ZeroHour
The Recordpublished ()ingested

CISA plans to share more information on ransomware actors in its exploited vulnerability alerts

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-20109
Out-of-Bounds Write in Cisco IOS/IOS XE GET VPN Enables Authenticated RCE

CVE-2023-20109 is an out-of-bounds write (CWE-787) in the Group Encrypted Transport VPN (GET VPN) feature of Cisco IOS and Cisco IOS XE, caused by insufficient validation of Group Domain of Interpretation (GDOI) and G-IKEv2 protocol attributes. An authenticated, remote attacker with administrative control of either a GET VPN group member or key server can trigger the flaw by compromising the installed key server or by modifying a group member's configuration to point at an attacker-controlled key server, then sending crafted GDOI/G-IKEv2 attributes. A successful exploit allows the attacker to execute arbitrary code and gain full control of the device, or to crash/reload it, causing a denial-of-service condition. Only organizations running Cisco IOS/IOS XE devices with the GET VPN feature configured (as group members or key servers) are affected; CVSS 3.1 rates it 6.6 (medium) because exploitation requires high privileges and high attack complexity. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-10, indicating confirmed in-the-wild exploitation, while EPSS estimates a 2.3% probability of exploitation in the next 30 days and no public PoC is known.

Do: Upgrade affected devices to a fixed release identified in Cisco's security advisory, and inventory GET VPN deployments with 'show crypto gdoi' to identify group members and their key servers. Because exploitation requires a compromised or attacker-controlled key server, harden and restrict access to key servers, verify that group member configurations point only to legitimate key servers, and rotate GET VPN keys if compromise is suspected. Per the CISA KEV required action, apply vendor mitigations promptly or discontinue use where mitigations are unavailable.

6.62% KEV
  • Cisco IOS
  • Cisco IOS XE
largeon the order of tens of thousands of devices (GET VPN group members/key servers within Cisco's multi-million-unit IOS/IOS XE installed base; not typically…
CVE-2023-21608
Actively Exploited Use-After-Free RCE in Adobe Acrobat and Reader

Adobe Acrobat and Reader contain a use-after-free memory-corruption flaw (CWE-416) that allows arbitrary code execution in the context of the current user. The bug is local and requires user interaction: a victim must open a malicious file, typically a crafted PDF delivered by email or web download, for the attacker's code to run. Affected builds are 22.003.20282 and earlier, 22.003.20281 and earlier, and 20.005.30418 and earlier, and CISA's affected list spans both Acrobat and Reader. Adobe shipped fixes in January 2023, but the flaw remained under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-10 and EPSS gives it a 61.5% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known and any ransomware use is unconfirmed, but in-the-wild exploitation makes urgent patching necessary.

Do: Update every Acrobat and Reader installation to a build later than 22.003.20282, 22.003.20281, and 20.005.30418 per Adobe's security advisory, using the built-in updater or enterprise deployment packages and prioritizing endpoints that handle untrusted PDFs; CISA's KEV required action is to apply the vendor's mitigations or discontinue use of the product. Until patched, query your software inventory for installs at or below the affected versions and remind users that opening a malicious PDF from an untrusted source can execute attacker code at their privilege level.

7.861% KEV
  • Adobe Acrobat DC 22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier
  • Adobe Acrobat Reader DC 22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier
  • Adobe Acrobat 22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier
  • +1 more
masshundreds of millions of users/installations plausibly affected (dominant desktop PDF viewer; cumulative install counts commonly cited at over a billion)
CVE-2023-36563
Information Disclosure in Microsoft WordPad Exploited in the Wild

CVE-2023-36563 is an information disclosure flaw (CWE-20, improper input validation) in Microsoft WordPad, the lightweight word processor bundled with supported Windows releases; Microsoft has published limited technical detail and CISA describes the flaw as unspecified. An attacker triggers it by persuading a user to open a specially crafted document in WordPad, where improper handling of the document content (including URL/remote-resource references) causes information to be disclosed to the attacker. A successful attacker gains access to sensitive information from the affected system rather than code execution, and exploitation requires user interaction with a malicious file. Any Windows installation with WordPad is potentially affected, making the population essentially the entire supported Windows installed base. Exploitation is confirmed: CISA added the flaw to its KEV catalog on 2023-10-10 and its advisory notes no public proof-of-concept is known and ransomware use is unknown; EPSS is 20.7% (97th percentile), indicating elevated near-term exploitation likelihood.

Do: Apply Microsoft's October 10, 2023 Windows security updates, which include the WordPad fix, prioritizing systems where users open untrusted documents; until patched, follow Microsoft's mitigation guidance to disable the WordPad URL protocol handler via the published registry change. Note that WordPad has since been removed entirely in Windows 11 24H2, so those systems are no longer exposed; per CISA, any ransomware linkage is unknown.

