Week in review: HiveNightmare on Windows 10, Kaseya obtains REvil decryptor
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-32589 | A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6. A Use After Free (CWE-416) vulnerability in FortiManager version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.2.10 and below, version 5.0.12 and below and FortiAnalyzer version 7.0.0, version 6.4.5 and below, version 6.2.7 and below, version 6.0.10 and below, version 5.6.10 and below, version 5.4.7 and below, version 5.3.11, version 5.2.10 to 5.2.4 fgfmsd daemon may allow a remote, non-authenticated attacker to execute unauthorized code as root via sending a specifically crafted request to the fgfm port of the targeted device. NVD description · AI analysis pending | 9.8 | 9% |
| — | ||
| CVE-2021-33909 | fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of fs/seq_file.c in the Linux kernel 3.16 through 5.13.x before 5.13.4 does not properly restrict seq buffer allocations, leading to an integer overflow, an Out-of-bounds Write, and escalation to root by an unprivileged user, aka CID-8cae8cd89f05. NVD description · AI analysis pending | 7.8 | 10% | PoC ×2 |
| — | |
| CVE-2021-36934 | Local Privilege Escalation (SeriousSAM/HiveNightmare) in Microsoft Windows 10 CVE-2021-36934 is an elevation of privilege vulnerability in Windows caused by overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database. A local attacker who already has the ability to execute low-privileged code on a victim system can leverage the misconfigured ACLs to gain arbitrary code execution with SYSTEM privileges, then install programs, view, change or delete data, or create new accounts with full user rights. Affected products per the CPE data are Windows 10 versions 1809, 1909, 2004, 20H2 and 21H1, with related coverage noting the bug impacts all Windows 10 versions released in the past 2.5 years and also references Windows 11. CISA added the flaw to its Known Exploited Vulnerabilities Catalog on 2022-02-10, confirming in-the-wild exploitation, and EPSS assigns a 67.3% probability of exploitation within 30 days (99th percentile). Mitigation is two-step: installing the security update alone is not sufficient — administrators must also manually delete all shadow copies of system files, including the SAM database, per KB5005357. Do: Apply Microsoft's security update per vendor instructions, then follow KB5005357 to manually delete all shadow copies of system files (including the SAM database), because the update alone does not fully mitigate the vulnerability. Restrict or verify ACLs on the System32 config directory and shadow-copy access if shadow-copy deletion cannot be done immediately, and prioritize patching given the flaw's listing in CISA's Known Exploited Vulnerabilities Catalog. | 7.8 | 67% | KEV |
| masshundreds of millions of Windows 10 devices (every supported feature update from mid-2018 through mid-2021 is in scope) |
Full article782 words · extracted from helpnetsecurity.com · click to collapse
Here’s an overview of some of last week’s most interesting news and articles:
Kaseya obtains universal REvil decryptor
There’s finally some good news for the MSPs and their customers that have been hit by the REvil ransomware gang via compromised Kaseya VSA software: a universal decryptor has made it available to affected organizations.
DDoS attacks are up, with ever-greater network impact
With an overall rise in available network capacity, cyber criminals are increasingly targeting their victims with high intensity attacks, rather than simply congesting client links.
MITRE Engenuity launches ATT&CK Evaluations for ICS
ATT&CK for ICS provides a common language to describe the tactics and techniques that cyber adversaries use when attacking the systems that operate some of the nation’s most critical infrastructures, including energy transmission and distribution plants, oil refineries, wastewater treatment facilities, and more.
Researchers flag 7-years-old privilege escalation flaw in Linux kernel (CVE-2021-33909)
A vulnerability (CVE-2021-33909) in the Linux kernel’s filesystem layer that may allow local, unprivileged attackers to gain root privileges on a vulnerable host has been unearthed by researchers.
Bug hunters asked to probe Microsoft Teams mobile apps, can earn up to $30k
Microsoft is looking for reports about vulnerabilities of Critical or Important severity reproducible on a fully patched operating system (iOS or Android) and the latest version of the corresponding Microsoft Teams mobile application.
Easily exploitable, unpatched Windows privilege escalation flaw revealed (CVE-2021-36934)
A researcher has unearthed an easily exploitable vulnerability (CVE-2021-36934) in Windows 10 that may allow local non-administrative users to gain administrative-level privileges. Several Windows Server versions are also vulnerable. A zero-day PoC exploit has been released.
IoT malware attacks rose 700% during the pandemic
Zscaler released a study examining the state of IoT devices left on corporate networks during a time when businesses were forced to move to a remote working environment.
40% fell victim to a phishing attack in the past month
Nearly three-quarters (74%) of respondents said their organizations have fallen victim to a phishing attack in the last year, with 40% confirming they have experienced one in the last month.
How do I select a data recovery solution for my business?
To select a suitable data recovery solution for your business, you need to think about a variety of factors. We’ve talked to several industry professionals to get their insight on the topic.
Protect your smartphone from radio-based attacks
Smartphones contain a plethora of radios – typically cellular, Wi-Fi, Bluetooth and Near Field Communication (NFC) – that enable wireless communication in a variety of circumstances, and these radios are designed to remain turned on as the user moves through the world. It’s important for all smartphone users to understand the security implications of these wireless interfaces.
There are new unpatched bugs in Windows Print Spooler
Security researchers have unearthed new elevation of privilege (EoP) bugs in Windows Print Spooler, one of the oldest Windows components.
Fortinet plugs RCE hole in FortiManager and FortiAnalyzer (CVE-2021-32589)
A vulnerability (CVE-2021-32589) in FortiManager and FortiAnalyzer could be exploited by remote, non-authenticated attackers to execute unauthorized / malicious code as root, Fortinet has warned.
Asset inventory management: What’s the ROI?
Asset inventory management is critical to any company’s planning and accounting process.
A unified approach is the future of data backup
Though disaster recovery and backup solutions have always been critical components for any business, the pandemic put a spotlight on the many threats to data today.
Combating deepfakes: How we can future-proof our biometric identities
How worried should we be about deepfakes? What sort of threat do they pose to digital ID verification and the biometric technology that we are becoming so reliant on, and are there ways to combat the threat?
Is differential privacy the ideal privacy-enhancing computation technique for your business?
Let’s explore some of the challenges and opportunities of integrating privacy-enhancing computation capabilities into operations, with special attention on differential privacy.
Vaccinate your data: Addressing and adapting to new data risks
As hybrid working becomes the norm and data sets inevitably continue to grow, data privacy, compliance and protection officers need to ensure they are fully immunized against new data risks to keep the trust of their employees, partners, and customers alike.
Questions that help CISOs and boards have each other’s back
Boards of directors and executives seem increasingly interested in understanding their companies’ security posture. This interest presents an opportunity for security teams.
Product showcase: Action1 RMM
Action1 RMM is a cloud-native, all-in-one solution that provides visibility and control over all your endpoints from one web-based console. It is free for organizations with up to 50 endpoints, without limitations or hidden costs.
New infosec products of the week: July 23, 2021
A rundown of infosec products released last week.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/07/25/week-in-review-hivenightmare-on-windows-10-kaseya-obtains-revil-decryptor/