Pinewood Security Bulletin – Critical vulnerability in Confluence Server and Confluence Data Center

For English, see below.

Beschrijving

Er bevindt zich een kritieke kwetsbaarheid (CVE-2023-22515) in Atlassian Confluence Server en Atlassian Confluence Data Center waarvoor recent aanvalscode is gepubliceerd. De kwetsbaarheid maakt het mogelijk om een nieuw beheeraccount aan te maken en toegang te krijgen tot Confluence.

Op basis van de publiek beschikbare aanvalscode is de inschatting van Pinewood dat de kwetsbaarheid eenvoudig te gebruiken is. Hiermee is de kans groot dat kwetsbare en via het internet bereikbare installaties via deze kwetsbaarheid gecompromitteerd worden of al gecompromitteerd zijn.

Er zijn berichten dat een statelijke actor de kwetsbaarheid op beperkte schaal gebruikt heeft om toegang te krijgen tot vertrouwelijke informatie in Confluence, voordat de beveiligingsupdate beschikbaar gemaakt is.

Kwetsbare versies

De onderstaande versies van Confluence Server en Data Center bevatten de genoemde kwetsbaarheid:

  • 8.0.0 t/m 8.0.4
  • 8.1.0 t/m 8.1.4
  • 8.2.0 t/m 8.2.3
  • 8.3.0 t/m 8.3.2
  • 8.4.0 t/m 8.4.2
  • 8.5.0 t/m 8.5.1

Versies ouder dan 8.0.0 zijn niet kwetsbaar.

Versies ouder dan 7.15 zijn End-of-Life (EOL).

Cloud-installaties, herkenbaar aan het atlassian.net-domein, zijn niet (meer) kwetsbaar.

Oplossingen en tijdelijke mitigaties

Atlassian heeft onderstaande versies van Confluence Server en Data Center uitgebracht om de betreffende kwetsbaarheid te verhelpen:

  • 8.3.3 (en nieuwer)
  • 8.4.3 (en nieuwer)
  • 8.5.2 (en nieuwer)

Voor zover bekend is de kwetsbaarheid (nog) niet opgelost is de laatste update binnen de 8.0, 8.1 en 8.2 versielijnen.

Detectie van mogelijk misbruik

Het installeren van een nieuwe versie zal een eventuele compromittatie niet ongedaan maken. Controleer daarom altijd op signalen van succesvol misbruik, zeker als de server bereikbaar is vanaf het internet.

Atlassian geeft aan dat onderstaande events een indicatie zijn van een eerdere succesvolle aanval:

  • Onverwachte/onbekende gebruikers in de groep confluence-administrators.
  • Onverwachte/onbekende nieuw aangemaakte gebruikers.
  • Verzoeken voor /setup/*.action die te zien zijn in de access logs.
  • De aanwezigheid van /setup/setupadministrator.action in een exception message in het logbestand atlassian-confluence-security.log in de home-directory van Confluence.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center (SOC). Het Pinewood SOC is bereikbaar via +31 15 251 36 33 en via soc@pinewood.nl.

===== ENGLISH =====

Description

There is a critical vulnerability (CVE-2023-22515) in Atlassian Confluence Server and Atlassian Confluence Data Center for which attack code was recently published. The vulnerability creates a new admin account and gives access to information in Confluence.

Based on the public Proof-of-Concept (PoC) code, Pinewood estimates that the vulnerability is easy to exploit. With this, there is a high probability that vulnerable and Internet-accessible installations will be compromised via this vulnerability or have already been compromised.

There are reports that a state actor used the vulnerability on a limited scale to access confidential information in Confluence before the security update was made available.

Vulnerable versions

The following versions of Confluence Server and Data Center contain the listed vulnerability:

  • 8.0.0 up to and including 8.0.4
  • 8.1.0 up to and including 8.1.4
  • 8.2.0 up to and including 8.2.3
  • 8.3.0 up to and including 8.3.2
  • 8.4.0 up to and including 8.4.2
  • 8.5.0 up to and including 8.5.1

Versions older than 8.0.0 are not vulnerable.

Versions older than 7.15 are End-of-Life (EOL).

Cloud installations, identified by the atlassian.net domain, are not vulnerable (anymore).

Solutions and workarounds

Atlassian has released the below versions of Confluence Server and Data Center to fix the affected vulnerability:

  • 8.3.3 (and newer)
  • 8.4.3 (and newer)
  • 8.5.2 (and newer)

As far as we know, the vulnerability has not (yet) been fixed is the latest update within the 8.0, 8.1 and 8.2 version lines.

Detection of possible misuse

Installing a new version will not undo any compromise. Therefore, always check for signs of successful abuse, especially if the server is accessible from the internet.

Atlassian states that the events below are indicative of a previous successful attack:

  • Unexpected/unknown users in the confluence-administrators group.
  • Unexpected/unknown newly created users.
  • Requests for /setup/*.action showing up in the access logs.
  • The presence of /setup/setupadministrator.action in an exception message in the log file atlassian-confluence-security.log in the home directory of Confluence.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center (SOC). The Pinewood SOC can be contacted at +31 15 750 1331 and via soc@pinewood.nl.

Pinewood Security Bulletin – Overview of F5 vulnerabilities (October 2023)

For English, see below.

Beschrijving

Vandaag heeft F5 Networks het Overview of F5 vulnerabilities (October 2023) uitgebracht [LINK].

De hooggekwalificeerde (CVSSv3 score ‘High’ of ‘Critical’) kwetsbaarheden zijn hieronder samengevat.

