ZeroHour
Security Affairspublished ()ingested @securityaffairs1

CISA adds Microsoft COM for Windows bug to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2018-0824

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-0824
Deserialization of Untrusted Data RCE in Microsoft COM for Windows

CVE-2018-0824 is a deserialization of untrusted data flaw (CWE-502) in Microsoft COM for Windows: the COM subsystem fails to properly handle serialized objects, allowing a remote attacker to achieve remote code execution (CVSS 3.1: 8.8, network vector). It is triggered when the affected Windows system deserializes attacker-controlled serialized data; the CVSS vector indicates user interaction is required in typical attack scenarios. Successful exploitation yields code execution with the privileges of the user or service that handles the serialized object, compromising confidentiality, integrity, and availability on the host. The affected footprint is extremely broad, spanning Windows 7, 8.1 and RT 8.1, Windows 10 (versions 1507 through 1803), and Windows Server 2008 through 2016, including Server versions 1709 and 1803. The flaw is confirmed exploited in the wild — CISA added it to the Known Exploited Vulnerabilities catalog on 2024-08-05 — and a public PoC exists (Exploit-DB 44906), with EPSS estimating a ~73.2% probability of exploitation within 30 days.

Do: Apply Microsoft's COM security updates to every in-scope Windows build, prioritizing internet-facing hosts and legacy systems (Windows 7, Windows Server 2008/2008 R2, Windows Server 2012) that commonly remain unpatched; because the flaw is on CISA's KEV list, patching is required for federal agencies under BOD 22-01. Verify patch installation via inventory rather than OS build alone, and where patching is impossible (end-of-support systems), isolate or restrict those hosts' network exposure. Ransomware use is not yet confirmed by CISA, but the high EPSS score and KEV listing warrant urgent remediation.

8.873% KEV PoC
  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803
  • Microsoft Windows 7 all editions listed by CISA (32-bit and x64)
  • Microsoft Windows 8.1 all editions listed by CISA
  • +6 more
masshundreds of millions of Windows devices run the affected versions (Windows 7–10 and Server 2008–2016); residual unpatched exposure plausibly in the millions
Full article407 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds a Microsoft COM for Windows bug to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a deserialization of untrusted data vulnerability in Microsoft COM for Windows, tracked as CVE-2018-0824 (CVSS score of 7.5), to its Known Exploited Vulnerabilities (KEV) catalog.

A deserialization of untrusted data vulnerability arises when an application deserializes data from an untrusted source without proper validation. Deserialization is the process of converting data from a serialized format (like JSON or XML) back into an object or data structure in memory.

“A remote code execution vulnerability exists in “Microsoft COM for Windows” when it fails to properly handle serialized objects.” reads the advisory published by Microsoft.

“An attacker who successfully exploited the vulnerability could use a specially crafted file or script to perform actions. In an email attack scenario, an attacker could exploit the vulnerability by sending the specially crafted file to the user and convincing the user to open the file. In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability.”

According to the advisory, an attacker can trigger the issue by tricking the victim into visiting a website by clicking a link and then convincing the user to open the specially crafted file.

This week, Cisco Talos researchers reported that the China-linked group compromised a Taiwanese government-affiliated research institute. The experts attributed the attack with medium confidence to the APT41 group.

The campaign started as early as July 2023 and threat actors delivered the ShadowPad malware, Cobalt Strike, and other post-exploitation tools. Talos also discovered that APT41 created a custom loader to inject a proof-of-concept for CVE-2018-0824 directly into memory. The threat actors used a remote code execution vulnerability to achieve local privilege escalation.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by August 26, 2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, US CISA Known Exploited Vulnerabilities catalog)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/166670/security/cisa-microsoft-com-for-windows-known-exploited-vulnerabilities-catalog.html