Emergency updates: Adobe, Chrome patch security bugs under active attack
(2022/02/16)
- Reference: 1645046743
- News link: https://www.theregister.co.uk/2022/02/16/adobe_chrome_patch/
- Source link:
Adobe has released an out-of-band security update for Adobe Commerce and Magento Open Source to address active exploitation of a known vulnerability, and Google has an emergency issue, too.
[1]Security Bulletin APSB22-12 fixes CVE-2022-24086, rated 9.8 (critical) out of 10 on the CVSS scale. Adobe has not released details about the issue beyond noting that it involves improper input validation ( [2]CWE-20 ). The software maker says exploitation does not require any special privileges and allows arbitrary code execution.
"Adobe is aware that CVE-2022-24086 has been exploited in the wild in very limited attacks targeting Adobe Commerce merchants," the Silicon Valley stalwart said.
[3]
Magento is an open source ecommerce system written in PHP and is used to support online shopping on [4]hundreds of thousands of websites. It was acquired by Adobe in May 2018 and has become the basis for Adobe Commerce.
[5]
[6]
Versions up to 2.3.7-p2 and up to 2.4.3-p1 for both Magento and Adobe Commerce are affected. Those using a vulnerable version of the software are advised to apply the appropriate patch immediately.
"This vulnerability has a similar severity as the Magento Shoplift vulnerability from 2015," said security firm Sansec in a [7]blog post on Monday. "At that time, nearly all unpatched Magento stores globally were compromised in the days after the exploit publication."
[8]
Sansec predicted mass scanning and exploitation would occur within 72 hours.
Google's in there too
Separately, Google released [9]a Chrome browser update on Valentine's Day that addresses 11 flaws, including a zero-day vulnerability that is being abused in the wild.
"Google is aware of reports that an exploit for CVE-2022-0609 exists in the wild," it warned. In other words, all hands to the patches.
[10]CVE-2022-0609 was reported by Adam Weidemann and Clément Lecigne of Google's Threat Analysis Group on February 10, 2022. It's a [11]use-after-free() vulnerability in Chrome's Animation code. When memory is used after it has been freed, via an uncleared pointer, that can lead to a crash and enable exploitation.
[12]Apple emits emergency fix for exploited-in-the-wild WebKit vulnerability
[13]Critical 'remote escalation' flaw in Android 12 fixed in Feb security patch batch
[14]Microsoft manages a mere 51 security fixes for February update bundle
[15]Open-source Kubernetes tool Argo CD has a high-severity path traversal flaw: Patch now
The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added both the Adobe and the Chrome zero-days, along with seven other CVEs dating back to 2013, to its [16]Known Exploited Vulnerabilities Catalog .
"These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise," [17]the CISA notification said.
The notification directs federal civilian executive branch (FCEB) agencies to fix the Adobe and Google bugs by March 1, 2022. ®
Get our [18]Tech Resources
[1] https://helpx.adobe.com/security/products/magento/apsb22-12.html
[2] https://cwe.mitre.org/data/definitions/20.html
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yg2CFsbNWv4OR3YXXLCKWgAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://trends.builtwith.com/shop/Magento
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yg2CFsbNWv4OR3YXXLCKWgAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yg2CFsbNWv4OR3YXXLCKWgAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://sansec.io/research/magento-2-cve-2022-24086
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yg2CFsbNWv4OR3YXXLCKWgAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop_14.html
[10] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0609
[11] https://cwe.mitre.org/data/definitions/416.html
[12] https://www.theregister.com/2022/02/11/apple_emergency_webkit/
[13] https://www.theregister.com/2022/02/09/android_security_bulletin/
[14] https://www.theregister.com/2022/02/09/microsoft_patch_tuesday/
[15] https://www.theregister.com/2022/02/04/argo_cd_0day_kubernetes/
[16] https://www.cisa.gov/known-exploited-vulnerabilities-catalog
[17] https://www.cisa.gov/uscert/ncas/current-activity/2022/02/15/cisa-adds-nine-known-exploited-vulnerabilities-catalog
[18] https://whitepapers.theregister.com/
[1]Security Bulletin APSB22-12 fixes CVE-2022-24086, rated 9.8 (critical) out of 10 on the CVSS scale. Adobe has not released details about the issue beyond noting that it involves improper input validation ( [2]CWE-20 ). The software maker says exploitation does not require any special privileges and allows arbitrary code execution.