Tenzij anders vermeld, zijn onderstaande kwetsbaarheden van toepassing op TMOS 13.x, 14.x, 15.x, 16.x en 17.x. Potentieel zijn ook oudere TMOS-versies kwetsbaar (omdat deze versies al langere tijd niet meer ondersteund worden, doet F5 geen uitspraak over de kwetsbaarheid van deze versies).

CVSSv3 score ‘High’/’Critical’

  • K000135689: BIG-IP Configuration utility vulnerability CVE-2023-41373 [LINK]

BIG-IP in appliance mode: CVSSv3 score: 9.9

BIG-IP in normale mode: CVSSv3 score: 8.8

Hiervoor moet eerst met succes ingelogd worden op de Configuration Utility (= de web-interface).

Vanuit de Configuration Utility kunnen dan willekeurige commando’s op de BIG-IP worden uitgevoerd. Administrators met ‘Advanced Shell’ toegang kunnen dat toch al. Dit heeft dus impact op gebruikers die zelf geen toegang hebben tot de ‘Advanced Shell’ CLI.

Niet kwetsbare versies: 14.1.5.6, 15.1.10.2, 16.1.4.1, 17.1.0.3.

Pinewood adviseert de management-toegang tot de BIG-IP te beperken tot vertrouwde netwerken en gebruikers. Wanneer gebruik gemaakt wordt van Appliance Mode [LINK], zal een upgrade gewenst zijn.

 

  • K41072952: BIG-IP Appliance mode external monitor vulnerability CVE-2023-43746 [LINK]

BIG-IP in appliance mode: CVSSv3 score: 8.7

BIG-IP in normale mode: niet kwetsbaar

Deze kwetsbaarheid staat het toe om de ‘appliance mode’ beveiliging te omzeilen.

Niet kwetsbare versies: 15.1.9, 16.1.4, 17.1.0.

Pinewood adviseert de management-toegang tot de BIG-IP te beperken tot vertrouwde netwerken en gebruikers. Wanneer gebruik gemaakt wordt van Appliance Mode [LINK], zal een upgrade gewenst zijn.

  • K29141800: Multi-blade VIPRION Configuration utility session cookie vulnerability CVE-2023-40537 [LINK]

CVSSv3 score: 8.1

Deze kwetsbaarheid betreft het niet correct uitloggen van een geauthentiseerde gebruiker in de Configuration Utility (= de web-interface) op multi-blade VIPRION-omgevingen.

Niet kwetsbare versies: 15.1.9, 16.1.4, 17.1.0.

Pinewood adviseert de management-toegang tot de BIG-IP/VIPRION te beperken tot vertrouwde netwerken en gebruikers.

  • K000136185: BIG-IP Edge Client for macOS vulnerability CVE-2023-43611 [LINK]

CVSSv3 score: 7.8

Deze kwetsbaarheid betreft de BIG-IP Edge Client (VPN) installer voor macOS.

Niet kwetsbare versies: Edge Client 7.2.4.4

  • K000133467: BIG-IP HTTP/2 vulnerability CVE-2023-40534 [LINK]

CVSSv3 score: 7.5

Deze kwetsbaarheid geldt wanneer aan een virtual server een HTTP/2 client profiel gekoppeld is en de MRF Router optie is ingeschakeld en een iRule gebruik maakt van het HTTP_REQUEST event (of een Local Traffic Policy aan de virtual server gekoppeld is). In dat specifieke geval kan TMM crashen (DoS).

Niet kwetsbare versies: 13.x, 14.x, 15.x, 16.1.4.1+Hotfix, 17.1.0.3+Hotfix.

De MRF Router optie is heel specifiek en niet standaard ingeschakeld, waardoor de kwetsbaarheid dan ook niet van toepassing is.

  • K000134652: BIG-IP TCP profile vulnerability CVE-2023-40542 [LINK]

CVSSv3 score: 7.5

Deze kwetsbaarheid geldt wanneer aan een virtual server een TCP-profiel gekoppeld is waarin de ‘Verified Accept’ optie is ingeschakeld.

Niet kwetsbare versies: 15.1.9, 16.1.4, 17.1.0.

‘Verified Accept’ is een heel specifieke instelling, welke standaard is uitgeschakeld, waardoor de kwetsbaarheid dan ook niet van toepassing is.

  • K000132420: BIG-IP IPsec vulnerability CVE-2023-41085 [LINK]

CVSSv3 score: 7.5

Deze kwetsbaarheid geldt wanneer IPsec is geconfigureerd op een virtual server. TMM kan dan crashen (DoS).

Niet kwetsbare versies: 15.1.9, 16.1.4, 17.1.0.

  • K000135040: BIG-IP Edge Client for macOS vulnerability CVE-2023-5450 [LINK]

CVSSv3 score: 7.3

Deze kwetsbaarheid betreft de BIG-IP Edge Client (VPN) installer voor macOS.

Niet kwetsbare versies: Edge Client 7.2.4.5

  • K26910459: BIG-IP iControl REST vulnerability CVE-2023-42768 [LINK]

CVSSv3 score: 7.2

Hiervoor moet eerst met succes ingelogd worden op de Configuration Utility (= de web-interface). Dit betreft een privilege escalation voor gebruikers die eerst de rol ‘Administrator’ hadden en welke daarna is verlaagd tot een niet-Administrator rol.

Niet kwetsbare versies: 15.1.9, 16.1.4, 17.1.0.

