Ransomware gangs are abusing a zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-38646 | RCE in Microsoft Office Access Connectivity Engine exploited by ransomware CVE-2021-38646 is a remote code execution vulnerability in the Microsoft Office Access Connectivity Engine (ACE), the database engine bundled with Office that opens and processes database files. It is triggered locally (CVSS:3.1 AV:L, user interaction required, no privileges needed) when a user is persuaded to open a specially crafted file — typically a database or Office file that invokes the ACE engine — on an affected Office installation. Successful exploitation lets an attacker execute arbitrary code in the context of the signed-in user, providing initial access that has been chained into ransomware deployments, which CISA confirms as known ransomware use. Users of Microsoft Office 2016, Office 2019, and Microsoft 365 Apps are affected according to CISA's listing. The flaw is known to be exploited in the wild — it was added to CISA's KEV on 2022-03-28 — while no public proof-of-concept is available, and EPSS assigns an 8% probability of exploitation within 30 days (94th percentile). Do: Apply Microsoft's security updates for CVE-2021-38646 to Microsoft 365 Apps, Office 2016, and Office 2019 per vendor instructions, and verify remediated builds across your fleet, prioritizing endpoints where users open untrusted files or where Microsoft Access is installed. Until patched, caution users against opening untrusted database/Office files, since exploitation requires user interaction. There is no public PoC, but confirmed ransomware use and the CISA KEV listing make this a priority patch within KEV remediation timelines. | 7.8 | 8% | KEV ransomware |
| mass≈ hundreds of millions of Office installations (Office 2016/2019 and Microsoft 365 Apps are among the most widely deployed Office editions; the currently… | |
| CVE-2021-42258 | Unauthenticated SQL Injection RCE in BQE BillQuick Web Suite CVE-2021-42258 is an unauthenticated SQL injection flaw (CWE-89) in BQE BillQuick Web Suite 2018 through 2021, fixed in version 22.0.9.1, that can be triggered through user-supplied input such as the txtID (username) parameter of the web interface. Because attacker-controlled input reaches the backend Microsoft SQL Server, an unauthenticated attacker with network access to the web suite can inject SQL and abuse xp_cmdshell to execute arbitrary code on the database server under the MSSQLSERVER$ account. This yields full unauthenticated remote code execution, and in observed intrusions it was used to deploy ransomware. Any organization running an affected BillQuick Web Suite release is affected, particularly those exposing the billing portal directly to the internet. The flaw is actively exploited in the wild (added to CISA KEV on 2021-11-03 with known ransomware use) and carries a high EPSS score of 74.4%, making urgent patching advisable. Do: Upgrade BillQuick Web Suite to version 22.0.9.1 or later per BQE's instructions, as required by the CISA KEV entry. Until patched, restrict internet-facing access to the Web Suite server and review logs for SQL injection attempts against the username (txtID) parameter, unexpected xp_cmdshell usage, or commands running as MSSQLSERVER$; the referenced Huntress advisory includes indicators of compromise for the October 2021 ransomware campaign. | 9.8 | 74% | KEV ransomware PoC |
| nichelikely low thousands of installations worldwide, with only hundreds of internet-exposed instances |
Full article389 words · extracted from therecord.media · click to collapse
Multiple ransomware gangs have weaponized and are abusing a zero-day in EntroLink VPN appliances after an exploit was released on an underground cybercrime forum at the start of September 2021. The zero-day is believed to impact EntroLink PPX-AnyLink devices, popular with South Korean companies, and used as user authentication gateways and VPNs to allow employees remote access to company networks and internal resources. An exploit targeting these devices was released last month, on September 13, 2021. The exploit, initially sold on another forum for $50,000, was released for free by the administrator of a newly-launched cybercrime forum in what appears to be a promotional stunt meant to raise the site's profile among other cybercrime groups. According to the forum post, the exploit is still unpatched, exploits a network protocol, and grants remote code execution with root-level access to PPX-AnyLink devices. The post also describes the bug as an input validation issue and that the exploit is self-contained and only needs a few seconds to compromise a device. Since the exploit's release, affiliates for the BlackMatter and LockBit ransomware operations have been linked to possible intrusions where this exploit might have been used, according to a researcher who is currently tracking and investigating ransomware attacks. EntroLink, the South Korean networking vendor, was notified of the exploit's release by the security researcher. The company did not engage with the researcher, and it also did not return a request for comment sent via email by The Record last week. During a phone call, a company spokesperson also refused to connect this reporter to a company representative responsible for product security. The EntroLink PPX-AnyLink exploit now becomes the 54th zero-day vulnerability that ransomware gangs are currently known to abuse, according to a tracker managed by security researchers Allan Liska and Pancak3. Updates include $MSFT Office CVE-2021-38646 and @billquick’s web suite CVE-2021-42258.
Also, I feel enough time has passed since continuously trying to reach the company with no response to uncensor the EntroLink PPX-AnyLink 0day item.
Cc: @uuallan pic.twitter.com/l6vetBONVu
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/ransomware-gangs-are-abusing-a-zero-day-in-entrolink-vpn-appliances