Threat Advisory

Microsoft Patch Fixes 3 Zero-Day Flaws

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Microsoft has patched a vulnerability, designated as CVE-2023-24932, which allowed threat actors to bypass the Secure Boot security feature. This flaw enabled an attacker with physical access or administrative privileges to install the BlackLotus UEFI bootkit. By exploiting the vulnerability, the attacker could install a compromised boot policy. UEFI bootkits are a type of malware that resides in the system firmware and evades detection from security software operating within the OS. This is possible because the malware loads during the initial boot sequence. Since October 2022, a threat actor has been selling the BlackLotus bootkit on underground forums and continuously enhancing its capabilities. For instance, in March, researchers reported that the malware had been updated to bypass Secure Boot, even on fully patched Windows 11 systems.[/subscribe_to_unlock_form]

Summary:

Microsoft has patched a vulnerability, designated as CVE-2023-24932, which allowed threat actors to bypass the Secure Boot security feature. This flaw enabled an attacker with physical access or administrative privileges to install the BlackLotus UEFI bootkit. By exploiting the vulnerability, the attacker could install a compromised boot policy. UEFI bootkits are a type of malware that resides in the system firmware and evades detection from security software operating within the OS. This is possible because the malware loads during the initial boot sequence. Since October 2022, a threat actor has been selling the BlackLotus bootkit on underground forums and continuously enhancing its capabilities. For instance, in March, researchers reported that the malware had been updated to bypass Secure Boot, even on fully patched Windows 11 systems.[emaillocker id="1283"]

Microsoft has addressed a critical vulnerability, identified as CVE-2023-29325, in Microsoft Outlook that affects Windows OLE (Object Linking and Embedding) functionality. This flaw can be leveraged by attackers through specially crafted emails. According to researchers’ advisory, in an email attack scenario, an attacker could send a malicious email to a target, who would be vulnerable if using an affected version of Microsoft Outlook. The vulnerability can be exploited either by the victim opening the malicious email or by the Outlook application previewing the email. Successful exploitation of the flaw could enable the attacker to execute remote code on the victim's machine. However, it is important to note that the attacker must win a race condition and perform additional actions to successfully exploit the vulnerability.

Microsoft has addressed a critical privilege escalation vulnerability, known as CVE-2023-29336, in the Win32k Kernel driver. This vulnerability allows an attacker to elevate their privileges to the highest level in Windows, known as SYSTEM. By exploiting this vulnerability, an attacker can gain full control over the targeted system. According to researchers’ advisory, the bug is actively being exploited, although specific details about the exploitation techniques are not disclosed.

Recommendations:

References:

The following reports contain further technical details:

https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2023-patch-tuesday-fixes-3-zero-days-38-flaws/
https://thehackernews.com/2023/05/microsofts-may-patch-tuesday-fixes-38.html

[/emaillocker]
crossmenu