ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

CVE-2021-40444 exploitation: Researchers find connections to previous attacks

criticalVulnerabilityimportance 60CVE-2021-40444

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-40444
Remote Code Execution via MSHTML Rendering Engine in Microsoft Windows/Office (CVE-2021-40444)

CVE-2021-40444 is a remote code execution vulnerability in the Microsoft MSHTML browser rendering engine, which Microsoft Office documents can load on Windows systems. It is triggered when a user is convinced to open a specially crafted Office document containing a malicious ActiveX control hosted by the MSHTML engine (tracked as a path-traversal-class issue, CWE-22). A successful attacker gains the ability to run arbitrary code in the context of the logged-on user, with greater impact when that user has administrative rights. Any Windows system that can open Office documents is exposed, spanning Windows 7, 8.1, RT 8.1, Windows 10 (1507 through 21H1) and Windows Server 2004/2008. Exploitation is confirmed in the wild: Microsoft observed targeted attacks at disclosure, the flaw is in CISA's KEV with known ransomware use, and Microsoft released security updates on September 14, 2021.

Do: Apply Microsoft's security updates released September 14, 2021 for your Windows version immediately; this is a CISA KEV item with known ransomware use, so patching is treated as mandatory. As interim protection, keep Microsoft Defender Antivirus/Defender for Endpoint signatures current (enterprise detection build 1.349.22.0 or newer, with alerts appearing as 'Suspicious Cpl File Execution') and avoid opening untrusted Office documents, since exploitation requires user interaction with a crafted file.

8.897% KEV ransomware PoC ×2
  • microsoft MSHTML as shipped in the affected Windows releases
  • microsoft Windows 10 1507, 1607, 1809, 1909, 2004, 20H2, 21H1
  • microsoft Windows 7 all versions covered by Microsoft's September 2021 security updates
  • +4 more
masshundreds of millions of Windows PCs and servers (nearly all Windows desktop/laptop installs on affected versions at disclosure)
Full article545 words · extracted from helpnetsecurity.com · click to collapse

The recent targeted attacks exploiting the (at the time) zero-day remote code execution vulnerability (CVE-2021-40444) in Windows via booby-trapped Office documents have been delivering custom Cobalt Strike payloads, Microsoft and Microsoft-owned RiskIQ have shared.

The researchers also found connections between the attackers’ exploit delivery infrastructure and an infrastructure previously used by attackers to deliver human-operated ransomware, the Trickbot trojan and the BazaLoader backdoor/downloader.

The attacks and their possible goals

Judging by the email lures used in these attacks, some of the targets were application development organizations.

The targets would receive an email pointing to the exploit documents hosted on file-sharing sites which, once downloaded and opened, would retrieve a custom Cobalt Strike Beacon loader and loads it into the Microsoft Address Book Import Tool.

CVE-2021-40444 exploitation

The exploit made sure that the target wouldn’t be asked to disable Protected Mode in Microsoft Office and that the payload is executed without any user interaction.

According to Microsoft, at least one organization that was compromised by the attackers was months ago compromised with malware that interacted with the infrastructure tied to ransomware operators (WIZARD SPIDER, aka Ryuk) wielding the Ryuk and Conti ransomware.

RiskIQ researchers also noted the connection and explained how they made it.

“Despite the historical connections, we cannot say with confidence that the threat actor behind the zero-day campaign is part of WIZARD SPIDER or its affiliates, or is even a criminal actor at all, though it is possible. If the threat actors were part of these groups, it means they almost surely purchased the zero-day exploit from a third party because they have not previously shown the ability to develop exploit chains of this complexity,” they added.

The limited nature of the attacks, the aforementioned repeated targeting of the same target, and the use of a zero-day seem to point more towards traditional espionage than ransomware attacks with pure monetary goals, though the researchers can’t be sure of the attackers’ goal.

“In this case, the overlap with known ransomware infrastructure could mean one of several things,” they explained.

“First, that the zero-day operators compromised the infrastructure of the ransomware operators. Second, that the criminal operators are allowing the zero-day operators to piggyback on their existing infrastructure. Third, that the zero-day and ransomware operators are one and the same but engaging in espionage instead of financial crime. Finally, it could mean that both entities could be utilizing the same third party providing Bulletproof Hosting services. There is strong ancillary evidence that suggests this is the case.”

CVE-2021-40444 exploitation in the wild

Security researcher Kevin Beaumont said today that he’s only just now starting to detect signs of “in the wild” exploitation of the flaw:

Btw I am starting to see signs of 'in the wild' (i.e. not targeted ransomware) exploitation of this as of this morning. Fairly low volume still.

— Kevin Beaumont (@GossiTheDog) September 16, 2021

Microsoft has delivered patches for CVE-2021-40444 on September 2021 Patch Tuesday and is urging administrators to implement them as soon as possible.

The company has also shared mitigation advice and hunting queries that can be used by admins to see whether their organization has been targeted. RiskIQ has shared domains and IP addresses that have been used in the attacks, so defenders can block them.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/09/16/cve-2021-40444-exploitation/