News: 1618343268

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

NSA helps out Microsoft with critical Exchange Server vulnerability disclosures in an April shower of patches

(2021/04/13)


Patch Tuesday April showers bring hours of patches as Microsoft delivers its Patch Tuesday fun-fest consisting of over a hundred CVEs, including four Exchange Server vulnerabilities reported to the company by the US National Security Agency (NSA).

Forty-four different products and services are affected, mainly having to do with Azure, Exchange Server, Office, Visual Studio Code, and Windows. Among the vulnerabilities, four have been publicly disclosed and a fifth is being actively exploited. Nineteen of the CVEs have been designated critical.

[1]

"This month’s release includes a number of critical vulnerabilities that we recommend you prioritize, including updates to protect against new vulnerabilities in on-premise Exchange Servers," Microsoft said in its [2]blog post .

"These new vulnerabilities were reported by a security partner through standard coordinated vulnerability disclosure and found internally by Microsoft. We have not seen the vulnerabilities used in attacks against our customers.

[3]

Clicking through Microsoft's coy links to [4]CVE-2021-28480 (9.8 severity), [5]CVE-2021-28481 (9.8 severity), [6]CVE-2021-28482 (8.8 severity), and [7]CVE-2021-28483 (9.0 severity), you'll find the unspecified security partner is the NSA.

SAP: It takes exploit devs about 72 hours to turn one of our security patches into a weapon against customers [8]READ MORE

Exchange Server 2013 [9]CU23 , Exchange Server 2016 [10]CU19 and [11]CU20 , and Exchange Server 2019 [12]CU8 and [13]CU9 are affected by this set of problems.

"NSA urges applying critical Microsoft patches released today, as exploitation of these #vulnerabilities could allow persistent access and control of enterprise networks," the signals intelligence agency [14]said via Twitter.

The NSA assist comes a month after Microsoft [15]fixed four Exchange Server zero-day flaws , claiming that a China-based hacking group, dubbed "Hafnium," exploited the vulnerabilities to steal data from US defense contractors, law firms, and medical researchers.

Pointing to the two 9.8 severity Exchange flaws, Dustin Childs, director of communications for the Zero Day Initiative, in a [16]blog post said, "Both code execution bugs are unauthenticated and require no user interaction. Since the attack vector is listed as 'Network,' it is likely these bugs are wormable – at least between Exchange servers."

2 of these are logic pre-auth RCEs btw, so if you don't patch fast you're going to have a bad time. [17]https://t.co/99tAMrHlgS — Pwn All The Things (@pwnallthethings) [18]April 13, 2021

Six of the 114 Microsoft CVEs correspond to Microsoft Edge and were inherited via a recent Chromium update. Of the remainder, Childs notes that 27 are identified as "Remote Procedure Call Runtime Remote Code Execution Vulnerability," with 12 of these designated critical and 15 rated important.

"In RPC vulnerabilities seen in the past, an attacker would need to send a specially crafted RPC request to an affected system," he explained. "Successful exploitation results in executing code in the context of another user."

Among the rest, only [19]CVE-2021-28310 , identified as a Win32k Elevation of Privilege Vulnerability, is known to be under active exploitation.

And the rest

SAP [20]reported a higher number of security advisories than usual: 23, of which 11 are medium severity, five are high severity, and three are designated "Hot News" because SAP evidently can't bring itself to say "critical."

Among these three, one flaw managed to score a perfect 10 CVSS score. SAP hasn't made the details publicly available but security firm Onapsis [21]explains that it's an update that fixes 62 vulnerabilities in Google's Chromium browser, which is used in SAP Business Client.

Forescout has identified a set of nine vulnerabilities, dubbed [22]NAME:WRECK , affecting DNS-related code in four TCP/IP stacks – FreeBSD, Nucleus NET, IPnet and NetX – which are used in an estimated 100 million or more devices. The bugs can be exploited to crash boxes or execute arbitrary code.

The patch for FreeBSD is [23]here . If you're using equipment powered by the vulnerable software, get it patched or block off access to its at-risk services.

This [24]open-source script can detect vulnerable machines on your network.

The runner-up is a 9.9 severity flaw designated CVE-2021-27602, which SAP describes as a remote code execution vulnerability in Source Rules of SAP Commerce, versions 1808, 1811, 1905, 2005, and 2011.

The last of the top three is a 9.6 severity missing authorization check in SAP NetWeaver AS JAVA (migration service) that earned the CVE-2021-21481.

Adobe meanwhile [25]issued four advisories – APSB21-28 for Photoshop, APSB21-26 for Digital Editions, APSB21-23 for Bridge, and APSB21-20 for RoboHelp – addressing ten CVEs. Four of these are critical – two of these in Photoshop and the other two in Bridge.

Google at the beginning of the month dropped [26]39 CVEs covering Android and components from MediaTek and Qualcomm. Two were designated critical.

[27]

"The most severe of these issues is a critical security vulnerability in the System component that could enable a remote attacker using a specially crafted file to execute arbitrary code within the context of a privileged process," Google's security bulletin said. ®

Get our [28]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YHYUgUpejw4eBi-fWkIQYAAAAJY&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://msrc-blog.microsoft.com/2021/04/13/april-2021-update-tuesday-packages-now-available/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YHYUgUpejw4eBi-fWkIQYAAAAJY&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28480

[5] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28481

[6] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28482

[7] https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-28483

[8] https://www.theregister.com/2021/04/06/sap_patch_attacks/

[9] https://www.microsoft.com/en-us/download/details.aspx?id=103000

[10] https://www.microsoft.com/en-us/download/details.aspx?id=103001

[11] https://www.microsoft.com/en-us/download/details.aspx?id=103002

[12] https://www.microsoft.com/en-us/download/details.aspx?id=103003

[13] https://www.microsoft.com/en-us/download/details.aspx?id=103004

[14] https://twitter.com/NSACyber/status/1382020839118344199?s=20

[15] https://www.theregister.com/2021/03/03/hafnium_exchange_server_attack/

[16] https://www.zerodayinitiative.com/blog/2021/4/13/the-april-2021-security-update-review

[17] https://t.co/99tAMrHlgS

[18] https://twitter.com/pwnallthethings/status/1382048052400242692?ref_src=twsrc%5Etfw

[19] https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-28310

[20] https://wiki.scn.sap.com/wiki/pages/viewpage.action?pageId=573801649

[21] https://onapsis.com/blog/sap-security-patch-day-april-2021-serious-vulnerability-patched-sap-commerce

[22] https://www.forescout.com/company/blog/forescout-and-jsof-disclose-new-dns-vulnerabilities-impacting-millions-of-enterprise-and-consumer-devices/

[23] https://www.freebsd.org/security/advisories/FreeBSD-SA-20:26.dhclient.asc

[24] https://github.com/Forescout/project-memoria-detector

[25] https://helpx.adobe.com/security.html

[26] https://source.android.com/security/bulletin/2021-04-01

[27] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YHYUgUpejw4eBi-fWkIQYAAAAJY&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[28] https://whitepapers.theregister.com/

You've been telling me to relax all the way here, and now you're telling
me just to be myself?
-- The Return of the Secaucus Seven