Severity rating: High

Software affected
·         VMware VeloCloud Orchestrator versions 3.x

Overview
A vulnerability has been reported in VMware VeloCloud Orchestrator which
could allow an attacker to perform SQL injection attack on a targeted
system.

Description
This vulnerability exists in VeloCloud Orchestrator due to improper input
validation by the software. An attacker could exploit this vulnerability by
using specially crafted SQL queries on a targeted system.

Successful exploitation of this vulnerability could allow the attacker to
perform SQL injection attack and access privileged information on the
targeted system.

Solution
Update to patched versions as mentioned in the VMWare advisory:

Vendor Information
VMWare

References
IBM X-Force Exchange

CVE Name
CVE-2020-3973

It has been reported that a new ransomware-as-a-service (RaaS) tool, called
"Thanos" which provides buyers and affiliates a customization tool to build
unique payloads, is spreading and gaining popularity among various
underground forums and channels. This ransomware family employs the RIPlace
tactics majorly used to bypass the anti-ransomware endpoint security.

Thanos ransomware primarily delivered via phishing emails. The attack
campaign attracts the user with luring financial information like
tax-refund details, invoice scheme etc. Upon launch the ransomware tries to
terminate various security processes and system utilities to ensure
thorough encryption.

Its originally advertised features in late 2019 includes auto update for
builder tool, written in .NET, unique encryption keys per host , Anti-VM /
VM-evasion, multiple persistence options and many more. Later RIPlace
technique along with other updated features have been added during the last
six months. Further noteworthy features are also added recently including
disabling of 3rd party backup solutions (in addition to AV product
termination), file-permission changing to capture (exfil) or encrypt more
files, Bootlocker feature to display the ransom note at boot level (non
UEFI / Secure Boot-protected clients), expanded support of encryption on
Windows Server 2012 and many more to make it more resilient and
sophisticated. This enhances threat potential of this Thanos ransomware.

More than 80 Thanos "clients" are observed with different configurations
options enabled. As observed, in Thanos ransomware builder, a user may
select the option to enable RIPlace, which results in a modification of the
encryption process workflow to use the technique.

Encryption strategy:
Thanos' encryption technique varies with the evolution of its payloads.
While encrypting, Thanos uses a random, 32-byte string generated at runtime
as a passphrase for the AES file encryption. The string is then encrypted
with the ransomware operator's public key and without the corresponding
private key, recovering the encrypted files is extremely difficult /
impossible.

However, the Thanos builder also provide feature to use a static password
for the AES file encryption. In this option chosen, AES password used to
encrypt files and if a Thanos client is recovered after the encryption has
occurred then there is a chance of files recovery without paying ransom.


IOC:

SHA1:
f086a802887c4b3ed9be69ffc018fb6ffb324f5e
15a00d3aba362aade900374b6d159de98e8eac62
0ecff2f818565e7eb28d3a7b7d295459a868e920
ffcc533b3b5630f405ff9e6274fc273f1bd33594
f5664b367a841643728cd90d0cb61df9e58fa4d7
4c6e634075781724cba954a76d1d831d077b7257
da0cd782f32088c0df8cd62deda1c61b4cedd6fb
caef3905436bdf99bda6a3de64b162630c527375
6be2e40bd6901462f9d87fbee63740a3971d1a75
31bd11c9d4dd19185a2ea42507ba8a3651198335
5b1d1de92d8b8163ac70281d6afa3113d0f86362
4e04822d6b8c3087be0550dba96f0c80d84359f8
a86ba83804da1f7d2675d5994c724995fef09771
c5517ca6e843efb0a4d2989e6ba16dde6cf7da65
ae42c46c6b8a5a60c232665abd6c9bc469021512
18529b6bef216231c34b2701eb3894ca2dd3a5ba
5f44342dc0cb0c4ef3a3b3dad1e974e9c6eb9120
f3264a5ecd6e1b3aef2884b1c35028eedcf442dc
b4fe4ce027afeb9ca0b88b52891fb7c73d822d10
018a392975a8731735ef709e6418e5af19db3756
db49455bbc76eb00a99e803aa46d5681ac60b17b
1867a1100203ea14f9496b938c23b44a3b31ec40