"Adobe is aware that CVE-2022-24086 has been exploited in the wild in very limited attacks targeting Adobe Commerce merchants," the Silicon Valley stalwart said.
[3]
Magento is an open source ecommerce system written in PHP and is used to support online shopping on [4]hundreds of thousands of websites. It was acquired by Adobe in May 2018 and has become the basis for Adobe Commerce.
[5]
[6]
Versions up to 2.3.7-p2 and up to 2.4.3-p1 for both Magento and Adobe Commerce are affected. Those using a vulnerable version of the software are advised to apply the appropriate patch immediately.
"This vulnerability has a similar severity as the Magento Shoplift vulnerability from 2015," said security firm Sansec in a [7]blog post on Monday. "At that time, nearly all unpatched Magento stores globally were compromised in the days after the exploit publication."
[8]
Sansec predicted mass scanning and exploitation would occur within 72 hours.
Google's in there too
Separately, Google released [9]a Chrome browser update on Valentine's Day that addresses 11 flaws, including a zero-day vulnerability that is being abused in the wild.
"Google is aware of reports that an exploit for CVE-2022-0609 exists in the wild," it warned. In other words, all hands to the patches.
[10]CVE-2022-0609 was reported by Adam Weidemann and Clément Lecigne of Google's Threat Analysis Group on February 10, 2022. It's a [11]use-after-free() vulnerability in Chrome's Animation code. When memory is used after it has been freed, via an uncleared pointer, that can lead to a crash and enable exploitation.
[12]Apple emits emergency fix for exploited-in-the-wild WebKit vulnerability
[13]Critical 'remote escalation' flaw in Android 12 fixed in Feb security patch batch
[14]Microsoft manages a mere 51 security fixes for February update bundle
[15]Open-source Kubernetes tool Argo CD has a high-severity path traversal flaw: Patch now
The US Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added both the Adobe and the Chrome zero-days, along with seven other CVEs dating back to 2013, to its [16]Known Exploited Vulnerabilities Catalog .
"These types of vulnerabilities are a frequent attack vector for malicious cyber actors of all types and pose significant risk to the federal enterprise," [17]the CISA notification said.
The notification directs federal civilian executive branch (FCEB) agencies to fix the Adobe and Google bugs by March 1, 2022. ®
Get our [18]Tech Resources
[1] https://helpx.adobe.com/security/products/magento/apsb22-12.html
[2] https://cwe.mitre.org/data/definitions/20.html
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yg2CFsbNWv4OR3YXXLCKWgAAAMw&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://trends.builtwith.com/shop/Magento
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yg2CFsbNWv4OR3YXXLCKWgAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yg2CFsbNWv4OR3YXXLCKWgAAAMw&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] https://sansec.io/research/magento-2-cve-2022-24086
[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yg2CFsbNWv4OR3YXXLCKWgAAAMw&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[9] https://chromereleases.googleblog.com/2022/02/stable-channel-update-for-desktop_14.html
[10] https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0609
[11] https://cwe.mitre.org/data/definitions/416.html
[12] https://www.theregister.com/2022/02/11/apple_emergency_webkit/
[13] https://www.theregister.com/2022/02/09/android_security_bulletin/
[14] https://www.theregister.com/2022/02/09/microsoft_patch_tuesday/
[15] https://www.theregister.com/2022/02/04/argo_cd_0day_kubernetes/
[16] https://www.cisa.gov/known-exploited-vulnerabilities-catalog
[17] https://www.cisa.gov/uscert/ncas/current-activity/2022/02/15/cisa-adds-nine-known-exploited-vulnerabilities-catalog
[18] https://whitepapers.theregister.com/