Severity Rating: HIGH

Software Affected

Microsoft Lync Server 2013
Microsoft SharePoint Enterprise Server 2016
Microsoft SharePoint Foundation 2013 Service Pack 1
Microsoft SharePoint Server 2019
Skype for Business Server 2015 CU 8
Skype for Business Server 2019 CU2
Overview

Elevation of privilege vulnerability has been reported in Microsoft
SharePoint Server and Skype for Business Server, which could allow an
attacker to gain elevated privileges, bypass security restrictions and
execute arbitrary code on the targeted system.

Description

This vulnerability exists in Microsoft SharePoint Server and Skype for
Business Server due to improper handling of the OAuth token validation. A
remote attacker could exploit this vulnerability by alter the token.  

Successful exploitation of this vulnerability could allow the attacker to
gain elevated privileges and bypass authentication of the targeted system.

Solution

Apply appropriate fix as mentioned in Microsoft Security Advisory 


Vendor Information

Microsoft

References

Microsoft
- -1025

CVE Name
CVE-2020-1025

Virus Type: Ransomware

It is reported that the ransomware named "CLOP" is active in attacking
organizations/institutions across the globe. Post compromise this
ransomware leaks information if negotiation deal of ransom fails. Recently
the threat actors behind Clop have stolen and encrypted the sensitive
information of various organizations and after failure of ransom payment,
the stolen information was leaked on their "CL0P^_- LEAKS" data leak
site, hosted on dark web. The leaked information includes data backups,
financial records, thousands of emails and vouchers etc. 

After encryption CLOP ransomware appends ".Clop" extension in each file
and generates a text file "ClopReadMe.txt" containing ransom note in each
folder. CLOP ransomware uses RSA (Rivest-Shamir-Adleman) encryption
algorithm and generated keys are stored on a remote server controlled by
Clop operators.


Updated versions of Clop have tried to expand their attack vectors through
disabling and removing local security solutions such as Windows Defender
and Microsoft Security Essentials etc. This ransomware has capability of
installing additional password stealing Trojans and other malware
infections.


In most cases, Clop is distributed via fake software updates, trojans,
cracks, unofficial software download sources, and spam emails. In the
recent attack on an Indian conglomerate, it is suspected that the bug
(CVE-2019-19781) in the Citrix Netscaler ADC VPN gateway was utilized to
carry out the attack. Unfortunately, as of now no decryptor tool is
available for Clop ransomware. 

Indicators of compromise: 

Hashes:

6d115ae4c32d01a073185df95d3441d51065340ead1eada0efda6975214d1920
6d8d5aac7ffda33caa1addcdc0d4e801de40cb437cf45cface5350710cde2a74
70f42cc9fca43dc1fdfa584b37ecbc81761fb996cb358b6f569d734fa8cce4e3
a5f82f3ad0800bfb9d00a90770c852fb34c82ecb80627be2d950e198d0ad6e8b
85b71784734705f6119cdb59b1122ce721895662a6d98bb01e82de7a4f37a188 (unpacked)
2ceeedd2f389c6118b4e0a02a535ebb142d81d35f38cab9a3099b915b5c274cb
00e815ade8f3ad89a7726da8edd168df13f96ccb6c3daaf995aa9428bfb9ecf1
0d19f60423cb2128555e831dc340152f9588c99f3e47d64f0bb4206a6213d579
408af0af7419f67d396f754f01d4757ea89355ad19f71942f8d44c0d5515eec8
7e91ff12d3f26982473c38a3ae99bfaf0b2966e85046ebed09709b6af797ef66
a867deb1578088d066941c40e598e4523ab5fd6c3327d3afb951073bee59fb02
Emails:

servicedigilogos@protonmail[d0t]com
managersmaers@tutanota[d0t]com
unlock@eqaltech[d0t]su
unlock@royalmail[d0t]su
unlock@goldenbay[d0t]su
unlock@graylegion[d0t]su
kensgilbomet@protonmail[d0t]com
Files Detection/aliases:

Ransom.Win32.CLOP.D
Ransom.Win32.CLOP.D
Ransom.Win32.CLOP.F
Ransom.Win32.CLOP.F.note
Ransom.Win32.CLOP.M
Ransom.Win32.CLOP.THBAAAI
Trojan.BAT.CLOP.A
Trojan.BAT.CLOP.A.component
Trojan.Win32.CLOP.A.note
For detailed IOC (Hashes, Files etc), please refer the links provide in
references.

