zerofox logo
Advisories

ZeroFox Daily Intelligence Brief - July 10, 2023

|by Alpha Team

banner image

ZeroFox Daily Intelligence Brief - July 10, 2023

ZeroFox Intelligence collects, curates, and analyzes information derived from open and proprietary sources. Please find today’s daily roundup to give you and your clients an advantage over the adversary.

Brief Highlights

  • Further Vulnerabilities Patched in MOVEit Transfer Software
  • Mastodon Releases Patch to Address Critical Vulnerabilities
  • CISA Warns Govt. Agencies to Patch Android Driver At Risk of Active Exploitation
  • Vulnerabilities: CVE-2023-20773 and CVE-2023-20766
  • Exploits: CVE-2020-29372 and CVE-2016-0075
  • Breaches: Credit Card Data Breach: 2023-7-8 and BreachForums/XSS: EvgexaСraft Data Breach

Further Vulnerabilities Patched in MOVEit Transfer Software

Progress Software has announced the release of a service pack to address three newly disclosed vulnerabilities (CVE-2023-36934, CVE-2023-36932, and CVE-2023-36933) in MOVEit Transfer. A threat actor could exploit these vulnerabilities to gain unauthorized access to the database and obtain sensitive information without requiring credentials or to cause unexpected shutdowns. However, no active exploitation has been reported thus far.

Mastodon Releases Patch to Address Critical Vulnerabilities

Decentralized social network Mastodon has released a critical security update to address several vulnerabilities. One of them, "TootRoot" (CVE-2023-36460), enabled hackers to exploit the media attachments feature, potentially creating or overwriting files. This poses a significant threat as it allows DoS attacks and arbitrary code execution. Four other vulnerabilities were fixed, including one (CVE-2023-36459) that enabled HTML injection into OEmbed preview cards, potentially leading to cross-site scripting attacks.

CISA Warns Govt. Agencies to Patch Android Driver At Risk of Active Exploitation

CISA has ordered federal agencies to patch a high-severity privilege escalation flaw affecting the Arm Mali GPU kernel driver. The flaw (CVE-2021-29256) allows attackers to escalate to root privileges or gain access to sensitive information on targeted Android devices. Google has also patched two other exploited vulnerabilities, including a memory leak flaw in Arm Mali GPU driver and an integer overflow bug in Google's Skia graphics library. Federal agencies have until July 28, 2023, to secure their devices against the CVE-2021-29256 vulnerability.

THREAT ACTIVITY: INITIAL-ACCESS BROKERS, DATA BROKERS, AND HACKTIVISTS

VULNERABILITIES

  • CVE-2023-20773 - There is a possible escalation of privilege due to a missing permission check.
  • CVE-2023-20766 - In gps, there is a possible out of bounds write due to a missing bounds check.

EXPLOITS

  • CVE-2020-29372 - IORING_OP_MADVISE races with coredumping
  • CVE-2016-0075 - Microsoft Windows - DeviceApi CMApi PiCMOpenDeviceKey Arbitrary Registry Key Write Privilege Escalation

BREACHES

Tags: DIB, tlp:green