ZeroHour
Kaspersky Securelistpublished ()ingested @Securelist

Microsoft Updates Internet Explorer against Highly Targeted 0day Distributing Pirpi

criticalVulnerability exploited in the wildimportance 60CVE-2014-1776

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2014-1776
Use-After-Free Memory Corruption RCE in Microsoft Internet Explorer

CVE-2014-1776 is a use-after-free memory corruption flaw in Microsoft Internet Explorer that can be triggered when the browser processes specially crafted web content, corrupting memory in a manner an attacker controls. A remote attacker can deliver the malicious content from a site they host or inject it into a compromised/legitimate website, causing Internet Explorer to access freed memory under attacker control. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker that user's privileges on the client machine. Any organization or user running an affected version of Internet Explorer is exposed, and the flaw has been associated with highly targeted attack activity, including the FireEye-documented zero-day exploit in the wild and the targeted Pirpi-distributed 0-day. The vulnerability was exploited in the wild as a zero-day, was addressed by Microsoft updates, and was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-01-28; no public proof-of-concept is known.

Do: Apply Microsoft's Internet Explorer security updates per vendor instructions, prioritizing this as a KEV-required remediation, and verify all workstations still launching IE or legacy MSHTML-based content are patched. Reduce residual exposure by steering users away from Internet Explorer for untrusted sites and auditing intranet applications and tooling for lingering IE dependencies. Because the exact affected versions are not in the data, cross-check Microsoft's advisory to confirm your deployed IE versions are covered by the fix.

88% KEV
  • Microsoft Internet Explorer
mass≈ hundreds of millions of users/endpoints (IE held roughly half of global browser market share when exploited in 2014)
Full article763 words · extracted from securelist.com · click to collapse

Software

Software

01 May 2014

minute read

The patch is up! Microsoft is pushing out an Out of Band (OOB) security update MS14-021 to address the recently disclosed Internet Explorer 0day exploit incidents involving a known, high end threat actor. Cheers to a quick response from such a large vendor on this issue!

The story goes like this. The week of the 20th, attackers known to send very well crafted emails to high value targets made an attempt to redirect folks’ browsers to sites hosting the IE 0day. The goal of the attacks was to deliver a newer version of the years-old Pirpi RAT to compromised, victim systems by taking control of their browsers, and in turn, their systems and networks.

The zero day exploit targeted a memory corruption vulnerability in Internet Explorer. This use-after-free vulnerability (CVE-2014-1776), a type that continues to trouble Microsoft code, was maintained in the mshtml.dll, mshtml.tlb, Microsoft-windows-ie-htmlrendering.ptxml, and Wow64_microsoft-windows-ie-htmlrendering.ptxml code executing in Internet Explorer on all Windows OS. The exploits focused on attacking this code in IE 9 through IE 11.

Researchers previously reported that vgx.dll code was vulnerable, but that is not the code being corrected. The MSRC engineers cleared it up yesterday “we-d like to clarify that VGX.DLL does not contain the vulnerable code leveraged in this exploit.” Unregistering that dll was simply the quickest way to disable related browser functionality. For those of you that unregistered vgx.dll and are applying the update, you will have to re-register the dll: “If you applied the workaround to unregister VGX.DLL, you do not have to undo this workaround before applying the security update. However, the security update will not re-register vgx.dll. See the Workarounds section for the vulnerability for steps on how to re-register vgx.dll.”

208193615The patch itself appears to be pretty large –onx64Windows 7systems running IE 11,it is an approximately16 mbdownload.mshtml.dll is over 20 mb on some versions of IE and the OS, so on some systems, the download may be larger. I haven’t seen any required reboots as a result of the patch yet. Fixes for Internet Explorer version 6 – 8 is being delivered as well for Windows XP SP3 and x64 XP SP2 users.

Now that the patch arrived, it is very important that everyone update. The vulnerability effects mostly all versions of Internet Explorer, on mostly all versions of Windows OS (Windows Update will sort it out for you). Before, it was used in very limited attack volume. According to a recent Microsoft post “The reality is there have been a very small number of attacks based on this particular vulnerability and concerns were, frankly, overblown. Unfortunately this is a sign of the times and this is not to say we don-t take these reports seriously. We absolutely do.” I mostly agree. Security teams just didn’t see it widely used, and we haven’t yet found it used against any of our customer systems. But ItW exploit code has expanded from IE 9 through 11 to attacking Internet Explorer 8 running on Windows XP, also in very limited attack volume.
But, once the update and code is analysed, it can easily be delivered into waiting mass exploitation cybercrime networks. Run Windows Update if you are using a Windows system, and cheers to Microsoft response for delivering this patch to their massive user base quickly.

One final thought, the week is turning out to be a busy one for reponse, as this is the second 0day patch up this week. Note that the Adobe Flash 0day that our guys reported to Adobe and posted earlier this week is unrelated to this IE incident. The targeted Flash 0day watering hole incidents occurred specifically on Syrian websites.

The Flash components used in the IE 0day attacks were “helper components” to enable evasion of defensive technologies built into newer versions of Internet Explorer and Windows software. Both Flash and Internet Explorer, of course, need to updated.

Latest Webinars
Reports

Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.

Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.

Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.

Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.

Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/microsoft-updates-internet-explorer/59408/