Countermeasures and Best practices for prevention:

Do not download and install applications from untrusted sources [offered
via unknown websites/ links on unscrupulous messages]. Install applications
downloaded from reputed application market only.
Update software and operating systems with the latest patches. Outdated
applications and operating systems are the targets of most attacks.
Don't open attachments in unsolicited e-mails, even if they come from
people in your contact list, and never click on a URL contained in an
unsolicited e-mail, even if the link seems benign. In cases of genuine URLs
close out the e-mail and go to the organization's website directly through
browser.
Install ad blockers to combat exploit kits such as Fallout that are
distributed via malicious advertising.
Prohibit external FTP connections and blacklist downloads of known
offensive security tools.
All operating systems and applications should be kept updated on a regular
basis. Virtual patching can be considered for protecting legacy systems and
networks. This measure hinders cybercriminals from gaining easy access to
any system through vulnerabilities in outdated applications and software.
Avoid applying updates / patches available in any unofficial channel.
Restrict execution of Power shell /WSCRIPT in an enterprise environment.
Ensure installation and use of the latest version of PowerShell, with
enhanced logging enabled. Script block logging and transcription enabled.
Send the associated logs to a centralized log repository for monitoring and
analysis.
ml
Establish a Sender Policy Framework (SPF) for your domain, which is an
email validation system designed to prevent spam by detecting email
spoofing by which most of the ransomware samples successfully reaches the
corporate email boxes.
Application whitelisting/Strict implementation of Software Restriction
Policies (SRP) to block binaries running from %APPDATA% and %TEMP% paths.
Ransomware sample drops and executes generally from these locations.
Users are advised to disable their RDP if not in use, if required, it
should be placed behind the firewall and users are to bind with proper
policies while using the RDP.
Block the attachments of file types,
exe|pif|tmp|url|vb|vbe|scr|reg|cer|pst|cmd|com|bat|dll|dat|hlp|hta|js|wsf
Consider encrypting the confidential data as the ransomware generally
targets common file types.
Perform regular backups of all critical information to limit the impact of
data or system loss and to help expedite the recovery process. Ideally,
this data should be kept on a separate device, and backups should be stored
offline.
Network segmentation and segregation into security zones - help protect
sensitive information and critical services. Separate administrative
network from business processes with physical controls and Virtual Local
Area Networks.
References

on
dian-conglomerate-fbecf72a
p.md
Severity Rating: HIGH

Software Affected

WebSphere Application Server 9.0
WebSphere Application Server 8.5
WebSphere Application Server 8.0
WebSphere Application Server 7.0
Overview

A Remote code execution vulnerability was reported in IBM Web Sphere
Application Server which could allow a remote attacker to execute arbitrary
code on the target system.

Description

The vulnerability exists in IBM Web Sphere Application Server due to
improper validation of user-supplied input. A remote attacker could exploit
this vulnerability by executing a specially-crafted sequence of serialized
objects over the SOAP connector. 

Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code on the target system.

Solution

Apply appropriate patches as mentioned in the below link: 


Vendor Information

IBM

References

IBM
erver-vulnerable-remote-code-execution-vulnerability-cve-2020-4464

CVE Name
CVE-2020-4464
Severity Rating: HIGH

Software Affected

Windows 10 for 32-bit Systems
Windows 10 for x64-based Systems
Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1607 for x64-based Systems
Windows 10 Version 1709 for ARM64-based Systems
Windows 10 Version 1709 for x64-based Systems
Windows 10 Version 1803 for 32-bit Systems
Windows 10 Version 1803 for ARM64-based Systems
Windows 10 Version 1803 for x64-based Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for ARM64-based Systems
Windows 10 Version 1809 for x64-based Systems
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 2004 for 32-bit Systems
Windows 10 Version 2004 for ARM64-based Systems
Windows 10 Version 2004 for x64-based Systems
Windows 7 for 32-bit Systems Service Pack 1
Windows 7 for x64-based Systems Service Pack 1
Windows 8.1 for 32-bit systems
Windows 8.1 for x64-based systems
Windows RT 8.1
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core
installation)
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core
installation)
Windows Server 2008 R2 for x64-based Systems Service Pack 1
Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core
installation)
Windows Server 2012
Windows Server 2012 (Server Core installation)
Windows Server 2012 R2
Windows Server 2012 R2 (Server Core installation)
Windows Server 2016
Windows Server 2016 (Server Core installation)
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server, version 1903 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
Windows Server, version 2004 (Server Core installation)
Overview

A remote code execution vulnerability has been reported in Microsoft
Windows, which could allow an attacker to gain the same user rights as the
local user.

