ZeroHour
The Recordpublished ()ingested 1

CISA adds Microsoft, Apple bugs to exploited vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-37969
Out-of-bounds write flaw in Microsoft Windows CLFS driver enables privilege escalation

The Windows Common Log File System (CLFS) driver contains an input-validation flaw (CWE-20) that leads to an out-of-bounds write (CWE-787), allowing an attacker who already has a foothold or local access on a system to escalate privileges. It is triggered when the driver processes malformed or specially crafted common log file data, rather than via a remote network request on its own. Successful exploitation yields elevated (typically SYSTEM-level) privileges, giving the attacker full control of the host and making the bug a common post-exploitation link in ransomware chains. CISA lists the affected product broadly as 'Microsoft Windows', so essentially all Windows installations current at the time of disclosure were in scope. The flaw is confirmed exploited in the wild: CISA added it to the KEV catalog on 2022-09-14 with known ransomware use, EPSS puts 30-day exploitation probability at 28.3% (98th percentile), and no public PoC is known.

Do: Apply Microsoft's September 2022 (or later) cumulative updates to every Windows host per vendor instructions, prioritizing endpoints and servers exposed for user or remote access. Because this is a local privilege escalation, treat it as a post-exploitation risk: also harden and patch initial-access surfaces (RDP, VPN, other exposed services) and hunt for signs of compromise such as unexpected SYSTEM-spawned processes or anomalous activity involving clfs.sys. Ransomware operators are known to use this bug, so remediation should be treated as urgent.

7.828% KEV ransomware
  • Microsoft Windows
mass>1 billion Windows devices (essentially all Windows installations at the time of disclosure; exploitation requires an existing local foothold)
CVE-2023-28205
Use-After-Free in Apple WebKit (iOS, iPadOS, macOS, Safari) Enables Code Execution

CVE-2023-28205 is a use-after-free flaw (CWE-416) in the WebKit engine shipped with Apple iOS, iPadOS, macOS, and the Safari browser, where memory is freed and then incorrectly reused while processing HTML. It is triggered when a device processes maliciously crafted web content, meaning simply loading an attacker-controlled page in Safari or any WebKit-based HTML renderer can trigger the bug. Successful exploitation allows the attacker to achieve code execution in the context of the WebKit process on the victim device. All users of iOS, iPadOS, macOS, and Safari are potentially affected, as are non-Apple products that rely on WebKit for HTML processing. The flaw is being actively exploited in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-04-10, with the required action to apply updates per vendor instructions — and EPSS assigns a 27.1% probability of exploitation within 30 days (98th percentile).

Do: Apply Apple's current security updates for iOS, iPadOS, macOS, and Safari as soon as possible, per the vendor instructions cited in the CISA KEV listing. Because this is a browser/HTML-engine flaw exploited in the wild, prioritize patching internet-facing and high-risk user fleets; users of non-Apple WebKit-based HTML parsers should check with their software vendors for updated WebKit components. Until patched, exercise caution with untrusted web content.

8.827% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
  • +3 more
mass≈ hundreds of millions of devices (WebKit is the HTML engine in every iOS, iPadOS, and macOS install and in Safari)
CVE-2023-28206
Out-of-Bounds Write in Apple IOSurfaceAccelerator Allows Kernel-Level Code Execution

Apple's IOSurfaceAccelerator component in iOS, iPadOS, and macOS contains an out-of-bounds write flaw (CWE-787). The bug is triggered by an application running locally on the device, which can corrupt memory in the component during a write past a buffer boundary. A successful exploit allows the app to execute arbitrary code with kernel privileges, giving it full control of the device beyond the normal app sandbox. Any user of an Apple iOS, iPadOS, or macOS device running an affected, unpatched version is exposed. The flaw was added to CISA KEV on 2023-04-10, confirming known in-the-wild exploitation; ransomware use is unknown, no public PoC is available, and EPSS assigns a 24.5% probability of exploitation within 30 days (98th percentile).

Do: Update all iPhones, iPads, and Macs to the latest iOS/iPadOS/macOS versions available as of April 2023, per CISA's required action and Apple's security advisories. Use MDM or patch-reporting tooling to inventory endpoints and confirm no devices remain on pre-patch builds. Because exploitation is confirmed in the wild and any local app can act as the trigger, patching is the primary mitigation and there is no dependable configuration workaround.

8.623% KEV
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
masshundreds of millions of devices (Apple's active iPhone/iPad/Mac installed base exceeds 1 billion)
CVE-2023-28252
Heap Overflow in Microsoft Windows CLFS Driver Enables Local Privilege Escalation

CVE-2023-28252 is a heap-based buffer overflow (CWE-122) in the Microsoft Windows Common Log File System (CLFS) driver that allows privilege escalation. The flaw is triggered when the kernel's CLFS driver processes malformed or maliciously crafted log file data, corrupting heap memory; an attacker who can already run code on a target system (e.g., a low-privileged user or an attacker chained with another flaw such as a remote code execution bug) can leverage it to gain SYSTEM-level privileges. Because the CLFS driver ships with supported Windows client and server releases, essentially the entire Windows installed base is potentially exposed. The vulnerability is being actively exploited: CISA added it to the KEV catalog on 2023-04-11 with known ransomware use, and EPSS estimates a 49.0% probability of exploitation within 30 days (99th percentile). It was addressed in Microsoft's April 2023 security updates, and the required remediation action is to apply the vendor updates.

