ZeroHour
Security Affairspublished ()ingested @securityaffairs

Microsoft fixes CVE-2019-1458 Zero-Day exploited in NK

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-0859
Local Privilege Escalation in Microsoft Win32k on Windows

CVE-2019-0859 is an elevation of privilege vulnerability in the Win32k kernel component of Microsoft Windows, caused by the component failing to properly handle objects in memory. It is exploited locally: a low-privileged user or process already running on the machine can trigger the mishandling with no user interaction required, per the CVSS vector (AV:L/PR:L/UI:N). Successful exploitation elevates the attacker to kernel privileges, with high impact to confidentiality, integrity and availability, typically used to break out of user-level restrictions after an initial foothold. Any unpatched Windows 7, 8.1, RT 8.1, Windows 10 versions 1507 through 1809, or Windows Server 2008, 1709, or 1803 system is affected; the flaw was fixed in Microsoft's April 2019 security updates. It was reported as actively exploited when patched, was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 with known ransomware use, and carries an EPSS of 4.2% (90th percentile); no public PoC is known.

Do: Apply Microsoft's April 2019 (or later) Windows security updates to all affected Windows 7, 8.1, RT 8.1, Windows 10 1507–1809, and Windows Server 2008/1709/1803 systems, per CISA's required action. Prioritize user-facing and shared systems (workstations, RDS/terminal servers, jump hosts) where an attacker is most likely to gain a local foothold, and verify patch levels through your update-management tooling.

7.84% KEV ransomware
  • Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809
  • Microsoft Windows 7
  • Microsoft Windows 8.1
  • +4 more
mass≈hundreds of millions of Windows devices (Win32k ships in every install of the listed Windows versions, which spanned the bulk of Microsoft's >1-billion-device…
CVE-2019-13720
Use-After-Free in Google Chrome WebAudio Allows Heap Corruption (Actively Exploited)

CVE-2019-13720 is a use-after-free (CWE-416) in the WebAudio component of Google Chrome that exists in all releases prior to 78.0.3904.87. A remote attacker can trigger the flaw by luring a user to a crafted HTML page, corrupting the heap when the browser processes audio through the freed memory. Successful exploitation can lead to remote code execution with high impact on confidentiality, integrity, and availability, and a public proof-of-concept for Chrome 78.0.3904.70 is available. The flaw affects desktop and mobile users running vulnerable Chrome builds as well as the Chromium package shipped for openSUSE Leap. Exploitation is confirmed in the wild: Google fixed it as an actively exploited issue in November 2019, it was used in the Operation WizardOpium attacks, and it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-05-23.

Do: Upgrade Google Chrome to 78.0.3904.87 or later (check the current version via the browser's About/Help page) and update the Chromium package on openSUSE Leap using the distribution's update channels. Because this flaw is triggered via a crafted web page and there are no reliable configuration workarounds, prioritizing browser patching across all endpoints is the key mitigation. Defenders should also review whether any user activity coincided with the Operation WizardOpium campaign, as this bug was chained in active attacks.

8.873% KEV PoC
  • google chrome all versions prior to 78.0.3904.87 (vulnerable builds include 78.0.3904.70 and earlier)
  • opensuse leap
masshundreds of millions to billions of Chrome installations worldwide (Chrome is the dominant web browser)
CVE-2019-1458
Win32k Object-Handling Flaw Enables Local Privilege Escalation in Microsoft Windows

An elevation of privilege vulnerability exists in the Windows kernel's Win32k component, which fails to properly handle objects in memory (an uninitialized-variable condition). A local attacker who can already execute limited code on a target machine can trigger the flaw to gain kernel-level execution and elevate to SYSTEM privileges, giving full control of the host. Affected platforms are Windows 7, Windows 8.1, Windows RT 8.1, Windows 10 1507 and 1607, and Windows Server 2008, 2012 and 2016. The bug was patched in Microsoft's December 2019 Patch Tuesday after being actively exploited as a zero-day, including in the WizardOpium campaign attributed to a North Korea-linked actor. It is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-01-10, with known ransomware use) and carries a high EPSS of 74.3%.