SHA256:
7e6db426de4677efbf2610740b737da03c68a7c6295aca1a377d1df4d35959e5
34b93f1989b272866f023c34a2243978565fcfd23869cacc58ce592c1c545d8e
7a7a5110cb9a8ee361c9c65f06293667451e5200d21db72954002e5725971950
befc6ff8c63889b72d1f5aec5e5accc1b4098a83cd482a6bb85182ecd640b415
81e81f0bbbdb831eda215033b7a7dbf2eed3812f4e58118f181a8e99e613179e
23d7693284e90b752d40f8c0c9ab22da45f7fe3219401f1209c89ac98a4d7ed3
989a9d2e08fcba4059ebc55afc049f34d2a12bfdd1e14f468ee8b5c27c9e7bda
794369bc9a06041f906910309b2ce45569a03c378ff0468b6335d4f653f190ab
855dcd368dbb01539e7efa4b3fefa9b56d197db87b1ba3ede5e1f95927ea2ca3
8a2b54d273d01f8d5f42311d5402950bb9983648a39b943c729314a97ede15a2
09fd6a13fbe723eec2fbe043115210c1538d77627b93feeb9e600639d20bb332
edcac243808957cc898d4a08a8b0d5eaf875f5f439a3ca0acfaf84522d140e7e
f0c0c989b018ee24cbd7548cec4e345fd34f491d350983fddb5ddc1ad1f4ba9f
10dc9cb12580bc99f039b1c084ca6f136047ac4d5555ad90a7b682a2ffac4dc5
a95f9d82097bdfa2dd47e075b75d09907d5913e5c15d05c926de0d8bbce9698f
f7d7111653c43476039efd370fb39fcdb2c22a3f1bb89013af643b45fb3af467
53806ba5c9b23a43ddbfa669798d46e715b55a5d88d3328c5af15ba7f26fbadd

Countermeasures and Best practices for prevention:
Don't open attachments in unsolicited e-mails, even if they come from
people in your contact list, and never click on a URL contained in an
unsolicited e-mail, even if the link seems benign. In cases of genuine URLs
close out the e-mail and go to the organization's website directly
through browser.
Install ad blockers to combat exploit kits such as Fallout that are
distributed via malicious advertising.
Prohibit external FTP connections and blacklist downloads of known
offensive security tools.
All operating systems and applications should be kept updated on a regular
basis. Virtual patching can be considered for protecting legacy systems and
networks. This measure hinders cybercriminals from gaining easy access to
any system through vulnerabilities in outdated applications and software.
Avoid applying updates / patches available in any unofficial channel.
Restrict execution of Power shell /WSCRIPT in an enterprise environment.
Ensure installation and use of the latest version of PowerShell, with
enhanced logging enabled. Script block logging and transcription enabled.
Send the associated logs to a centralized log repository for monitoring and
analysis.
ml
Establish a Sender Policy Framework (SPF) for your domain, which is an
email validation system designed to prevent spam by detecting email
spoofing by which most of the ransomware samples successfully reaches the
corporate email boxes.
Application whitelisting/Strict implementation of Software Restriction
Policies (SRP) to block binaries running from %APPDATA% and %TEMP% paths.
Ransomware sample drops and executes generally from these locations.
Users are advised to disable their RDP if not in use, if required, it
should be placed behind the firewall and users are to bind with proper
policies while using the RDP.
Block the attachments of file types,
exe|pif|tmp|url|vb|vbe|scr|reg|cer|pst|cmd|com|bat|dll|dat|hlp|hta|js|wsf
Consider encrypting the confidential data as the ransomware generally
targets common file types.
Perform regular backups of all critical information to limit the impact of
data or system loss and to help expedite the recovery process. Ideally,
this data should be kept on a separate device, and backups should be stored
offline.
Network segmentation and segregation into security zones - help protect
sensitive information and critical services. Separate administrative
network from business processes with physical controls and Virtual Local
Area Networks.
References

added-to-feature-set/

Severity Rating: High

Software Affected
·          Citrix ADC and Citrix Gateway prior to version13.0-58.30
·         Citrix ADC and NetScaler Gateway prior to version 12.1-57.18
·         Citrix ADC and NetScaler Gateway prior to version 12.0-63.21 
·         Citrix ADC and NetScaler Gateway prior to version 11.1-64.14 
·         NetScaler ADC and NetScaler Gateway prior to version 10.5-70.18
·         Citrix SD-WAN WANOP 11.1.1a prior to version
·         Citrix SD-WAN WANOP 11.0.3d prior to version
·         Citrix SD-WAN WANOP 10.2.7 prior to version
·         Citrix Gateway Plug-in for Linux  prior to version 1.0.0.137.

Overview
Multiple vulnerabilities have  been reported in Citrix ADC (Application
Delivery Controller), Citrix Gateway and Citrix SD-WAN WANOP appliance
models 4000-WO, 4100-WO, 5000-WO, and 5100-WO which could allow an attacker
to gain elevated privileges or cause denial of services (DoS),information
disclosure, authorization bypass ,code injection and Cross Site Scripting
on the targeted system.

Description
1.Information disclosure Vulnerability
(CVE-2019-18177)(CVE-2020-8196)(CVE-2020-8195)

A Vulnerability exists in Citrix ADC, Citrix Gateway and Citrix SD-WAN
WANOP that could allow a remote authenticated user to obtain sensitive
information. An attacker could exploit this vulnerability by sending a
crafted request to the targeted device.