Do: Apply Microsoft's April 2023 (or later) cumulative security updates to all Windows clients and servers per vendor instructions, prioritizing high-value and domain infrastructure systems given the known ransomware use; there is no public PoC or known workaround, so patching is the primary mitigation. Note that this is a local elevation-of-privilege flaw, so also hunt for prior low-privilege access or exploitation chains on hosts, and confirm remediation by checking installed update levels across the estate.

7.849% KEV ransomware PoC
  • Microsoft Windows Wide range of supported Windows client and server releases (CISA lists 'Microsoft Windows'); exact affected builds are enumerated in Microsoft's April 2023 secu
masshundreds of millions of Windows devices (the CLFS driver is present across essentially all modern Windows 10/11 and Windows Server installations)
Full article902 words · extracted from therecord.media · click to collapse

The Cybersecurity and Infrastructure Security Agency added three bugs to its catalog of known exploited vulnerabilities this week, highlighting issues with popular products from Microsoft and Apple.

On Monday, CISA added two Apple vulnerabilities to its list, giving federal civilian agencies until May 1 to patch the issues.

Apple released patches for the bugs — CVE-2023-28205 and CVE-2023-28206 — on Friday after they were reported by Clément Lecigne of Google's Threat Analysis Group and Donncha Ó Cearbhaill of Amnesty International’s Security Lab.

The two organizations released a report last week about a spyware vendor selling exploits for Google, Apple and Samsung devices to governments.

Both of the vulnerabilities affect macOS, iPhone 8 and later, all models of the iPad Pro, iPad Air 3rd generation and later, iPad 5th generation and later, and iPad mini 5th generation and later.

In its advisory, Apple said it was “aware of a report that this issue may have been actively exploited.”

Mobile security company Zimperium’s Krishna Vishnubhotla explained that CVE-2023-28206 revolves around the OSurfaceAccelerator framework – a tool used by many iOS and macOS applications that need high-performance graphics processing, such as video editors, games, and augmented reality applications.

“If IOSurfaceAccelerator is exploited, it could potentially allow an attacker to gain unauthorized access to sensitive data or execute malicious code on an iOS device,” Vishnubhotla said.

“Since IOSurfaceAccelerator provides low-level access to graphics hardware resources, exploiting a vulnerability in the framework could give an attacker the ability to manipulate graphics resources, intercept or modify data, or even cause the device to crash.”

Vishnubhotla noted that the exposure of the vulnerability could go beyond macOS due to how many iOS apps rely on the feature.

The other bug, CVE-2023-28205, affects WebKit, a core software component of macOS and iOS that is responsible for rendering web pages and executing JavaScript code in the Safari web browser and other applications.

Like IOSurfaceAccelerator, Vishnubhotla said WebKit is used widely across mac and iOS, posing significant risk to users because exploitation would allow attackers to take control of the device's web browsing capabilities and steal sensitive user data, such as login credentials and other personal information.

Several other experts noted that because the bugs were reported together by the same researchers, it is likely they were used in conjunction with one another.

Microsoft’s bug

On Tuesday, CISA added Microsoft’s CVE-2023-28252 to its list, ordering civilian agencies to patch the bug by May 2.

The bug, which was among the more than 100 vulnerabilities included in Microsoft’s Patch Tuesday release for April, caused alarm among security researchers who called it the most serious unveiled on Tuesday.

Dustin Childs of Trend Micro’s Zero Day Initiative said the issue affects the Windows Common Log File System Driver (CLFS), which effectively allows users to record a series of steps required for some actions so that they can be either reproduced accurately in the future or undone.

“This is the one bug under active attack this month, and if it seems familiar, that’s because there was a similar 0-day patched in the same component just two months ago. To me, that implies the original fix was insufficient and attackers have found a method to bypass that fix,” Childs said.

“As in February, there is no information about how widespread these attacks may be. This type of exploit is typically paired with a code execution bug to spread malware or ransomware. Definitely test and deploy this patch quickly.”

Cloud security company Automox’s Gina Geisel said the zero-day affects versions of Windows 10, Windows 11, as well as Windows Server 2008, 2012, 2016, 2019, and 2022.

Geisel explained that the vulnerability has a low level of complexity and requires relatively few privileges to exploit. The bug “leverages existing system access to actively exploit a device and is a result of how the CLFS driver interacts with objects in memory on a system,” she said.

Researchers from Kaspersky said the vulnerability was exploited by hackers attempting to spread the Nokoyawa ransomware. The controversial security company said they found the vulnerability in February after it was used in attacks on several small and medium-sized businesses in the Middle East, Asia and North America.

Trend Micro researchers said Nokoyawa uses many tactics similar to the now defunct Hive ransomware group and Play ransomware actors, who recently attacked the city of Oakland.

Kaspersky researchers said they previously saw versions of Nokoyawa that resembled variants of the JSWorm ransomware but the version used in the exploitation of CVE-2023-28252 was distinct from the others in terms of its codebase.

The attackers used the vulnerability to elevate their system privileges and steal credentials from a database.

Bharat Jogi, director of vulnerability and threat research at Qualys, told The Record that CVE-2023-28252 allows an attacker to gain the highest system-level privileges on the vulnerable system.

Jogi added that this is not the first time that this specific driver has been an attractive target for threat actors. In September 2022, Microsoft fixed another vulnerability – CVE-2022-37969, which was known to be exploited in the wild – which affected the same component.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-microsoft-apple-bugs-to-exploited-list