5.521% KEV
  • Microsoft WordPad (word processor bundled with supported Windows releases)
mass≈1.4 billion Windows devices (WordPad ships by default with Windows)
CVE-2023-41763
Unauthenticated SSRF/Elevation-of-Privilege Flaw in Microsoft Skype for Business Server

CVE-2023-41763 is a vulnerability in Microsoft Skype for Business Server that Microsoft classifies as an elevation-of-privilege issue, with the underlying weakness mapped to CWE-918 (server-side request forgery). The CVSS vector (AV:N/AC:L/PR:N/UI:N, scope unchanged) shows it can be triggered remotely by an unauthenticated attacker sending crafted network requests, and the impact is confined to confidentiality, meaning an attacker can potentially obtain limited sensitive information from the affected server. Any organization running on-premises Skype for Business Server is potentially affected; the source data does not specify the affected version ranges. The flaw was patched in Microsoft's October 2023 Patch Tuesday, where it was fixed alongside the actively exploited WordPad zero-day (CVE-2023-36563), and it was added to CISA's Known Exploited Vulnerabilities catalog on October 10, 2023, carrying a 90.4% EPSS probability of exploitation within 30 days.

Do: Apply Microsoft's October 2023 Patch Tuesday security updates for Skype for Business Server immediately; CISA's KEV required action is to apply vendor mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. No public proof-of-concept is known, but exploitation is confirmed in the wild, so prioritize internet-facing deployments and review Skype for Business web-service logs for anomalous requests. Check which Skype for Business Server versions your organization runs against Microsoft's advisory to confirm patch applicability.

5.390% KEV
  • Microsoft Skype for Business Server
massplausibly >1 million users across tens of thousands of on-premises server deployments (estimate)
CVE-2023-44487
Rapid Reset Denial-of-Service in HTTP/2 (CWE-400 Resource Exhaustion)

CVE-2023-44487 is a flaw in the HTTP/2 protocol's stream handling (CWE-400, uncontrolled resource consumption) in which a client opens a large number of streams and immediately cancels them with RST_STREAM frames, forcing the server to repeatedly allocate and tear down per-stream state. When this 'rapid reset' pattern is driven at high volume from many sources, it exhausts server CPU and memory, producing a distributed denial-of-service; Google, Cloudflare and AWS all reported record-scale attacks using this technique. The only impact is availability (denial of service), not code execution or data exposure, but any system speaking HTTP/2 is in scope, including web servers, load balancers, API gateways and CDN edges, and client-side implementations are also affected in a reverse-direction variant. Because the weakness is in the protocol specification itself (attributed to IETF HTTP/2), virtually every deployment with HTTP/2 enabled is affected until vendors ship mitigations or patches. Exploitation is confirmed in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-10, and EPSS assigns a 100% probability of exploitation within 30 days.

Do: Apply mitigations per vendor instructions as required by CISA KEV/BOD 22-01 guidance — most major web server, load balancer, and CDN vendors have shipped patches or tuning knobs, so check and update each HTTP/2-facing component in your estate. Where patching is not yet possible, limit the number of concurrent HTTP/2 streams per connection, rate-limit new stream creation and inbound HTTP/2 connections, or disable HTTP/2 on internet-exposed servers. Confirm with your CDN or cloud provider that rapid-reset DDoS mitigations are in place at the edge.

7.5100% KEV
  • IETF HTTP/2 All HTTP/2 implementations (protocol-level flaw; CISA lists IETF HTTP/2 with no specific version range)
massmillions of servers and network edges (HTTP/2 is negotiated on a large share of HTTPS-capable hosts in public internet scans)
Full article1,030 words · extracted from therecord.media · click to collapse

The U.S.’s top cybersecurity agency said it plans to add a section dedicated to ransomware gangs to its list of vulnerabilities being exploited by hackers.

Cybersecurity and Infrastructure Security Agency (CISA) officials said on Thursday that all organizations will now have access to information about which vulnerabilities are commonly associated with ransomware attacks through its known exploited vulnerabilities (KEV) catalog.

This information was previously only offered through CISA’s Ransomware Vulnerability Warning Pilot Program (RVWP) – an effort that began earlier this year where organizations can enroll and receive private warnings from CISA about vulnerabilities commonly associated with known ransomware exploitation.

Through the program, CISA identifies organizations with internet-accessible vulnerabilities commonly associated with known ransomware actors by using existing services, data sources, technologies, and authorities.