Successful exploitation of this vulnerability could allow the attacker to
obtain sensitive information and use this information to launch further
attacks against the affected system.

2. Privilege elevation vulnerability (CVE-2020-8190)  (CVE-2020-8197) 
(CVE-2020-8199)                                                            
A Vulnerability exists in Citrix ADC, Citrix Gateway and Citrix Gateway
Plug-in for Linux that could allow a local authenticated malicious user to
gain elevated privileges on the system. An attacker could exploit this
vulnerability by executing a specially-crafted program to the targeted
device.

Successful exploitation of this vulnerability could allow the attacker to
gain elevated privileges.

3. Cross Site Scripting vulnerability (CVE-2020-8191 (CVE-2020-8198)
A Vulnerability exists in Citrix ADC, Citrix Gateway and Citrix SD-WAN
WANOP due to improper validation of user-supplied input. This vulnerability
could allow a remote attacker to gain user credentials. An attacker could
exploit this vulnerability by executing a specially-crafted URL to execute
script in a victim's Web browser.

Successful exploitation of this vulnerability could allow the attacker to
steal the victim's cookie-based authentication credentials.

4. Authorization bypass vulnerability (CVE-2020-8193)
A Vulnerability exists in Citrix ADC, Citrix Gateway and Citrix SD-WAN
WANOP due to improper authentication validation. This vulnerability could
allow a remote attacker to bypass security restrictions. An attacker could
exploit this vulnerability by sending a specially-crafted request to the
targeted device.

Successful exploitation of this vulnerability could allow the attacker to
bypass access restrictions.

5. Code Injection vulnerability (CVE-2020-8194)
A Vulnerability exists in Citrix ADC, Citrix Gateway and Citrix SD-WAN
WANOP due to a code injection flaw. This vulnerability could allow a remote
attacker to execute arbitrary code on the system. An attacker could exploit
this vulnerability by persuading a victim to open a specially-crafted
content on the targeted system.

Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code on the targeted system.

Solution
Apply appropriate updates as mentioned in:

Vendor Information
CITRIX

Reference
CITRIX

CVE Name
(CVE-2019-18177)
(CVE-2020-8196)
(CVE-2020-8195)
(CVE-2020-8190)
(CVE-2020-8197)
(CVE-2020-8199)
(CVE-2020-8198)
(CVE-2020-8191)
(CVE-2020-8193)
(CVE-2020-8194)
(CVE-2020-8187)

Severity Rating: High

Software Affected
·         Mozilla Firefox versions prior to 78.0
·         Mozilla Firefox ESR versions prior to 68.10
·         Mozilla Thunderbird versions prior to 68.10

Overview
Multiple vulnerabilities have been reported in Mozilla Products which could
allow a remote attacker to bypass security restrictions, obtain sensitive
information, execute arbitrary code on the target system, or cause denial
of service (DoS) conditions.

Description      
These vulnerabilities exist in Mozilla products due to missing
sign-extension for ValueTags on ARM64 platforms, manipulated URL object,
use-after-free error in nsGlobalWindowInner, use-after-free error while
trying to connect to a STUN server, an error while following certificate
trust rules by the Add-On updates, an error while processing url encoded
character, use-after-free error in WebRTC VideoBroadcaster, an error during
RSA key generation in Network Security Services (NSS), integer overflow
error in nsJPEGEncoder, missing Windows DLL "webauthn.dll" from the
operating system, an error in permission prompt for WebRTC, out of bound
read in Date.parse(), memory corruption errors. A remote attacker could
exploit these vulnerabilities by executing malicious contents on the target
system.

Successful exploitation of these vulnerabilities could allow the attacker
to bypass security restrictions, obtain sensitive information, execute
arbitrary code on the target system, or cause denial of service (DoS)
conditions.

Solution
Apply appropriate updates as mentioned in the Mozilla Security Advisories

Vendor Information
Mozilla

Reference
Mozilla

CVE Name
CVE-2020-12402
CVE-2020-12415
CVE-2020-12416
CVE-2020-12417
CVE-2020-12418
CVE-2020-12419
CVE-2020-12420
CVE-2020-12421
CVE-2020-12422
CVE-2020-12423
CVE-2020-12424
CVE-2020-12425
CVE-2020-12426

Severity Rating: HIGH

Software Affected
IBM Db2 version 9.7
IBM Db2 version 10.1
IBM Db2 version 10.5
IBM Db2 version 11.1
IBM Db2 version 11.5

Overview
Multiple vulnerabilities have been reported in IBM DB2which could allow an
attacker to gain elevated privileges or cause denial of service conditions
on the targeted system.

