification has long been an accepted cost in business strategy for categories like connectivity, it’s time to widen the aperture.

Image provided by authors

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/beyond-code-unearthing-subtle-business-ramifications-six-months-vulnerabilities