Pinewood adviseert de management-toegang tot de BIG-IP te beperken tot vertrouwde netwerken en gebruikers.

Oplossingen en tijdelijke mitigaties

Controleer eerst of een kwetsbaarheid van toepassing is. Sommige kwetsbaarheden zijn slechts in heel specifieke gevallen van toepassing. Bepaal daarna of een work-around beschikbaar is en pas deze toe. Indien gewenst, voer een upgrade uit naar een niet-kwetsbare versie.

Meer informatie

Zie de [LINK] referenties hierboven.

Managed Security Services (MSS) klanten

Als u een Pinewood Managed Security Services contract heeft is er geen actie nodig. Pinewood neemt de benodigde maatregelen om uw omgeving te beschermen tegen deze kwetsbaarheden.

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met de Pinewood Servicedesk. De servicedesk is bereikbaar via +31 15 251 36 33 en via support@pinewood.nl.

===== ENGLISH =====

Description

Today, F5 Networks has released: Overview of F5 vulnerabilities (October 2023) [LINK].

Vulnerabilities with a CVSSv4 score ‘High’ or ‘Critical’ are summarised below.

Unless mentioned otherwise, the vulnerabilities affect all TMOS versions 13.x, 14.x, 15.x, 16.x, and 17.x. Older versions of TMOS are potentially vulnerable as well (F5 does not mention these old, long out of support, versions anymore).

CVSSv3 score ‘High’/’Critical’

  • K000135689: BIG-IP Configuration utility vulnerability CVE-2023-41373 [LINK]

BIG-IP in appliance mode: CVSSv3 score: 9.9

BIG-IP in normal mode: CVSSv3 score: 8.8

This vulnerability requires an attacker to first successfully login into the Configuration Utility (= web interface).

Then, using the vulnerability, the attacker can execute commands on the BIG-IP system.

Note that Administrators with ‘Advanced Shell’ privileges are already able to do so. Hence, this vulnerability mainly affects customers with non-administrative users on the BIG-IP that do not have ‘Advanced Shell’ access already.

Non-vulnerable versions: 14.1.5.6, 15.1.10.2, 16.1.4.1, 17.1.0.3.

Pinewood recommends restricting access to the management network and to the BIG-IP itself to trusted users only. When using Appliance Mode [LINK], an upgrade is recommended.

  • K41072952: BIG-IP Appliance mode external monitor vulnerability CVE-2023-43746 [LINK]

BIG-IP in appliance mode: CVSSv3 score: 8.7

BIG-IP in normal mode: not vulnerable

When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing BIG-IP external monitor on a BIG-IP system.

Non-vulnerable versions: 15.1.9, 16.1.4, 17.1.0.

Pinewood recommends restricting access to the management network and to the BIG-IP itself to trusted users only. When using Appliance Mode [LINK], an upgrade is recommended.

  • K29141800: Multi-blade VIPRION Configuration utility session cookie vulnerability CVE-2023-40537 [LINK]

CVSSv3 score: 8.1

An authenticated user’s session cookie may remain valid for a limited time after logging out from the BIG-IP Configuration utility (= web interface) on a multi-blade VIPRION platform.

Non-vulnerable versions: 15.1.9, 16.1.4, 17.1.0.

Pinewood recommends restricting access to the management network and to the BIG-IP itself to trusted users only.

  • K000136185: BIG-IP Edge Client for macOS vulnerability CVE-2023-43611 [LINK]

CVSSv3 score: 7.8

he BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process.

Non-vulnerable versions: Edge Client 7.2.4.4

  • K000133467: BIG-IP HTTP/2 vulnerability CVE-2023-40534 [LINK]

CVSSv3 score: 7.5

When a client-side HTTP/2 profile and the HTTP MRF Router option are enabled for a virtual server, and an iRule using the HTTP_REQUEST event or Local Traffic Policy are associated with the virtual server, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate.

Non-vulnerable versions: 13.x, 14.x, 15.x, 16.1.4.1+Hotfix, 17.1.0.3+Hotfix.

The MRF Router option is uncommon to use and disabled by default (in which case the vulnerability is not applicable).

  • K000134652: BIG-IP TCP profile vulnerability CVE-2023-40542 [LINK]

CVSSv3 score: 7.5

When TCP Verified Accept is enabled on a TCP profile that is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization.

Non-vulnerable versions: 15.1.9, 16.1.4, 17.1.0.

The ‘Verified Accept’ option is uncommon to use and disabled by default (in which case the vulnerability is not applicable).

  • K000132420: BIG-IP IPsec vulnerability CVE-2023-41085 [LINK]

CVSSv3 score: 7.5

When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate.

Non-vulnerable versions: 15.1.9, 16.1.4, 17.1.0.

  • K000135040: BIG-IP Edge Client for macOS vulnerability CVE-2023-5450 [LINK]

CVSSv3 score: 7.3

An insufficient verification of data vulnerability exists in BIG-IP Edge Client Installer on macOS that may allow an attacker elevation of privileges during the installation process.

Non-vulnerable versions: Edge Client 7.2.4.5

  • K26910459: BIG-IP iControl REST vulnerability CVE-2023-42768 [LINK]

CVSSv3 score: 7.2

When a non-admin user has been assigned an administrator role via an iControl REST PUT request and later the user’s role is reverted back to a non-admin role via the Configuration utility, tmsh, or iControl REST, the BIG-IP non-admin user can still access the iControl REST admin resource.