Do: Apply the December 2019 security updates (or later cumulative updates) from Microsoft per CISA's required action. Because Windows 7/8.1 and Server 2008/2012 are past end of support and Server 2016 support is winding down, prioritize migration to supported Windows versions. Hunt for signs of local privilege escalation and follow-on activity, since this bug was used as a zero-day and appears in ransomware attack chains.

7.874% KEV ransomware PoC ×2
  • microsoft windows 10 1507 all supported editions at time of patch (December 2019)
  • microsoft windows 10 1607 all supported editions at time of patch (December 2019)
  • microsoft windows 7 all supported editions
  • +5 more
masshundreds of millions of devices (Windows 7 alone held roughly a third of desktop market share at disclosure; millions of Server 2008/2012/2016 hosts remain…
Full article636 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 11, 2019

Microsoft’s December 2019 Patch Tuesday updates fix a total of 36 flaws, including CVE-2019-1458 Windows zero-day exploited in North Korea-linked attacks

Microsoft’s December 2019 Patch Tuesday updates address a total of 36 flaws, including a Windows zero-day, tracked as CVE-2019-1458 exploited in attacks linked to North Korea. The vulnerability could be exploited to execute arbitrary code in kernel mode.

“An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.” reads the security advisory published by Microsoft.

“To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.”

The CVE-2019-1458 vulnerability is a privilege escalation issue related to how the Win32k component handles objects in memory.

Microsoft addresses this vulnerability by correcting how Win32k handles objects in memory.

The vulnerability was reported by Kaspersky, experts at the security firm confirmed that the CVE-2019-1458 flaw has been exploited in a campaign called Operation WizardOpium.

“In November 2019, Kaspersky technologies successfully detected a Google Chrome 0-day exploit that was used in Operation WizardOpium attacks. During our investigation, we discovered that yet another 0-day exploit was used in those attacks.” reads the analysis published by Kaspersky. “The exploit for Google Chrome embeds a 0-day EoP exploit (CVE-2019-1458) that is used to gain higher privileges on the infected machine as well as escaping the Chrome process sandbox. The exploit is very similar to those developed by the prolific 0-day developer known as ‘Volodya’.”

The exploit was developed by an individual known as “Volodya,” who has been offering for sale exploit in the cybercrime underground. 

We found another 0day used in the wild, CVE-2019-0859. This one seems to have been developed by the prolific 0day maker and seller known as “Volodya”. Volodya sells 0days to both criminals and APTs https://t.co/1WBvETJTF2

— Costin Raiu (@craiu) April 18, 2019

The vulnerability has been exploited alongside the CVE-2019-13720 Chrome zero-day as part of a campaign tracked as Operation WizardOpium at the end of October.

The researchers pointed out that the campaign has very weak code similarities with past Lazarus‘s operations, but the evidence they collected doesn’t allow a certain attribution.

“We are calling these attacks Operation WizardOpium. So far, we have been unable to establish a definitive link with any known threat actors. There are certain very weak code similarities with Lazarus attacks, although these could very well be a false flag.” reads a post published by Kaspersky.

At least one of the websites targeted in Operation WizardOpium is in line with earlier attacks of the DarkHotel operation.

Kaspersky experts discovered that the Chrome exploit also embeds an exploit for the CVE-2019-1458 vulnerability that was used by attackers to escalate privileges on the compromised system and escape the Chrome process sandbox.

The privilege escalation exploit works against Windows 7 and some Windows 10 builds, according to the experts it doesn’t affect the latest Windows 10 builds.

“The vulnerability itself is related to windows switching functionality (for example, the one triggered using the Alt-Tab key combination). That’s why the exploit’s code uses a few WinAPI calls (GetKeyState/SetKeyState) to emulate a key press operation,” Kaspersky explained.

The experts noticed that the compilation timestamp for the file containing the exploit for CVE-2019-1458 was “Wed Jul 10 00:50:48 2019” that is different from the other binaries, a circumstance that indicates it has been in use for some time.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, North Korea)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/94936/hacking/microsoft-fixes-cve-2019-1458.html