CISA warns of attacks using Microsoft Word, Adobe bugs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-26369 | Out-of-Bounds Write RCE in Adobe Acrobat and Reader via Malicious PDFs Adobe Acrobat and Reader contain an out-of-bounds write (CWE-787) memory-corruption vulnerability in the listed versions. The flaw is triggered by user interaction: a victim must open a malicious file (e.g., a crafted PDF) for exploitation to occur. Successful exploitation gives the attacker arbitrary code execution in the context of the current user. Anyone running affected versions of Acrobat, Acrobat DC, Acrobat Reader, or Acrobat Reader DC is exposed, and because Reader is the dominant PDF viewer, that spans effectively all unpatched desktops that open PDFs. The bug was exploited as a zero-day before being patched, was added to CISA's KEV catalog on 2023-09-14 with CISA warning of active attacks, and EPSS assigns a roughly 7% probability of exploitation in the next 30 days (94th percentile). Do: Upgrade all Acrobat and Reader installations to builds newer than 23.003.20284 and 20.005.30516/20.005.30514 per Adobe's security bulletin, as required by the CISA KEV listing (added 2023-09-14) which mandates applying vendor mitigations or discontinuing use. Until patched, caution users against opening PDFs from untrusted sources and consider blocking automatic PDF opening in browsers or email. Because the flaw was exploited as a zero-day, hunt for signs of compromise on endpoints that were running the affected versions. | 7.8 | 7% | KEV |
| masshundreds of millions of users (Acrobat/Reader is the world's dominant PDF viewer; effectively every unpatched desktop that opens PDFs) | |
| CVE-2023-36761 | Information Disclosure Flaw in Microsoft Word Actively Exploited (CVE-2023-36761) CVE-2023-36761 is an information disclosure vulnerability in Microsoft Word caused by improper input validation (CWE-20). It is triggered when a user opens a specially crafted document, requiring user interaction but no authentication or special privileges, per the CVSS vector (AV:N/PR:N/UI:R). A successful attacker gains access to sensitive information from the affected system, with public reporting indicating the flaw can leak authentication material such as NTLM credentials. Anyone running affected versions of Word, including Word within Microsoft 365 Apps, Microsoft Office, and Office LTSC, is exposed, and the flaw was fixed in Microsoft's September 2023 Patch Tuesday updates. The vulnerability was exploited as a zero-day before patching: CISA added it to the Known Exploited Vulnerabilities catalog on September 12, 2023, and its EPSS score of 19.0% (97th percentile) signals elevated near-term exploitation risk. Do: Apply Microsoft's September 2023 security updates for Microsoft 365 Apps, Office, Office LTSC, and Word immediately, per vendor instructions and CISA KEV requirements. Until patched, treat unsolicited documents as untrusted and consider restricting outbound SMB/NTLM traffic to limit credential leakage. Given confirmed in-the-wild exploitation and no known public PoC, prioritize this KEV remediation and verify patch deployment across endpoints. | 6.5 | 20% | KEV |
| masshundreds of millions of users/devices (Word ships with Microsoft 365 and Office across enterprise and consumer fleets) | |
| CVE-2023-36802 | Use-After-Free Privilege Escalation in Microsoft Streaming Service Proxy CVE-2023-36802 is a use-after-free vulnerability (CWE-416) in the Microsoft Streaming Service Proxy, a component that ships with Windows, that allows an attacker to escalate privileges. It is triggered by a local attacker who can already execute code on a target machine and interacts with the streaming service proxy component in a way that mishandles freed memory. Successful exploitation typically yields elevated (SYSTEM/kernel-level) privileges, giving an attacker full control of the host and making it a common link in chained attack sequences alongside other exploits. Any Windows system carrying the affected component is potentially affected, which in practice means a very broad installed base of Windows client and server machines. The flaw is being actively exploited — CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-12 — though no public proof-of-concept is known and Microsoft's severity scoring was not yet available in the source data; EPSS estimates a high 27.5% chance of exploitation within 30 days (98th percentile). Do: Apply Microsoft's security updates for this vulnerability via the vendor's mitigation instructions (Windows Update/patch channel), as required by the CISA KEV listing, prioritizing internet-reachable and multi-user Windows hosts. Since exploitation requires local access, limit who can run code on Windows systems and review endpoints for signs of local privilege escalation activity; confirm the patch landed by checking installed updates against Microsoft's advisory. | 7.8 | 28% | KEV |