Non-vulnerable versions: 15.1.9, 16.1.4, 17.1.0.

Pinewood recommends restricting access to the management network and to the BIG-IP itself to trusted users only.

Solutions and workarounds

First determine if a vulnerability is applicable to your environment and configuration. Most vulnerabilities only apply to specific configurations. Next, consider if a work-around can be applied. If required, upgrade the system to a version that is not vulnerable.

More information

Please refer to the [LINK] references above.

Managed Security Services (MSS) customers

If you have a Pinewood Managed Security Services contract, no action is required. Pinewood takes the necessary measures to protect your environment from these vulnerabilities.

Questions

For questions about this security bulletin, please contact the Pinewood Service desk. The service desk can be contacted at +31 15 251 36 33 and via support@pinewood.nl.

Pinewood Security Bulletin – End of support F5 TMOS 14.1

For English, see below.

Beschrijving

Dit bulletin heeft betrekking op de BIG-IP- en VIPRION-producten van F5 Networks.

Op 31 december 2023 bereikt de TMOS 14.1.x versie de ‘End-of-Technical-Support’ (EoTS) en ‘End-of-Software-Development’ (EoSD) fase. Dit geldt voor alle BIG-IP hardware appliances, de BIG-IP Virtual Editions (BIG-IP VE) en voor het VIPRION-platform.

Dit betekent dat:

  • EoTS: F5 no longer provides technical support services, such as troubleshooting or configuration advice.
  • EoSD: F5 no longer develops maintenance releases for a software product or software product version. F5 does not release any software product fixes, including fixes for bugs or CVEs, using maintenance or EHF releases.

Ondersteuning vanuit Pinewood voor EoTS- en EoSD-producten vindt plaats op basis van best effort voor klanten met een support contract.

Klanten met een Managed Security Services contract zijn inmiddels benaderd door Pinewood.

Advies

De meest recente versie van TMOS is 17.1. Deze versie is relatief nieuw en Pinewood is nog terughoudend met het inzetten van deze versie voor productie-omgevingen.

Deze versie heeft support vanuit F5 tot 31 maart 2027.

Pinewood adviseert te upgraden naar de meest recente versie van TMOS 16.1 (momenteel 16.1.4.1).

Deze versie heeft support vanuit F5 tot 31 juli 2025.

Voor BIG-IP VE geldt dat deze licenties geldig zijn voor een bepaalde reeks van TMOS-versies. Met name de wat oudere ‘V13’-licenties kunnen ingezet worden tot maximaal TMOS 15.1. In dat geval adviseert Pinewood te upgraden naar de meest recente versie van TMOS 15.1 (momenteel 15.1.10.2).

Deze versie heeft support vanuit F5 tot 31 december 2014.

In alle gevallen geldt dat een geldig F5 support contact nodig is.

Meer informatie

Managed Security Services (MSS) klanten

Als u een Pinewood Managed Security Services contract heeft is er geen actie nodig. Pinewood neemt de benodigde maatregelen om uw omgeving te beschermen tegen deze kwetsbaarheden.

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met de Pinewood Servicedesk. De servicedesk is bereikbaar via +31 15 251 36 33 en via support@pinewood.nl.

===== ENGLISH =====

Description

This bulletin concerns the F5 Network products: BIG-IP hardware appliances, BIG-IP Virtual Editions (VE), and the VIPRION chassis hardware.

TMOS 14.1.x will reach both ‘End-of-Technical-Support’ (EoTS) and ‘End-of-Software-Development’ (EoSD) on December 31, 2023. This applies to all BIG-IP hardware appliances, the BIG-IP Virtual Editions (BIG-IP VE) and the VIPRION chassis-based blades.

This implies that:

  • EoTS: F5 no longer provides technical support services, such as troubleshooting or configuration advice.
  • EoSD: F5 no longer develops maintenance releases for a software product or software product version. F5 does not release any software product fixes, including fixes for bugs or CVEs, using maintenance or EHF releases.

Support by Pinewood for customers with a valid support contact, regarding EoTS and EoSD products, can only be supplied on a best effort basis.

Pinewood has already informed customers with a Managed Security Services contract.

Recommendations

TMOS 17.1 is the most recent version of TMOS. However, this version is relatively new. Pinewood is still hesitant to use this version for production environments.

Support for TMOS 17.1 ends on March 31, 2027.

Pinewood recommends upgrading to the most recent version of TMOS 16.1 (currently: 16.1.4.1).

Support for TMOS 16.1 ends on July 31, 2025.

BIG-IP VE licenses are only valid for a fixed range of TMOS versions. In particular the older ‘V13’ VE licenses support TMOS 15.1 as the highest version. In this case Pinewood recommends upgrading to the most recent version of TMOS 15.1 (currently: 15.1.10.2).

Support for TMOS 15.1 ends on December 31, 2024.

A valid F5 support contract is required to obtain support from F5 Networks.

More information

Managed Security Services (MSS) customers

If you have a Pinewood Managed Security Services contract, no action is required. Pinewood takes the necessary measures to protect your environment from these vulnerabilities.

Questions

For questions about this security bulletin, please contact the Pinewood Service desk. The service desk can be contacted at +31 15 251 36 33 and via support@pinewood.nl.

Pinewood Security Bulletin – Account compromise activity

For English, see below.

