ZeroHour
Security Affairspublished ()ingested @securityaffairs

Stuxnet bug is still one of the most exploited flaws in the wild

mediumExploit / PoCimportance 50CVE-2010-2568

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2010-2568
Remote Code Execution in Microsoft Windows via Malicious Shortcut (LNK) Parsing

CVE-2010-2568 is an input-validation flaw (CWE-20) in how Microsoft Windows parses shortcut files, allowing malicious code to execute when the operating system merely displays the icon of a malicious shortcut (.lnk) file. Triggering requires nothing more than the Windows shell rendering the shortcut's icon — for example when browsing a folder containing the file, a vector widely abused via USB drives and network shares in incidents tied to Stuxnet and Gauss. A successful attacker gains arbitrary code execution with the privileges of the logged-on user, suitable for initial access or lateral movement. All Microsoft Windows systems as listed by CISA are affected; the provided data does not specify exact version ranges. Exploitation is confirmed in the wild: the flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2022-09-15), carries a 91.3% EPSS probability of exploitation (100th percentile), and related headlines report Microsoft having to re-issue the fix more than once for Stuxnet-related attacks.

Do: Apply Microsoft updates per vendor instructions (CISA's required action); since headlines indicate this LNK fix was re-released multiple times, verify systems carry the latest cumulative Windows updates rather than only the original patch. Until patched, avoid browsing untrusted removable drives or network shares with a shell that renders shortcut icons, and monitor for LNK-delivered malware.

91% KEV
  • Microsoft Windows
mass≈1 billion+ Windows installations worldwide (unknown share unpatched; legacy versions carry the highest risk)
Full article382 words · extracted from securityaffairs.com · click to collapse

A new report published by Kaspersky confirms that Stuxnet exploits targeting a Windows Shell Vulnerability is still widely adopted by threat actors.

The case that I’m going to present to you demonstrates the importance of patch management and shows the effects of the militarization of cyberspace.

Unpatched software is an easy target for hackers that can exploit old vulnerabilities to compromise the systems running them. Let’s consider, for example, the exploit code used in the notorious Stuxnet cyber weapon that hit the centrifuges at the Iranian nuclear plant at Natanz.

The flaw exploited by the Stuxnet worm was first patched by Microsoft in 2010, but threat actors in the wild continue to exploit it in a huge number of cyber attack.

According to Kaspersky Lab, the flaw used by Stuxnet to target Windows machines, tracked as CVE-2010-2568 has been weaponized to remotely execute code on unpatched Windows computers.

The dangerous trend continues, in August 2014 experts from Kaspersky revealed that in the period between November 2013 and June 2014, the Windows Shell vulnerability (CVE-2010-2568) exploited by Stuxnet was detected 50 million times targeting nearly 19 million machines all over the world.

In 2015, and in 2016, roughly one in four Kaspersky users was targeted by an exploit code leveraging the CVE-2010-2568.

“To take just one example, when we looked at our most recent threat statistics we found that exploits to CVE-2010-2568 (used in the notorious Stuxnet campaign) still rank first in terms of the number of users attacked. Almost a quarter of all users who encountered any exploit threat in 2016 were attacked with exploits to this vulnerability.” states a report published by Kaspersky.

Stuxnet attack

Of course, the CVE-2010-2568 vulnerability only affects very old OS, including Windows XP and Windows Server 2008, and unpatched versions of Windows 7.

Attackers most used the Stuxnet exploit code to create malicious codes that can “self-replicate” over a targeted network.

Concluding, the militarization of cyberspace has serious consequences for Internet users, even if the malware was spread many years ago.

I suggest reading of the research published by Kaspersky that provides interesting data on the most exploited vulnerabilities and threat actors leveraging on them.

[adrotate banner=”9″] [adrotate banner=”12″]

Pierluigi Paganini

(Security Affairs – Stuxnet exploits, hacking)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/58200/uncategorized/stuxnet-vulnerability.html