CISA Warns of Active Exploitation of Microsoft SharePoint Vulnerability (CVE-2024
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-38094 | Authenticated deserialization RCE in Microsoft SharePoint Server CVE-2024-38094 is a deserialization of untrusted data flaw (CWE-502) in on-premises Microsoft SharePoint Server, rated 7.2 (high) on CVSS 3.1 and classified by Microsoft as a remote code execution vulnerability. The CVSS vector (AV:N/AC:L/PR:H/UI:N) indicates the attack is network-reachable but requires an attacker who already holds high-privileged access, such as site collection or farm administrator credentials, to submit maliciously crafted serialized data to the server. Successful exploitation yields remote code execution on the SharePoint server with high impact to confidentiality, integrity, and availability, giving attackers a foothold for follow-on activity such as ransomware deployment. Any organization running on-premises SharePoint Server is potentially affected, while SharePoint Online in Microsoft 365 is a separate cloud service. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-22 with known ransomware use, and the EPSS of 50.9% (99th percentile) signals a high probability of continued exploitation, although no public proof-of-concept is known. Do: Apply Microsoft's vendor-supplied mitigations and security updates for SharePoint Server as soon as possible; CISA's required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Limit internet exposure of SharePoint front-ends, review high-privileged site and farm administrator accounts for compromise or unusual activity, and prioritize patching given the confirmed ransomware use. No public PoC is known, but the 50.9% EPSS and KEV listing indicate attackers are actively working this flaw. | 7.2 | 51% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed SharePoint Server deployments (roughly 10k-100k servers) | |
| CVE-2024-44068 | An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. An issue was discovered in the m2m scaler driver in Samsung Mobile Processor and Wearable Processor Exynos 9820, 9825, 980, 990, 850,and W920. A Use-After-Free in the mobile processor leads to privilege escalation. NVD description · AI analysis pending | 8.1 | 1% |
| — |
Full article673 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 23, 2024Vulnerability / Threat Intelligence
A high-severity flaw impacting Microsoft SharePoint has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2024-38094 (CVSS score: 7.2), has been described as a deserialization vulnerability impacting SharePoint that could result in remote code execution.
"An authenticated attacker with Site Owner permissions can use the vulnerability to inject arbitrary code and execute this code in the context of SharePoint Server," Microsoft said in an alert for the flaw.
Patches for the security defect were released by Redmond as part of its Patch Tuesday updates for July 2024. The exploitation risk is compounded by the fact that proof-of-concept (PoC) exploits for the flaw are available in the public domain.
"The PoC script [...] automates authentication to a target SharePoint site using NTLM, creates a specific folder and file, and sends a crafted XML payload to trigger the vulnerability in the SharePoint client API," SOCRadar said.
There are currently no reports about how CVE-2024-38094 is exploited in real-world attacks. In light of in-the-wild abuse, Federal Civilian Executive Branch (FCEB) agencies are required to apply the latest fixes by November 12, 2024, to secure their networks.
The development comes as Google's Threat Analysis Group (TAG) revealed that a now-patched zero-day vulnerability in Samsung's mobile processors has been weaponized as part of an exploit chain to achieve arbitrary code execution.
Assigned the CVE identifier CVE-2024-44068 (CVSS score of 8.1), it has been addressed as of October 7, 2024, with the South Korean electronics giant characterizing it as a "use-after-free in the mobile processor [that] leads to privilege escalation."
While Samsung's terse advisory makes no mention of it having been exploited in the wild, Google TAG researchers Xingyu Jin and Clement Lecigne said a zero-day exploit for the shortcoming has been used as part of a privilege escalation chain.
"The actor is able to execute arbitrary code in a privileged cameraserver process," the researchers said. "The exploit also renamed the process name itself to '[email protected],' probably for anti-forensic purposes."
The disclosures also follow a new proposal from CISA that puts forth a series of security requirements in order to prevent bulk access to U.S. sensitive personal data or government-related data by countries of concern and covered persons.
In line with the requirements, organizations are expected to remediate known exploited vulnerabilities within 14 calendar days, critical vulnerabilities with no exploit within 15 calendar days, and high-severity vulnerabilities with no exploits within 30 calendar days.
"To ensure and validate that a covered system denies covered persons access to covered data, it is necessary to maintain audit logs of such accesses as well as organizational processes to utilize those logs," the agency said.
"Similarly, it is necessary for an organization to develop identity management processes and systems to establish an understanding of what persons may have access to different data sets."
Update
Cybersecurity company Rapid7 has warned that unknown threat actors are actively exploiting CVE 2024-38094 to gain initial access and drop a web shell, adding the attacker remained undetected for a period of two weeks.
After establishing an initial foothold, the adversary is said to have set up persistence, carry out lateral movement, and ultimately compromise a Microsoft Exchange service account with domain administrator privileges.
Some of the tools deployed over the course of the attack included Impacket, Fast Reverse Proxy (FRP), and Mimikatz, but not before disabling Windows Defender Threat Detection (WDTD) and adding an exclusion rule to prevent flagging the execution of FRP.
The Exchange service account, per Rapid7, was used to install the Horoung Antivirus software, causing a conflict with security tools already installed on the compromised host and resulting in a crash. "Stopping the system's current security solutions allowed the attacker freedom to pursue follow-on objectives," the company said.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/cisa-warns-of-active-exploitation-of.html