Beschrijving

De afgelopen tijd ziet het Pinewood Security Operations Center (SOC) dat aanvallers er regelmatig in slagen om accounts binnen de Microsoft cloudomgevingen van organisaties over te nemen. De Microsoft cloud is populair, en het is dan ook geen verrassing dat aanvallers zeer geïnteresseerd zijn in de accounts die zich hierin bevinden (geconfigureerd in Microsoft Entra ID, voorheen Azure AD). Het succesvol overnemen van een account kan grote consequenties hebben. Immers, het verkrijgen van toegang tot een dergelijk account stelt een aanvaller in staat om bijvoorbeeld malafide e-mails uit naam van de eigenaar te versturen (Exchange Online) en om vertrouwelijke bestanden in te zien (SharePoint/OneDrive). Verschillende vragen komen dan ook naar boven: hoe kan dit gebeuren, hoe kun je het detecteren, wat gebeurt er na een succesvolle aanval, wat moet je doen als het misgaat en wat kun je doen om het te voorkomen?

Hoe kan dit gebeuren?

Bij vrijwel alle incidenten die het Pinewood SOC de afgelopen tijd heeft gezien, startte een succesvolle inbraak op een account met een zogenoemde Actor-in-the-Middle aanval, kortweg AitM-aanval. Een AitM-aanval is vergelijkbaar met een traditionele phishingaanval, met het verschil dat de aanvaller de gegevens die het slachtoffer invoert op een phishingwebsite niet alleen verzamelt, maar óók direct ter verificatie doorstuurt naar Microsoft. Daardoor krijgt het slachtoffer bijvoorbeeld ook gewoon een verzoek te zien in zijn/haar Authenticator app om de inlogactiviteit te bevestigen. Zodra het slachtoffer dit heeft gedaan, beschikt de aanvaller niet alleen over de gebruikersnaam en wachtwoord van het slachtoffer, maar ook over een session token én een refresh token. Met deze tokens kan de aanvaller zich toegang blijven verschaffen tot het account van het slachtoffer (standaard gedurende 90 dagen), zonder dat de aanvaller daarvoor opnieuw hoeft in te loggen.

Hoe kun je het detecteren?

Het detecteren van malafide inlogpogingen op een account kan vrij complex zijn. Gelukkig levert Microsoft binnen Entra ID Protection diverse alarmen die helpen om een mogelijke inbraak op een account te detecteren. Het belangrijkste alarm hierbij is Atypical travel: volgens de beschrijving van Microsoft gaat dit alarm af wanneer een gebruiker vanaf twee geografisch verschillende locaties inlogt, waarbij minstens één van deze locaties atypisch is voor de gebruiker. Stel bijvoorbeeld dat een gebruiker normaal gesproken altijd inlogt vanaf zijn thuisnetwerk en vanaf het netwerk van zijn werkgever, terwijl de gebruiker nu plotseling inlogt vanaf een adres in Nigeria. Dit is typisch een situatie die een atypical travel alarm triggert en wat een indicatie vormt dat een aanvaller mogelijk misbruik maakt van het account van de gebruiker.

Natuurlijk bestaan er meer manieren om inbraak op een account te detecteren (en meer manieren om op een account in te breken). Het Pinewood SOC heeft de afgelopen maanden dan ook diverse aanvullende detectieregels geïmplementeerd die moeten helpen om malafide gebruik van een account in een zo’n vroeg mogelijk stadium vast te stellen.

Wat gebeurt er na een succesvolle aanval?

Nadat een aanvaller succesvol toegang weet te krijgen tot het account van een slachtoffer, kunnen er allerlei verschillende activiteiten volgen. Veel is hierbij afhankelijk van de intenties van de aanvaller. Om een idee te geven, zijn hier wat mogelijke scenario’s:

  • De aanvaller registreert een nieuw verificatiemechanisme zodat hij in staat is om op het account in te blijven loggen, zelfs als de tokens die hij heeft bemachtigd niet langer meer geldig zijn.
  • De aanvaller verstuurt uit naam van het slachtoffer phishing e-mails naar een lijst aan bekende contacten van het slachtoffer. Hiermee probeert hij ook de accounts van andere slachtoffers over te nemen. De kans dat nieuwe slachtoffers geraakt worden door een dergelijke phishing e-mail is groot, aangezien ze bekend zijn met de verzender en veelal geen argwaan zullen hebben bij het aanklikken van links die zich in de e-mail bevinden.
  • De aanvaller monitort de e-mails die het slachtoffer uitwisselt, in de hoop dat er een conversatie gaat plaatsvinden over een grote betaling. Op dat moment breekt de aanvaller in op de conversatie en zal hij bijvoorbeeld een bericht sturen om aan te geven dat het rekeningnummer van de organisatie is veranderd. Aangezien de andere partij “gewoon” een antwoord ziet op een e-mail binnen een bestaande e-mailconversatie, is de kans groot dat zij de wijziging in het rekeningnummer klakkeloos overneemt en een groot geldbedrag op de rekening van de aanvaller terechtkomt.

Wat moet je doen als het misgaat?

