ZeroHour
The Recordpublished ()ingested

CISA adds Apple zero-day, Cisco and Gigabyte bugs to exploited vulnerabilities list

criticalExploit / PoC exploited in the wildimportance 60CVE-2020-3433CVE-2020-3153

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3153
DLL Search Path Hijacking LPE in Cisco AnyConnect Secure Mobility Client for Windows

CVE-2020-3153 is an uncontrolled search path vulnerability (CWE-427) in the Windows client of Cisco AnyConnect Secure Mobility Client, which mishandles directory paths when running with elevated privileges. An attacker or malware that already has valid credentials and local access on a Windows endpoint can copy malicious files, such as DLLs, into locations loaded by the elevated AnyConnect process. Successful exploitation yields system-level (SYSTEM) privilege execution on the endpoint via DLL preloading or DLL hijacking, making it an effective local privilege escalation step in broader intrusion chains. Any organization running the AnyConnect VPN client on Windows endpoints is potentially affected. The flaw was added to CISA KEV on 2022-10-24 with known ransomware use, and its EPSS of 28.3% (98th percentile) indicates an elevated probability of near-term exploitation, though no public PoC is known.

Do: Apply the fixed AnyConnect release per Cisco's instructions, as required by CISA's KEV listing, prioritizing Windows endpoints where the client is installed. Inventory your estate for AnyConnect installations and verify client builds are current. Given the known ransomware use, hunt for signs of local DLL planting in writable directories and review privilege-escalation activity on Windows hosts.

6.528% KEV ransomware PoC ×4
  • Cisco AnyConnect Secure Mobility Client for Windows
massmillions of enterprise Windows endpoints (AnyConnect is among the most widely deployed corporate VPN clients)
CVE-2020-3433
DLL Hijacking LPE in Cisco AnyConnect Secure Mobility Client for Windows

Cisco AnyConnect Secure Mobility Client for Windows contains a DLL hijacking flaw (CWE-427) in its interprocess communication (IPC) channel, caused by insufficient validation of resources loaded at run time. An attacker who already has valid credentials on the Windows machine can send a crafted IPC message to the AnyConnect process and coerce it into loading a malicious DLL. Successful exploitation allows arbitrary code execution with SYSTEM privileges, turning a low-privileged local foothold into full administrative control of the endpoint. Any organization running AnyConnect on Windows endpoints is affected. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-10-24 with known ransomware use, a public proof-of-concept is available, and news reports confirm active exploitation alongside another AnyConnect Windows flaw.

Do: Upgrade Cisco AnyConnect for Windows to a fixed release per Cisco's security advisory, as required by the CISA KEV required action (apply updates per vendor instructions). Since exploitation requires valid local credentials, limit local logon privileges on endpoints and prioritize patching given known ransomware use. Inventory Windows endpoints for AnyConnect installs and monitor for suspicious DLL loads in the AnyConnect process path.

7.810% KEV ransomware PoC
  • Cisco AnyConnect Secure Mobility Client for Windows
masstens of millions of Windows endpoints running AnyConnect (dominant enterprise VPN client installed base; no precise public count in this data)
Full article626 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency (CISA) added several vulnerabilities to its list of bugs currently being exploited by hackers, ordering all federal civilian agencies to patch the bugs before November 15.

On Tuesday, CISA added a zero-day vulnerability affecting all iPhone 8 and later models as well as several iPad models.

“An application may be able to execute arbitrary code with kernel privileges,” Apple explained in an advisory on Monday. “Apple is aware of a report that this issue may have been actively exploited.”

It is the ninth zero-day affecting Apple devices that has been exploited this year and Apple addressed the bug in its latest iOS update. 

Michael Covington of the Apple-focused cybersecurity company Jamf explained that the bug allowed rogue applications to write data to a location it should not have been allowed to access, resulting in data corruption or unauthorized code execution. 

“The latest security fixes from Apple are a good reminder that even the most recent software releases can contain bugs,” he said. “Details on the vulnerabilities are still emerging, but we know that eight of the issues fixed were being actively exploited.”

Ryan Cribelar, vulnerability research engineer at Nucleus Security, said the issue was part of a larger trend of vulnerabilities related to the kernel – effectively the foundation of a computer's operating system.

Cribelar explained that for Apple and others, the kernel is becoming a more popular home for threat actors to explore unfound exploitation – something that has had global implications in recent months with the controversy surrounding spyware makers employed by governments.

“I think part of it stems from an increase in Linux-based malware, but also the continuing pressure on the spyware industry. Targeting high-value individuals that would fall victim to spyware stems highly from zero-days a lot like this one,” he said. 

Vulcan Cyber’s Mike Parkin echoed that assessment, adding that anything that could potentially allow remote code execution with kernel privileges is problematic.  

Gigabyte and Cisco

CISA also added six other vulnerabilities to its list yesterday — four from hardware company Gigabyte and two affecting Cisco products. 

People who use Gigabyte products typically build their own custom PCs for playing video games at home, Cribelar told The Record, adding that these are suitable for mining cryptocurrency and “are a great target for a rogue nation looking to use cryptocurrency as a way to evade sanctions.”

According to Cribelar, a proof of concept exploit for the Gigabyte vulnerabilities has been available since 2019. 

“In the case of the GIGABYTE vulnerabilities, the addition could mean anything from nation-state actors pulling off a sophisticated attack against a high-value target's home network,” he said. “Or it could simply be that gaming PCs are rampant with hardware for crypto mining capabilities, and are a high-yielding target." 

The other vulnerabilities added to CISA’s list concern issues affecting Cisco’s AnyConnect Secure Mobility Client for Windows. A proof of concept exploit for both of the vulnerabilities – CVE-2020-3433 and CVE-2020-3153 – has been available on GitHub since September 2020. 

A patch has been available since August 5, 2020, but yesterday Cisco updated their advisory on the issue, noting that its Product Security Incident Response Team “became aware of additional attempted exploitation” in October 2022. 

Cribelar theorized that the issue is part of a larger trend of exploiting transition to working from home, noting that there has been a “fluctuation of disclosure of vulnerabilities in vital technologies like VPN.”

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-apple-zero-day-cisco-and-gigabyte-bugs-to-exploited-vulnerabilities-list