ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Government Spooks Urge Firms to Patch SharePoint Bug

criticalVulnerability exploited in the wildimportance 60CVE-2020-16952CVE-2019-0604

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0604
RCE in Microsoft SharePoint via Application Package Markup Validation Flaw

Microsoft SharePoint fails to check the source markup of an application package, an improper input validation flaw (CWE-20) that allows maliciously crafted markup to be processed by the server. An attacker triggers the flaw by getting an affected SharePoint server to handle a crafted application package, without any special privileges described in the disclosure. Successful exploitation lets the attacker run remote code in the context of the SharePoint application pool and the SharePoint server farm account, providing control of the web server and access to a highly privileged farm-level identity. Any organization running an affected on-premises Microsoft SharePoint deployment is exposed, with internet-facing SharePoint servers at greatest risk. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use and EPSS puts the probability of exploitation at 99.9%, although no public proof-of-concept is catalogued.

Do: Apply Microsoft's SharePoint security updates per vendor instructions immediately, prioritizing internet-exposed SharePoint servers as CISA's required action directs. Given known in-the-wild and ransomware use, hunt for signs of compromise such as unexpected .aspx or webshell files in SharePoint directories and anomalous use of the SharePoint farm account. Restrict or firewall internet exposure of SharePoint servers until patches are confirmed applied.

9.8100% KEV ransomware
  • Microsoft SharePoint
mass≈ hundreds of thousands of on-prem SharePoint server deployments worldwide, of which tens of thousands are directly internet-facing (estimate)
CVE-2020-16952
A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package.

A remote code execution vulnerability exists in Microsoft SharePoint when the software fails to check the source markup of an application package. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the SharePoint application pool and the SharePoint server farm account. Exploitation of this vulnerability requires that a user uploads a specially crafted SharePoint application package to an affected version of SharePoint. The security update addresses the vulnerability by correcting how SharePoint checks the source markup of application packages.

NVD description · AI analysis pending
8.671% PoC
  • microsoft sharepoint enterprise server
  • microsoft sharepoint foundation
  • microsoft sharepoint server
Full article301 words · extracted from infosecurity-magazine.com · click to collapse

Government experts are warning SharePoint customers to urgently patch a remote code execution (RCE) vulnerability fixed by Microsoft last week.

A National Cyber Security Centre (NCSC) alert on Friday claimed successful exploitation of CVE-2020-16952 could enable attackers to run arbitrary code and carry out security actions in the context of a local administrator, on affected installations.

“The NCSC always recommends applying security updates promptly to mitigate the exploitation of all vulnerabilities but in this case the NCSC has previously seen a large number of exploitations of SharePoint vulnerabilities, such as CVE-2019-0604, against UK organizations,” it continued.

“Two SharePoint CVEs also appear in the CISA Top 10 Routinely Exploited Vulnerabilities.”

The vulnerability itself affects Microsoft SharePoint Foundation 2013 Service Pack 1, SharePoint Enterprise Server 2016 and SharePoint Server 2019, but not SharePoint Online as part of Office 365.

It occurs because the software fails to check the source markup of an application package, according to Microsoft. Exploitation therefore requires a user to upload a specially crafted SharePoint application package to an affected version.

The NCSC’s warning comes despite Microsoft rating exploitation as “less likely.” The bug has a CVSS score of 8.6 on all affected versions for SharePoint.

However, although there are no reports of attackers leveraging this vulnerability at the moment, proof-of-concept code is already available.

Experts at Rapid7 also urged SharePoint administrators to prioritize patching.

“SharePoint is a high-value attack target and has seen a number of high-severity vulnerabilities patched in recent months,” the security vendor said. “It is likely that active exploitation will occur within a relatively short time frame; it was trivial for Rapid7 researchers to validate the vulnerability’s exploitability and weaponize [the] PoC.”

As well as this vulnerability, SharePoint accounted for just under a third of the 23 critical flaws patched by Microsoft in September.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/government-spooks-urge-firms-patch/