Op het moment dat een account in handen van een aanvaller valt, is het allereerst van groot belang om dit zo snel mogelijk vast te stellen. Het spreekt voor zich dat de schade het kleinst is als de aanvaller al snel weer de toegang tot een account kwijtraakt. Na het vaststellen van misbruik van een account raden wij aan om standaard een aantal stappen uit te voeren:

  1. Schakel het account in eerste instantie uit (disable account) zodat de aanvaller geen gebruik meer kan maken van het account. Verklaar tevens direct alle refresh tokens die aan het account hangen ongeldig zodat de aanvaller ook daar geen gebruik meer van kan maken.
  2. Ga ervanuit dat de aanvaller volledige controle heeft over de authenticatie-informatie van de gebruiker. Reset daarom het wachtwoord én de verificatiemethoden (MFA) van de gebruiker. Controleer of alle voorgaande MFA-methoden van de gebruiker zijn verwijderd.
  3. Het is bekend dat aanvallers na een succesvolle inbraak op een account ook regelmatig mail forwarding rules aanmaken zodat zij toegang blijven houden tot de e-mails van een gebruiker, zelfs als zij de controle over het account zelf zijn kwijtgeraakt. Controleer daarom altijd alle mailbox rules en mailbox forwarding rules die op het account zijn geconfigureerd.
  4. In sommige gevallen slaagt een aanvaller er zelfs in om een eigen apparaat (device) te registreren op naam van de gebruiker welke vervolgens vertrouwd wordt. Controleer daarom ook altijd of de lijst aan “enrolled devices” valide is.
  5. Controleer tot slot alle activiteiten die vanuit het account zijn uitgevoerd vanaf het moment dat dit account in handen van de aanvaller viel. Maak hiervoor gebruik van de uitgebreide audit-functionaliteiten die Microsoft biedt.

Hoe kun je het voorkomen?

Het is cliché, maar voorkomen blijft altijd beter dan genezen. Er zijn verschillende manieren waarop een organisatie succesvolle aanvallen kan voorkomen. Wij raden dan ook aan nog eens kritisch naar de inrichting van de Microsoft-tenant van de organisatie te kijken en daar waar mogelijk verbeteringen door te voeren. Ga er daarnaast vanuit dat een aanvaller er altijd in kan blijven slagen om een account over te nemen en dat een goede detectie van malafide activiteiten op accounts daarom een essentieel vangnet blijft.

Multifactor-authenticatie

Het spreekt tegenwoordig voor zich dat multifactor-authenticatie standaard moet zijn. Het beschermen van een account op basis van alleen een gebruikersnaam en wachtwoord is uitermate onveilig en zal men alleen op basis van hele stringente restricties mogen toestaan (bijvoorbeeld gebruik van een serviceaccount vanuit één IP-adres). Daarnaast biedt Microsoft tegenwoordig de mogelijkheid tot “MFA number matching”, waarbij de gebruiker een code moet invoeren bij het aanroepen van de multifactor-authenticatie. Uiteraard raden wij het gebruik hiervan sterk aan (sinds mei 2023 is dit ook de standaardoplossing vanuit Microsoft). Verder heeft het gebruik van phishing-resistente MFA-oplossingen de voorkeur boven de oplossingen die wél gevoelig zijn voor phishing, zeker voor het beveiligen van administratieve accounts. Onder phishing-resistente MFA-oplossingen vallen FIDO2 security keys, Windows Hello for Business en certificaatauthenticatie.

Conditional access

Via conditional access biedt Microsoft de mogelijkheid om aanvullende restricties op te leggen aan inlogactiviteiten op de Microsoft-tenant van de organisatie. Specifiek voor het voorkomen van een aanval zoals beschreven in dit artikel, raden wij het volgende aan:

  • Verklein de standaard “sign-in frequency” van 90 dagen naar een kortere periode. Deze waarde beschrijft hoe lang een gebruiker maximaal gebruik mag maken van refresh tokens zonder zich opnieuw aan te hoeven melden.
  • Vereis dat gebruikers zich alleen kunnen aanmelden vanuit managed en compliant devices. Hoewel dit voor veel organisaties wellicht lastig in te regelen valt, zorgt dit wel voor een veel kleinere kans op misbruik.
  • Maak gebruik van de “location”-conditie waarmee het mogelijk is om eisen op te leggen m.b.t. de locatie van waaruit de gebruiker inlogt. Zo is het bijvoorbeeld mogelijk om de toegang te blokkeren vanuit landen waarin de organisatie niet actief is of om alleen maar toegang te verlenen vanuit de netwerken van de organisatie zelf.
  • Maak gebruik van Entra ID Protection Risk policies. Microsoft maakt daarbij onderscheid tussen user risk policies en sign-in risk policies. De eerste policy richt zich m.n. op signalen die erop wijzen dat het account van de gebruiker is gecompromitteerd (op basis van activiteiten van de gebruiker over langere tijd), terwijl de tweede policy zich vooral richt op verdachte eigenschappen van de specifieke inlogpoging.  Voor beide policies geldt dat geautomatiseerde actie mogelijk is voor laag, gemiddeld en hoog risico. Microsoft adviseert om bij de user risk policy bij een hoog risico een wachtwoordwijziging te vereisen (incl. de vereiste om opnieuw aan te melden met MFA) en bij de sign-in risk policy een extra MFA-verificatie te vereisen bij een gemiddeld of hoog risico.

Tot slot

Aanvallers zullen continu op zoek blijven gaan naar nieuwe manieren om gebruikersaccounts over te nemen. Veel beveiligingsmaatregelen die Microsoft en klantorganisaties implementeren, leiden uiteindelijk vaak weer tot nieuwe aanvalsmethodieken waarmee de aanvallers pogen deze maatregelen te omzeilen. Het is dan ook belangrijk om de beveiliging van een omgeving continu up-to-date te houden en gebruik te blijven maken van de laatste mogelijkheden en inzichten om succesvolle aanvallen zoveel mogelijk te voorkomen.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center (SOC). Het Pinewood SOC is bereikbaar via +31 15 251 36 33 en via soc@pinewood.nl.

