{"id":21708,"date":"2023-04-11T16:17:04","date_gmt":"2023-04-12T00:17:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2023\/04\/11\/news-15439\/"},"modified":"2023-04-11T16:17:04","modified_gmt":"2023-04-12T00:17:04","slug":"news-15439","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2023\/04\/11\/news-15439\/","title":{"rendered":"Microsoft (&#038; Apple) Patch Tuesday, April 2023 Edition"},"content":{"rendered":"<p><strong>Credit to Author: BrianKrebs| Date: Wed, 12 Apr 2023 00:06:51 +0000<\/strong><\/p>\n<p><strong>Microsoft<\/strong> today released software updates to plug 100 security holes in its <strong>Windows<\/strong> operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, <strong>Apple<\/strong> has released a set of important updates addressing <em>two<\/em> zero-day vulnerabilities that are being used to attack <strong>iPhones<\/strong>, <strong>iPads<\/strong> and <strong>Macs<\/strong>.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-56287\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2021\/07\/windupate.png\" alt=\"\" width=\"841\" height=\"592\" srcset=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2021\/07\/windupate.png 841w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2021\/07\/windupate-768x541.png 768w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2021\/07\/windupate-782x550.png 782w, https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2021\/07\/windupate-100x70.png 100w\" sizes=\"auto, (max-width: 841px) 100vw, 841px\" \/><\/p>\n<p>On April 7, Apple issued emergency security updates to fix two weaknesses that are being actively exploited, including <a href=\"https:\/\/support.apple.com\/en-us\/HT213723\" target=\"_blank\" rel=\"noopener\">CVE-2023-28206<\/a>, which can be exploited by apps to seize control over a device. <a href=\"https:\/\/support.apple.com\/en-us\/HT213723\" target=\"_blank\" rel=\"noopener\">CVE-2023-28205<\/a> can be used by a malicious or hacked website to install code.<\/p>\n<p>Both vulnerabilities are addressed in <a href=\"https:\/\/support.apple.com\/en-us\/HT201222\" target=\"_blank\" rel=\"noopener\">iOS\/iPadOS 16.4.1, iOS 15.5.7, and macOS 12.6.5 and 11.7.6<\/a>. If you use Apple devices and you don&#8217;t have automatic updates enabled (they are on by default), you should probably take care of that soon as detailed instructions on how to attack CVE-2023-28206 <a href=\"https:\/\/www.idownloadblog.com\/2023\/04\/10\/linus-henze-poc-cve-2023-28206\/\" target=\"_blank\" rel=\"noopener\">are now public<\/a>.<\/p>\n<p>Microsoft&#8217;s bevy of 100 security updates released today include <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28252\" target=\"_blank\" rel=\"noopener\">CVE-2023-28252<\/a>, which is a weakness in Windows that Redmond says is under active attack. The vulnerability is in the <strong>Windows Common Log System File System<\/strong> (CLFS) driver, a core Windows component that was the source of <a href=\"https:\/\/krebsonsecurity.com\/2023\/02\/microsoft-patch-tuesday-february-2023-edition\/\" target=\"_blank\" rel=\"noopener\">attacks targeting a different zero-day vulnerability in February 2023<\/a>.<\/p>\n<p>&#8220;If it seems familiar, that&#8217;s because there was a similar 0-day patched in the same component just two months ago,&#8221; said <strong>Dustin Childs<\/strong> at the <strong>Trend Micro Zero Day Initiative<\/strong>. &#8220;To me, that implies the original fix was insufficient and attackers have found a method to bypass that fix. As in February, there is no information about how widespread these attacks may be. This type of exploit is typically paired with a code execution bug to spread malware or ransomware.&#8221;<\/p>\n<p>According to the security firm <strong>Qualys<\/strong>, this vulnerability has been leveraged by cyber criminals to deploy <strong>Nokoyawa<\/strong> ransomware.<\/p>\n<p>&#8220;This is a relatively new strain for which there is some open source intel to suggest that it is possibly related to Hive ransomware \u2013 one of the most notable ransomware families of 2021 and linked to breaches of over 300+ organizations in a matter of just few months,&#8221; said <strong>Bharat Jogi<\/strong>, director of vulnerability and threat research at Qualys.<\/p>\n<p>Jogi said while it is still unclear which exact threat actor is targeting CVE-2023-28252, targets have been observed in South and North America, regions across Asia and at organizations in the Middle East.<span id=\"more-63336\"><\/span><\/p>\n<p><strong>Satnam Narang<\/strong> at <strong>Tenable<\/strong> notes that CVE-2023-28252 is also the second CLFS zero-day disclosed to Microsoft by researchers from <strong>Mandiant<\/strong> and <strong>DBAPPSecurity<\/strong> (<a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2022-37969\" target=\"_blank\" rel=\"noopener\">CVE-2022-37969<\/a>), though it is unclear if both of these discoveries are related to the same attacker.