Description
1. Buffer Overflow Vulnerabilities ( CVE-2020-4204   CVE-2020-4363   ) 

These vulnerability exists in IBM DB2 due to improper bounds checking. A
local attacker could exploit this vulnerability to execute arbitrary code
with root privileges.
Successful exploitation of this vulnerability could allow the attacker to
gain privileges on the target system. 

2. Denial of Service Vulnerability ( CVE-2020-4420   ) 
This vulnerability exists in IBM DB2 due to improper handling of certain
commands. A local attacker could exploit this vulnerability due to hang in
the execution of a terminate command.
Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions resulting in the DB2 to stop working. 

3. Information Disclosure Vulnerability ( CVE-2020-4387   CVE-2020-4386   )
This vulnerability exists in IBM DB2 due to a symbolic link. A local
attacker could exploit this vulnerability by using race condition of a
symbolic link.
Successful exploitation of this vulnerability could allow the attacker to
obtain sensitive information on the target system. 

4. Denial of Service Vulnerability ( CVE-2020-4355   ) 
This vulnerability exists in IBM DB2 due to improper handling of Secure
Sockets Layer (SSL) renegotiation requests. A remote attacker could exploit
this vulnerability by executing specially crafted DB2 commands and increase
the resource usage on the system.
Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions resulting in the DB2 to stop working. 

5. Information Disclosure and Denial of Service Vulnerability (
CVE-2020-4414   ) 
This vulnerability exists in IBM DB2 due to improper usage of shared
memory. A remote attacker could exploit this vulnerability by executing
specially crafted request and perform unauthorized actions on the system.
Successful exploitation of this vulnerability could allow the attacker to
cause denial of service condition and obtain sensitive information.

Solution
Apply appropriate updates mentioned in the IBM Security Bulletin 

Vendor Information
IBM

References
IBM

CVE Name
CVE-2020-4204
CVE-2020-4363
CVE-2020-4420
CVE-2020-4387
CVE-2020-4386
CVE-2020-4355
CVE-2020-4414

Severity Rating: HIGH

Software Affected 
·         Apache Guacamole 1.1.0 and older

Overview
Multiple vulnerabilities have been reported in Apache Guacamole product
which could allow an attacker with access to a malicious or compromised RDP
server to execute arbitrary code, cause memory corruption or enable
information disclosure from a targeted guacd process.

Description
1. Improper input validation of RDP static virtual channels (CVE-2020-9497)

This vulnerability exists due to improper validation of data received from
RDP servers via static virtual channels. If a user connects to a malicious
or compromised RDP server, specially-crafted PDUs could result in
disclosure of information within the memory of the guacd process handling
the connection.

Successful exploitation of this vulnerability could allow an attacker to
access the sensitive information on the targeted system.

2.  Dangling pointer in RDP static virtual channel handling (CVE-2020-9498)
This vulnerability exists due to mishandling of pointers involved in
processing data received via RDP static virtual channels. If a user
connects to a malicious or compromised RDP server, a series of
specially-crafted PDUs could result in memory corruption, possibly allowing
arbitrary code to be executed with the privileges of the running guacd
process.

Successful exploitation of this vulnerability could allow an attacker to
use specially-crafted PDUs to cause memory corruption and execute arbitrary
code with the privileges of the running guacd process.

Solution
Apply appropriate patches as mentioned in Apache Guacamole.

Vendor Information
Apache Guacamole

References
CheckPoint Research

CVE Name
CVE-2020-9497
CVE-2020-9498

Severity Rating: HIGH

Software Affected
·         Windows 10 Version 1709 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1709 for ARM64-based Systems
·         Windows 10 Version 1803 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1803 for ARM64-based Systems
·         Windows 10 Version 1809 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1809 for ARM64-based Systems
·         Windows 10 Version 1903 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1903 for ARM64-based Systems
·         Windows 10 Version 1909 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1909 for ARM64-based Systems
·         Windows 10 Version 2004 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 2004 for ARM64-based Systems

Overview
Multiple vulnerabilities have been reported in Microsoft Windows which
could allow a remote attacker to execute arbitrary code on a targeted
system.

Description
These vulnerabilities exist in Microsoft Windows Codecs Library due to
improper handling of objects in memory. A remote attacker could exploit
this vulnerability by convincing the user to open a specially crafted image
file on an affected system.

Successful exploitation of these vulnerabilities could allow the attacker
to execute arbitrary code on the targeted system.

Solution
The affected systems are being updated automatically via Microsoft Store.
To receive the update immediately, users can check for updates with the
Microsoft Store App. For further information, refer to the FAQ sections at:


Vendor Information
Microsoft

References
ESET WeLiveSecurity

CyberSecurityHelp

CVE Name
CVE-2020-1425
CVE-2020-1457

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top