===== ENGLISH =====

Description

Recently, the Pinewood Security Operations Center (SOC) has seen attackers regularly succeed in taking over accounts within organizations’ Microsoft cloud environments. The Microsoft cloud is popular, so it is no surprise that attackers are very interested in the accounts contained within it (configured in Microsoft Entra ID, formerly Azure AD). Successfully taking over an account can have major consequences. After all, gaining access to such an account allows an attacker to, for example, send malicious emails in the owner’s name (Exchange Online) and access confidential files (SharePoint/OneDrive). Several questions therefore arise: how can this happen, how can you detect it, what happens after a successful attack, what should you do if an account gets compromised and what can you do to prevent it?

How can this happen?

In almost all of the incidents the Pinewood SOC has seen recently, a successful break-in to an account started with what is known as an Actor-in-the-Middle attack, or AitM attack for short. An AitM attack is similar to a traditional phishing attack, except that the attacker not only collects the data the victim enters on a phishing website, but also sends it directly to Microsoft for verification. As a result, the victim also will receive e.g. a prompt in his/her Authenticator app to confirm the login activity. Once the victim has done this, the attacker not only possesses the victim’s username and password, but also a session token and a refresh token. With these tokens, the attacker can continue to gain access to the victim’s account (by default for 90 days), without the need to log in again.

How can you detect it?

Detecting rogue login attempts to an account can be quite complex. Fortunately, Microsoft provides several alarms within Entra ID Protection that can help detect a potential intrusion into an account. The most important alarm here is Atypical travel: according to Microsoft’s description, this alarm triggers when a user logs in from two geographically different locations, with at least one of these locations being atypical for the user. For example, suppose a user normally always logs in from his home network and from his employer’s network, and now the user suddenly logs in from an address in Nigeria. This is typically a situation that triggers an atypical travel alarm and which is an indication that an attacker may be abusing the user’s account.

Of course, there are more ways to detect account intrusions (and more ways to break into an account). Accordingly, the Pinewood SOC has implemented several additional detection rules in recent months to help identify malicious use of an account at the earliest possible stage.

What happens after a successful attack?

After an attacker successfully manages to gain access to a victim’s account, a variety of different activities may follow. Much here depends on the attacker’s intentions. To give you an idea, here are some possible scenarios:

  • The attacker registers a new authentication mechanism so that he is able to continue logging into the account even if the tokens he obtained are no longer valid.
  • The attacker sends phishing emails in the victim’s name to a list of the victim’s known contacts. In doing so, he also tries to take over the accounts of other victims. The chances of new victims being hit by such a phishing email are high, since they are familiar with the sender and will usually not be suspicious when clicking on links located in the email.
  • The attacker monitors the emails exchanged by the victim, hoping for a conversation about a large payment. At that point, the attacker breaks into the conversation and will, for example, send a message indicating that the organization’s bank account number has changed. Since the other party “just sees” a response to an email within an existing email conversation, there is a good chance that they will blindly adopt the change in the account number and a large amount of money will end up in the attacker’s account.

What should you do if an account gets compromised?

First of all, the moment an account falls into the hands of an attacker, it is very important to determine this as soon as possible. Obviously, the damage is the least if the attacker quickly loses access to an account again. After determining that an account has been compromised, we recommend a number of standard steps:

  1. First disable the account so that the attacker can no longer use it. Also immediately invalidate all refresh tokens attached to the account so that the attacker can no longer use them either.
  2. Assume that the attacker has full control over the user’s authentication information. Therefore, reset both the user’s password and authentication methods (MFA). Verify that all the user’s previous MFA methods have been removed.
  3. Attackers are also known to regularly create mail forwarding rules after a successful intrusion into an account so that they continue to have access to a user’s emails even if they have lost control of the account itself. Therefore, always check all mailbox rules and mailbox forwarding rules configured on the account.
  4. In some cases an attacker even manages to register his own device in the name of the user which is then trusted. Therefore, always check if the list of “enrolled devices” is valid.
  5. Finally, verify all activities performed from the account from the time this account fell into the hands of the attacker. To do this, take advantage of the extensive auditing functionality provided by Microsoft.

How can you prevent it?

It’s cliché, but prevention is always better than cure. There are several ways in which an organization can prevent successful attacks. We therefore recommend taking another critical look at the organization’s Microsoft tenant setup and making improvements where possible. In addition, assume that an attacker can always succeed in taking over an account and that proper detection of malicious activity on accounts therefore remains an essential safety net.

Multifactor authentication

It goes without saying these days that multifactor authentication should be standard. Protecting an account based only on a username and password is extremely insecure and should only be allowed on the basis of very stringent restrictions (for example, use of a service account from a single IP address). In addition, Microsoft now offers the option of “MFA number matching,” which requires the user to enter a code when invoking multifactor authentication. Of course, we strongly recommend using this (since May 2023, this is also the default solution from Microsoft). Furthermore, the use of phishing-resistant MFA solutions is preferable to those that are indeed susceptible to phishing, especially for securing administrative accounts. Phishing-resistant MFA solutions include FIDO2 security keys, Windows Hello for Business and certificate authentication.

