ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz1

Microsoft patches three exploited zero-days (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823)

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-21715
+1 in the same advisory: …21716
Actively Exploited Security Feature Bypass in Microsoft Office Publisher

Microsoft Office Publisher contains a security feature bypass (CWE-863, incorrect authorization) in which a specially crafted Publisher document can circumvent an Office security mechanism, widely reported as a bypass of the Mark-of-the-Web/Protected View protections applied to files from untrusted sources. The flaw is triggered locally when a user opens the malicious document, consistent with the CVSS vector (local attack, low privileges, user interaction required). Successful bypassing yields high impact on the victim system, with high ratings for confidentiality, integrity, and availability. Anyone running Microsoft 365 Apps or Microsoft Office editions that include Publisher is affected, and no specific affected version numbers are published in this data beyond the requirement to apply the February 2023 fixes. The vulnerability is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2023-02-14 and was patched as one of three exploited zero-days in Microsoft's February 2023 Patch Tuesday.

Do: Apply Microsoft's February 2023 Patch Tuesday security updates to Microsoft 365 Apps and any Office edition that includes Publisher, per vendor instructions as required by the CISA KEV entry; because affected builds differ by update channel, confirm the installed build after updating rather than relying on the date alone. Until patched, exercise caution with Publisher documents from untrusted sources. No public PoC or workaround is documented, so patching is the primary mitigation.

7.3
group max
12% KEV
  • Microsoft 365 Apps
  • Microsoft Office (Publisher)
mass≈hundreds of millions of Office/365 installations worldwide
CVE-2023-23376
+1 in the same advisory: …21823
Out-of-Bounds Write Privilege Escalation in Microsoft Windows CLFS Driver

CVE-2023-23376 is a heap-based buffer overflow (out-of-bounds write, CWE-122/CWE-787) in the Windows Common Log File System (CLFS) kernel driver. A local attacker with low privileges can trigger the flaw when the driver mishandles CLFS log-file data, with no user interaction required. Successful exploitation elevates the attacker from a low-privileged user to SYSTEM/kernel-level privileges, which is why ransomware operators chain it with other bugs after gaining an initial foothold. All supported Windows 10 (1507, 1607, 1809, 20H2, 21H2, 22H2), Windows 11 (21H2, 22H2), and Windows Server 2008, 2012, 2016, and 2019 releases as of February 2023 are affected. The flaw is actively exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on February 14, 2023 with known ransomware use, Microsoft shipped the fix in the February 2023 Patch Tuesday release, and EPSS estimates roughly an 11% probability of exploitation within the next 30 days (96th percentile).

Do: Apply the Microsoft security updates released on February 14, 2023 (February Patch Tuesday) to every Windows 10, Windows 11, and Windows Server system in the affected version list, prioritizing servers and endpoints exposed to ransomware-prone environments. Verify patch status via update history or vulnerability scanning, since exploitation requires only local low-privileged access and there is no substitution for patching. Given confirmed ransomware chaining, also hunt for signs of post-compromise privilege escalation on hosts that were unpatched before mid-February 2023.

7.811% KEV ransomware
  • Microsoft Windows 10 1507 (all builds prior to the February 2023 security updates)
  • Microsoft Windows 10 1607 (all builds prior to the February 2023 security updates)
  • Microsoft Windows 10 1809 (all builds prior to the February 2023 security updates)
  • +9 more
mass~1 billion+ Windows devices (the CLFS driver ships in every listed Windows 10/11 client and Windows Server 2008-2019 release)
Full article445 words · extracted from helpnetsecurity.com · click to collapse

The February 2023 Patch Tuesday is upon us, with Microsoft releasing patches for 75 CVE-numbered vulnerabilities, including three actively exploited zero-day flaws (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823).

CVE-2023-21715 CVE-2023-23376 CVE-2023-21823

The three zero-days (CVE-2023-21715, CVE-2023-23376, CVE-2023-21823)

CVE-2023-21715 a vulnerability that allows attackers to bypass a Microsoft Publisher security feature: Office macro policies used to block untrusted or malicious files.

“The attack itself is carried out locally by a user with authentication to the targeted system. An authenticated attacker could exploit the vulnerability by convincing a victim, through social engineering, to download and open a specially crafted file from a website which could lead to a local attack on the victim computer,” Microsoft explains.

Due to the local attack vector and the fact that elevated privileges and user interaction is required to exploit the flaw, the vulnerability is rated as Important. Still, any flaw that allows attackers to misuse macros in an Office document and not trigger a block should be patched quickly, whether it’s currently exploited in highly targeted attacks or more widely. Attackers have been slowly abandoning the use of macros as Microsoft started blocking them by default in Office documents downloaded from the internet, but vulnerabilities like this one obviously allow them to still be a good option.

CVE-2023-23376 is a vulnerability in the Windows Common Log File System that could allow attackers to achieve SYSTEM privileges on a target host.

“This is likely being chained with an RCE bug to spread malware or ransomware. Considering this was discovered by Microsoft’s Threat Intelligence Center (aka MSTIC), it could mean it was used by advanced threat actors. Either way, make sure you test and roll these fixes quickly,” says Trend Micro’s Dustin Childs.

CVE-2023-21823 is a vulnerability in Windows Graphics Component and could lead to remote code execution and a total takeover of a vulnerable system.

“The Microsoft Store will automatically update affected customers,” Microsoft says. Those who have disabled automatic updates should get them via the Microsoft Store (go to: Library > Get updates > Update all).

Unfortunately, Microsoft did not share any details about the attacks in which these vulnerabilities are being exploited.

Other vulnerabilities of note

Childs advises admins to patch quickly CVE-2023-21716, a critical RCE in Microsoft Word that can be exploited by the system simply opening the Preview Pane.

“An unauthenticated attacker could send a malicious e-mail containing an RTF payload that would allow them to gain access to execute commands within the application used to open the malicious file,” Microsoft shared.

A few Microsoft Exchange Server RCE bugs require the attacker to authenticate before exploitation, but given attackers’ predilection for targeting Exchange servers, admins should also prioritize those patches.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/02/14/microsoft-patches-three-exploited-zero-days-cve-2023-21715-cve-2023-23376-cve-2023-21823/