| mass≈hundreds of millions of Windows devices (the Streaming Service Proxy component ships with Windows, so exposure broadly mirrors the Windows install base) |
Full article627 words · extracted from therecord.media · click to collapse
The federal government is urging IT administrators to fix several vulnerabilities disclosed in Microsoft’s latest batch of Patch Tuesday bugs, including two critical issues that are actively being exploited by hackers. Overall, Microsoft disclosed 59 bugs, including zero-day vulnerabilities related to Microsoft Word (CVE-2023-36761) and Microsoft Streaming Service Proxy (CVE-2023-36802). The Cybersecurity and Infrastructure Security Agency (CISA) confirmed that both bugs are being used in attacks, adding them to the list of known exploited vulnerabilities shortly after they were disclosed on Tuesday and giving federal civilian agencies until October 3 to patch them. Immersive Labs’ lead cybersecurity engineer, Natalie Silva, said CVE-2023-36761 – which carries a CVSS score of 6.2 out of 10 – relates to an issue with Microsoft Word that poses a high risk to confidentiality. It could be exploited if a malicious document or file is opened or previewed within the Preview Pane – a feature in Windows File Explorer that allows you to see a preview of the file's contents in the view's reading pane. “Attackers could specially craft documents or files that contain malicious code or exploit vulnerabilities in the software rendering engine used by the Preview Pane,” Silva said. “When a user previews or opens such a document in the Preview Pane, malicious code can be executed, leading to potential compromise of the system.” The exploitation of the bug could lead to the exposure of tools used for authentication in Windows environments. Attackers could gain unauthorized access to sensitive information or systems via a relay attack or cracked offline to recover user credentials, Silva added. Automox product manager Tom Bowyer said the authentication tools, called Net-NTLMv2 hashes, are “essentially digital keys to a user's credentials.” Gaining access to the keys would allow someone to impersonate a user and access sensitive data. “This sort of breach can lead to compromises in data integrity and security, opening the door for further exploits and even causing a cascading effect of system vulnerabilities,” Bowyer said. The other zero-day being exploited — CVE-2023-36802 — has a severity score of 7.8 out of 10 and affects Microsoft’s Streaming Service Proxy. Immersive Labs’ Nikolas Cemerkic explained that Microsoft Streaming Service Proxy is related to Microsoft Stream and is the successor to Office 365 Video. The application is built on top of the cloud-based Azure Media Services and allows playback at scale across any device on the network, Cemerkic said. “A vulnerability has been discovered within this service that would allow an attacker who has managed to compromise the target system the ability to gain Administrator privileges on that same machine,” he said. “Although an attacker would need to be on the machine with low-level privileges, no user interaction would be required for the attacker to elevate their privileges.” CISA also published a warning about CVE-2023-26369, a vulnerability affecting Adobe Acrobat and Reader. While the cybersecurity agency didn’t add the bug to its exploited list, it released a warning urging administrators to update their systems and install a patch. In an advisory, Adobe warned on Tuesday that the vulnerability “has been exploited in the wild in limited attacks targeting Adobe Acrobat and Reader.” The bug affects both Windows and Mac versions of Acrobat DC, Acrobat Reader DC, Acrobat 2020, and Acrobat Reader 2020. It is rated critical and carries a CVSS score of 7.8 out of 10. CISA also warned of other lower-severity bugs affecting Adobe Experience Manager and Adobe Connect.Adobe bug
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-adobe-bugs-cisa-kev-list