Description

This vulnerability exists in Microsoft Windows due to incorrect processing
of the ".LNK" file. An attacker could exploit this vulnerability by
presenting to the user a removable drive, or remote share, that contains a
malicious ".LNK" file and an associated malicious binary. When the user
opens this removable drive (or remote share) in Windows Explorer, or any
other application that parses the ".LNK" file, the malicious code will be
executed by the associated binary on the target system. 

Successful exploitation of this vulnerability would allow to gain same user
rights as the local user.

Solution

Apply appropriate fix as mentioned in Microsoft Security Advisory 


Vendor Information

Microsoft

References

Microsoft
- -1421

CVE Name
CVE-2020-1421
Virus Type: Ransomware

It has been reported that a new ransomware, named "Conti ransomware" is
spreading. In its infection stages, threat actors breach the corporate
networks and spread laterally to acquire domain administration privilege
for deploying ransomware. The coding pattern of Conti appears similar to
erstwhile "Ryuk ransomware" version 2 and ransomware note used is also same
as Ryuk had dropped in its earlier attacks. Moreover, the same TrickBot
infrastructure is utilized by both Ryuk and Conti threat actors as part
attacking mechanism. Conti is a human-operated ransomware designed to be
directly controlled by its operator rather than execute automatically by
itself. 

Infection mechanism: 

When starts, Conti executes 146 commands focused on stopping potential
Windows services related to security, backup, database and email solutions.
Then it deletes the Volume Shadow Copies in a unique way and begins
encryption. The ransomware appends the .CONTI extension to encrypted files
and drop a ransom note named CONTI_README.txt in each folder.


When encrypting data, the ransomware uses a unique AES-256 encryption key
per file, which is then encrypted with a bundled RSA-4096 public encryption
key (unique per victim).


Conti ransomware is also special in its selection of encryption targets
that could be local hard drive or network shares, even specific, targeted,
IP addresses via a command-line client. It can be configured to skip
encrypting files on local drives and encrypt data on networked SMB shares.
This may lead to targeted damage and may cause destruction limited to
shares of a server that has no internet capability making it likely
unnoticeable for days or weeks. 

It also supports an "--encrypt_mode" argument to upgrade its encryption
strength. When using "-encrypt_mode local," only the local drives are
encrypted, and when using the "-encrypt_mode network," only the network
shares are encrypted. 

Another notable feature of Conti ransomware is that it utilizes a large no.
of concurrent CPU thread, namely 32 threads for encrypting different files
simultaneously with a very fast speed. However due to this, CPU and disk
utilization goes up causing of machine become sluggish and may serve as an
alarming situation for a user.


Another feature observed that its code abusing "Windows Restart Manager" -
the Windows component that unlocks files before performing an OS restart.
Conti utilizes this component to unlock and shut down app processes so it
can encrypt their respective data. This technique can be phenomenal on
Windows servers where sensitive data is usually managed by a database and
almost always up and running. 

IOC: 

Associated emails:

flapalinta1950@protonmail[dot]com
xersami@protonmail[dot]com
For Metadata for the Conti malware sample, AES-256 public key used for
encryption and another detailed IOC please refer the URL:

Countermeasures and Best practices for prevention:

Users are advised to disable their RDP if not in use, if required, it
should be placed behind the firewall and users are to bind with proper
policies while using the RDP.
All operating systems and applications should be kept updated on a regular
basis. Virtual patching can be considered for protecting legacy systems and
networks. This measure hinders cybercriminals from gaining easy access to
any system through vulnerabilities in outdated applications and software.
Avoid applying updates / patches available in any unofficial channel.
Restrict execution of Power shell /WSCRIPT in an enterprise environment.
Ensure installation and use of the latest version of PowerShell, with
enhanced logging enabled. Script block logging and transcription enabled.
Send the associated logs to a centralized log repository for monitoring and
analysis.
ml
Establish a Sender Policy Framework (SPF) for your domain, which is an
email validation system designed to prevent spam by detecting email
spoofing by which most of the ransomware samples successfully reaches the
corporate email boxes.
Application whitelisting/Strict implementation of Software Restriction
Policies (SRP) to block binaries running from %APPDATA% and %TEMP% paths.
Ransomware sample drops and executes generally from these locations.
Don't open attachments in unsolicited e-mails, even if they come from
people in your contact list, and never click on a URL contained in an
unsolicited e-mail, even if the link seems benign. In cases of genuine URLs
close out the e-mail and go to the organization's website directly through
browser.
Block the attachments of file types,
exe|pif|tmp|url|vb|vbe|scr|reg|cer|pst|cmd|com|bat|dll|dat|hlp|hta|js|wsf
Consider encrypting the confidential data as the ransomware generally
targets common file types.
Perform regular backups of all critical information to limit the impact of
data or system loss and to help expedite the recovery process. Ideally,
this data should be kept on a separate device, and backups should be stored
offline.
Network segmentation and segregation into security zones - help protect
sensitive information and critical services. Separate administrative
network from business processes with physical controls and Virtual Local
Area Networks.
Install ad blockers to combat exploit kits such as Fallout that are
distributed via malicious advertising.
References