<\/p>\n<p>Seven of the 100 vulnerabilities Microsoft fixed today are rated &#8220;Critical,&#8221; meaning they can be used to install malicious code with no help from the user. Ninety of the flaws earned Redmond&#8217;s slightly less-dire &#8220;Important&#8221; label, which refers to weaknesses that can be used to undermine the security of the system but which may require some amount of user interaction.<\/p>\n<p>Narang said Microsoft has rated nearly 90% of this month&#8217;s vulnerabilities as &#8220;Exploitation Less Likely,&#8221; while just 9.3% of flaws were rated as &#8220;Exploitation More Likely.&#8221; <strong>Kevin Breen<\/strong> at <strong>Immersive Labs<\/strong> zeroed in on several notable flaws in that 9.3%, including <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28231\" target=\"_blank\" rel=\"noopener\">CVE-2023-28231<\/a>, a remote code execution vulnerability in a core Windows network process (DHCP) with a CVSS score of 8.8.<\/p>\n<p>&#8220;&#8216;Exploitation more likely&#8217; means it&#8217;s not being actively exploited but adversaries may look to try and weaponize this one,&#8221; Breen said. &#8220;Micorosft does note that successful exploitation requires an attacker to have already gained initial access to the network. This could be via social engineering, spear phishing attacks, or exploitation of other services.&#8221;<\/p>\n<p>Breen also called attention to <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28220\" target=\"_blank\" rel=\"noopener\">CVE-2023-28220<\/a> and <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2023-28219\" target=\"_blank\" rel=\"noopener\">CVE-2023-28219<\/a> &#8212; a pair of remote code execution vulnerabilities affecting <strong>Windows Remote Access Servers<\/strong> (RAS) that also earned Microsoft&#8217;s &#8220;exploitation more likely&#8221; label.<\/p>\n<p>&#8220;An attacker can exploit this vulnerability by sending a specially crafted connection request to a RAS server, which could lead to remote code execution,&#8221; Breen said. While not standard in all organizations, RAS servers typically have direct access from the Internet where most users and services are connected. This makes it extremely enticing for attackers as they don\u2019t need to socially engineer their way into an organization. They can simply scan the internet for RAS servers and automate the exploitation of vulnerable devices.&#8221;<\/p>\n<p>For more details on the updates released today, see the <a href=\"https:\/\/isc.sans.edu\/diary\/Microsoft%20April%202023%20Patch%20Tuesday\/29736\" target=\"_blank\" rel=\"noopener\">SANS Internet Storm Center roundup<\/a>. If today\u2019s updates cause any stability or usability issues in Windows,\u00a0<a href=\"https:\/\/www.askwoody.com\/2023\/march-madness-here-we-come\/\" target=\"_blank\" rel=\"noopener\">AskWoody.com<\/a>\u00a0will likely have the lowdown on that.<\/p>\n<p>Please consider backing up your data and\/or imaging your system before applying any updates. And feel free to sound off in the comments if you experience any problems as a result of these patches.<\/p>\n<p><a href=\"https:\/\/krebsonsecurity.com\/2023\/04\/microsoft-apple-patch-tuesday-april-2023-edition\/\" target=\"bwo\" >https:\/\/krebsonsecurity.com\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/krebsonsecurity.com\/wp-content\/uploads\/2021\/07\/windupate.png\"\/><\/p>\n<p><strong>Credit to Author: BrianKrebs| Date: Wed, 12 Apr 2023 00:06:51 +0000<\/strong><\/p>\n<p>Microsoft today released software updates to plug 100 security holes in its Windows operating systems and other software, including a zero-day vulnerability that is already being used in active attacks. Not to be outdone, Apple has released a set of important updates addressing two zero-day vulnerabilities that are being used to attack iPhones, iPads and Macs.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10643,10642],"tags":[29077,27505,29078,29079,29065,29080,24602,29081,29082,29083,11290,29084,13457,17220,17061,16936,25285,29085],"class_list":["post-21708","post","type-post","status-publish","format-standard","hentry","category-independent","category-krebs","tag-bharat-jogi","tag-cve-2022-37969","tag-cve-2023-28219","tag-cve-2023-28220","tag-cve-2023-28252","tag-dbappsecurity","tag-dustin-childs","tag-ios-15-5-7","tag-ios-ipados-16-4-1","tag-macos-12-6-5-and-11-7-6","tag-mandiant","tag-nokoyawa-ransomware","tag-qualys","tag-security-tools","tag-the-coming-storm","tag-time-to-patch","tag-trend-micro-zero-day-initiative","tag-windows-common-log-system-file-system"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21708","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=21708"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/21708\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=21708"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=21708"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=21708"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}