CISA associate director of vulnerability management Sandra Radesky and lead operations risk advisor Gabriel Davis said they would now be adding a column in the KEV catalog titled “known to be used in ransomware campaigns.”

“Furthermore, CISA has developed a second new RVWP resource that serves as a companion list of misconfigurations and weaknesses known to be used in ransomware campaigns,” the two said. “This list will guide organizations to quickly identify services known to be used by ransomware threat actors so they can implement mitigations or compensating controls.”

CISA added the 1,000th vulnerability to the KEV list three weeks ago and it has quickly become a go-to repository for the most concerning vulnerabilities being used by a wide range of hackers.

So far, the RVWP has notified organizations of more than 800 vulnerable systems that have internet-accessible vulnerabilities commonly associated with known ransomware campaigns. They noted that “all critical infrastructure sectors have benefited from the RVWP to include Energy, Healthcare and Public Health, Water and Wastewater Systems sectors, and Education Facilities subsector specifically.”

The RVWP was created as part of the rollout of the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) of 2022 – the rules of which are slated to be announced some time next year. CISA director Jen Easterly said the new incident reporting rules would allow government officials to get a better handle on how their actions are affecting the number of ransomware attacks facing U.S. organizations.


Five Patch Tuesday additions to KEV list

In addition to the ransomware announcement, CISA added five serious issues to its list of vulnerabilities being exploited.

On the heels of the latest Patch Tuesday vulnerability releases from the world’s leading technology firms, CISA picked out five specific issues, giving federal civilian agencies until the last day of October to patch them.

The issues being exploited include:

  • Adobe Acrobat’s CVE-2023-21608
  • Cisco’s CVE-2023-20109
  • Microsoft Skype’s CVE-2023-41763
  • Microsoft WordPad’s CVE-2023-36563
  • CVE-2023-44487 affecting HTTP/2

The HTTP/2 issue was announced earlier this week by Google, Amazon and Cloudflare, each of which said the vulnerability facilitated some of the largest distributed denial-of-service (DDoS) attacks on record.

Adobe Acrobat’s CVE-2023-21608 was patched in January after being reported by Trend Micro’s Zero Day Initiative.

The Cisco vulnerability caused alarm last week after the company warned that hackers are using it to attack their VPN products. It allows a hacker to take actions on an affected device or cause the device to crash, but experts noted that a hacker would already need to be deep in an organization’s systems to use it.

Both of the Microsoft vulnerabilities — CVE-2023-41763 and CVE-2023-36563 — were among the 105 vulnerabilities announced by the tech giant on Tuesday.

Rapid7’s lead software engineer Adam Barnett noted that public exploit code exists for CVE-2023-41763, which affects Skype and could lead to the disclosure of IP addresses and/or port numbers.

Barnett added that while Microsoft does not specify what the scope of the disclosure might be, it will “presumably be limited to whatever the Skype for Business server can see; as always, appropriate network segmentation will pay defense-in-depth dividends.”

Action1 president Mike Walters explained that the bug affects Skype for Business versions 2015 to 2019 and requires no user privileges or interaction.

Experts from Trend Micro’s Zero Day Initiative told Recorded Future News that the bug “acts more like an information disclosure than a privilege escalation.”

“An attacker could make a malicious call to an affected Skype for Business server that results in the server parsing an HTTP request to an arbitrary address,” they said. “This could result in disclosing information, which could include sensitive information that provides access to internal networks.”

For CVE-2023-36563 — which affects Microsoft WordPad — the concerns revolve around how the vulnerability would allow hackers to access NTLM hashes. Immersive Labs cybersecurity engineer Nikolas Cemerikic explained that NTLM hashes are a fixed-length string of characters created from a user's password using a one-way mathematical algorithm.

“They are used for authentication in Windows operating systems, where the hash of the password is compared during login attempts rather than the real password being saved on the machine. This is for increased security,” he said.

The vulnerability affects Windows 10 and later as well as Windows Server 2008 and later.

Several other experts said the issue can be exploited in two ways: either through a specially crafted application designed for the vulnerability or through a malicious WordPad file that would typically come as an attachment to a phishing email.

“It should be noted, however, that simply obtaining user password hashes would not inherently provide the attacker with knowledge of the user password itself,” Cemerikic said.

“The attacker would need to take these hashes and then perform an offline crack against the hash, such as a dictionary attack or brute-force attack.”

Rapid7’s Barnett noted that Microsoft announced last month that WordPad is no longer being updated and will be removed in a future version of Windows, although no specific timeline has yet been given. Microsoft recommends Word as a replacement for WordPad.

Walters said a proof of concept demonstrating its impact is available.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-adds-ransomware-information-to-exploited-vulnerability-list