ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

OilRig Exploits Windows Kernel Flaw in Espionage Campaign Targeting UAE and Gulf

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-30088
Microsoft Windows Kernel TOCTOU Race Condition Privilege Escalation (CVE-2024-30088)

CVE-2024-30088 is a time-of-check to time-of-use (TOCTOU) race condition in the Microsoft Windows kernel (CWE-367) that allows a local, low-privileged attacker to elevate to SYSTEM-level privileges. Because it is a timing race with high attack complexity, exploitation requires locally executing crafted code that repeatedly races the kernel's validation of a resource, but no user interaction is needed and the attacker only needs the ability to already run code on the target. Successful exploitation grants full control of the local machine (high confidentiality, integrity, and availability impact), which attackers typically chain after initial access or another flaw to gain complete host compromise. Virtually all supported Windows 10 and Windows 11 client releases and Windows Server 2016 through 2022 23H2 are affected if unpatched. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, Iran-linked OilRig used it in an espionage campaign targeting UAE and Gulf governments, and EPSS assigns a ~68% probability of exploitation within 30 days (99th percentile).

Do: Apply the Windows cumulative security update for CVE-2024-30088 from Microsoft's advisory on every affected Windows 10, Windows 11, and Windows Server release (the fix shipped in Microsoft's June 2024 monthly security updates; confirm your build number against the advisory). Prioritize multi-user hosts, RDP/jump servers, and endpoints where untrusted users or code run, since this is a local privilege escalation used post-compromise — check endpoint logs for suspicious local process activity coinciding with privilege changes. Consistent with the CISA KEV required action (added 2024-10-15), patch promptly per vendor instructions or discontinue use of affected builds if patching is not possible.

7.068% KEV ransomware
  • microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • microsoft Windows 11 21H2, 22H2, 23H2
  • microsoft Windows Server 2016, 2019, 2022, 2022 23H2
mass≈1 billion+ Windows 10/11 client devices and hundreds of thousands to millions of Windows Server hosts (unpatched installed base)
Full article461 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananOct 13, 2024

The Iranian threat actor known as OilRig has been observed exploiting a now-patched privilege escalation flaw impacting the Windows Kernel as part of a cyber espionage campaign targeting the U.A.E. and the broader Gulf region.

"The group utilizes sophisticated tactics that include deploying a backdoor that leverages Microsoft Exchange servers for credentials theft, and exploiting vulnerabilities like CVE-2024-30088 for privilege escalation," Trend Micro researchers Mohamed Fahmy, Bahaa Yamany, Ahmed Kamal, and Nick Dai said in an analysis published on Friday.

The cybersecurity company is tracking the threat actor under the moniker Earth Simnavaz, which is also referred to as APT34, Crambus, Cobalt Gypsy, GreenBug, Hazel Sandstorm (formerly EUROPIUM), and Helix Kitten.

The attack chains entail the deployment of a previously undocumented implant that comes with capabilities to exfiltrate credentials through on-premises Microsoft Exchange servers, a tried-and-tested tactic adopted by the adversary in the past, while also incorporating recently disclosed vulnerabilities to its exploit arsenal.

CVE-2024-30088, patched by Microsoft in June 2024, concerns a case of privilege escalation in the Windows kernel that could be exploited to gain SYSTEM privileges, assuming the attackers can win a race condition.

Initial access to target networks is facilitated by means of infiltrating a vulnerable web server to drop a web shell, followed by dropping the ngrok remote management tool to maintain persistence and move to other endpoints in the network.

The privilege escalation vulnerability subsequently serves as a conduit to deliver the backdoor, codenamed STEALHOOK, responsible for transmitting harvested data via the Exchange server to an email address controlled by the attacker in the form of attachments.

A notable technique employed by OilRig in the latest set of attacks involves the abuse of the elevated privileges to drop the password filter policy DLL (psgfilter.dll) in order to extract sensitive credentials from domain users via domain controllers or local accounts on local machines.

"The malicious actor took great care in working with the plaintext passwords while implementing the password filter export functions," the researchers said. "The threat actor also utilized plaintext passwords to gain access and deploy tools remotely. The plaintext passwords were first encrypted before being exfiltrated when sent over networks."

It's worth noting that the use of psgfilter.dll was observed back in December 2022 in a connection with an OilRig campaign targeting organizations in the Middle East using another backdoor dubbed MrPerfectionManager.

"Their recent activity suggests that Earth Simnavaz is focused on abusing vulnerabilities in key infrastructure of geopolitically sensitive regions," the researchers noted. "They also seek to establish a persistent foothold in compromised entities, so these can be weaponized to launch attacks on additional targets."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2024/10/oilrig-exploits-windows-kernel-flaw-in.html