- -of-being-ryuks-successor/
eads-for-blazing-fast-encryption/
Severity Rating: High

Software Affected

·         JBoss Enterprise Application Platform 7.3 for RHEL 8 x86_64

·         JBoss Enterprise Application Platform 7.3 for RHEL 7 x86_64

·         JBoss Enterprise Application Platform 7.3 for RHEL 6 x86_64

·         JBoss Enterprise Application Platform 6.4 for RHEL 7 x86_64

·         JBoss Enterprise Application Platform 6.4 for RHEL 6 x86_64

·         JBoss Enterprise Application Platform 6 for RHEL 7 x86_64

·         JBoss Enterprise Application Platform 6 for RHEL 6 x86_64

·         Keycloak versions prior to 11.0.0



Overview

A vulnerability has been reported in Red Hat JBoss Enterprise Application
Platform which could be exploited by a remote attacker to execute arbitrary
code on the target system.

Description

This vulnerability exists in Keycloak in Red Hat JBoss Enterprise
Application Platform due to lack of checks in ObjectInputStream, A remote
attacker could exploit this vulnerability by injecting crafted serialized
Java Objects resulting in deserialization in a privileged context.



Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code on the target system.



Solution

Apply appropriate updates as mentioned in the vendor advisory




Vendor Information

Red Hat





References

Red Hat





CVE Name

CVE-2020-1714
Severity Rating: High

Software Affected

·         Apple iOS and iPadOS versions prior to 13.6

Overview

Multiple vulnerabilities have been reported in Apple iOS and iPadOS which
could allow a remote attacker to execute arbitrary code with kernel
privileges, cause denial of service conditions, access sensitive
information, bypass security restrictions, hijack VPN connections or
perform cross site scripting attacks on a targeted system.

Description

Multiple vulnerabilities exist in Apple iOS and iPadOS due to out-of-bounds
read and write errors, multiple memory corruption issues, improper input
validation, improper state management, improper access restrictions,
insufficient verification and checks, buffer overflow error, use after free
error, improper escaping and other logical errors in Audio,
AVEVideoEncoder, Bluetooth, CoreFoundation, Crash Reporter, GeoServices,
iAP, ImageIO, Kernel, Mail, Messages, Model I/O, Safari Login AutoFill,
Safari Reader, WebKit, WebKit Page Loading, WebKit Web Inspector and Wi-Fi
components of the software.

Successful exploitation of these vulnerabilities could allow the attacker
to execute arbitrary code with kernel privileges, cause denial of service
conditions, access sensitive information, bypass security restrictions,
hijack VPN connections or perform cross site scripting attacks on the
targeted system. 


Solution          

Apply appropriate updates mentioned in the Apple security updates

Vendor Information

Apple


References

CISecurity

cts-could-allow-for-arbitrary-code-execution_2020-098/



CVE Name

CVE-2020-9888
CVE-2020-9889
CVE-2020-9890

CVE-2020-9891

CVE-2020-9907

CVE-2020-9931

CVE-2020-9934

CVE-2020-9865

CVE-2020-9933

CVE-2020-9914

CVE-2020-9936

CVE-2020-9923

CVE-2019-14899

CVE-2020-9909

CVE-2019-19906

CVE-2020-9885

CVE-2020-9878

CVE-2020-9903

CVE-2020-9911

CVE-2020-9894

CVE-2020-9915

CVE-2020-9893

CVE-2020-9895

CVE-2020-9925

CVE-2020-9910

CVE-2020-9916

CVE-2020-9862

CVE-2020-9918

CVE-2020-9917

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top