Conditional access

Through conditional access, Microsoft provides the ability to impose additional restrictions on login activities on the organization’s Microsoft tenant. Specifically for preventing an attack as described in this article, we recommend the following:

  • Reduce the default “sign-in frequency” of 90 days to a shorter time period. This value describes the maximum time a user can use refresh tokens without having to sign in again.
  • Require that users can only log in from managed and compliant devices. While this may be difficult for many organizations to set up, it does ensure a much lower chance of abuse.
  • Make use of the “location” condition that makes it possible to impose requirements on the location from which the user logs in. For example, it is possible to block access from countries in which the organization does not operate or to allow access only from the organization’s own networks.
  • Make use of Entra ID Protection Risk policies. Microsoft distinguishes between user risk policies and sign-in risk policies. The first policy focuses on signals that the user’s account has been compromised (based on user activity over time), while the second policy focuses on suspicious characteristics of the specific login attempt. For both policies, automated action is possible for low, medium and high risk. Microsoft recommends that the user risk policy requires a password change at high risk (including the requirement to re-login with MFA) and that the sign-in risk policy requires additional MFA authentication at medium or high risk.

In conclusion

Attackers will continuously continue to look for new ways to take over user accounts. Many security measures implemented by Microsoft and customer organizations often eventually lead to new attack methodologies with which attackers attempt to circumvent these measures. Therefore, it is important to continuously keep an environment’s security up to date and continue to use the latest capabilities and insights to prevent successful attacks as much as possible.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center (SOC). The Pinewood SOC can be contacted at +31 15 251 36 33 and via soc@pinewood.nl.

 

Het security consultancy spreekuur

Kom je er niet uit? Vraag het de consultant!

Pinewood organiseert vanaf nu iedere maand een cyber security spreekuur.

Tijdens dit spreekuur kunnen onze klanten bij ons terecht met vragen over de informatiebeveiliging van systemen, netwerken en applicaties. Het eerst volgende spreekuur zal plaatsvinden op:

Elke 2e donderdagochtend van de maand via MS Teams: 6 timeslots van 25 min beschikbaar (1 slot per klant)

Voorbeelden van vragen:

  • Wat kan ik nu alvast doen voor de NIS2?
  • Hoe werkt het certificeringsproces voor bv. ISO27001 of NEN7510?
  • Hoe ga ik om met beveiliging van mijn data bij Cloud-leveranciers?
  • Wat voor oplossing past er bij mijn organisatie om het niveau van awareness verder te verhogen?

 

De 6 timeslots:

Waar: Online

Prijs: GRATIS

Aanmelden:

Aanmelden en kies je tijdslot

Nadat u een afspraak heeft ingepland vragen we u het onderwerp wat u wilt bespreken door te sturen naar sc@pinewood.nl met het onderwerp “Consultancy Spreekuur”.

Natuurlijk zijn we ook buiten dit spreekuur bereikbaar voor vragen (over uiteenlopende onderwerpen). Dit spreekuur is echter bedoeld om optimale focus en aandacht te hebben voor de vragen van de klant.

Medewerkers in de zorg wisselen iedere dag belangrijke informatie uit met zorgaanbieders, zorgkantoren, verzekeraars, collega’s en vele andere partijen. Communicatie vindt vaak plaats via verschillende kanalen waaronder e-mail of soms via de cloud. Het komt nogal eens voor dat gebruikers of applicaties beperkingen bevatten of dat er tegen ingewikkelde zaken aangelopen wordt. In dergelijke gevallen wordt er weleens ongeautoriseerd gezocht naar alternatieven. Dit leidt tot ‘Shadow IT’. Applicaties, apparatuur en systemen welke niet bekend zijn en niet goedgekeurd zijn voor gebruik door de organisatie. Om te zorgen voor een juiste bescherming van een organisatie is het zeer belangrijk om grip te krijgen en houden op Shadow IT, om zo onnodige risico’s te voorkomen, persoonsgegevens te beschermen en privacy van zorggegevens te borgen.

Shadow IT: ‘IT-middelen welk zonder medeweten van de organisatie worden gebruikt.’

Wat is het probleem?

In eerste instantie denk je wellicht dat Shadow IT niet direct een probleem is, want medewerkers die op zoek gaan naar effectievere oplossingen, die zijn toch extra productief? Helaas is dat te simpel beredeneert. De aanschaf en het gebruik van allerlei applicaties en oplossingen leidt tot een ongeorganiseerd en chaotisch IT-landschap welke moeilijk te beheren valt. Daarnaast wordt het lastiger te achterhalen welke informatie nou waar opgeslagen is, iets dat cruciaal is ten tijde van een datalek of incident en ter bescherming van persoonsgegevens. Bovendien is het kostenefficienter om allemaal een en dezelfde oplossing te gebruiken in plaats van dat iedereen zijn of haar eigen oplossing aanschaft. Het bundelen, verzamelen en analyseren van gegevens wordt bovendien ingewikkelder als het verspreid staat over verschillende oplossingen. Bovendien wordt het onderhoud, patchen , relatieonderheid en beheer van oplossingen en leveranciers een gigantische klus.

Ongeorganiseerd & chaotisch

Verspreide data

Kosteninefficient

Analyse onmogelijk

Onderhoud en beheer

Leveranciersmanagement

Welke maatregelen kun je nemen?

Als organisatie is het belangrijk om keuzes te maken met betrekking tot Shadow IT en daarvoor procedures en protocollen opstelt, zodat het voor iedereen duidelijk is wat wel en niet toegestaan is. Procedures met betrekking tot het delen van informatie, hoe en in welke vorm, via welke applicaties en welke gegevens zijn cruciaal hierin.

Voor medewerkers moet het duidelijk zijn waarom bepaalde keuzes zijn gemaakt voor oplossingen en wat de risico’s en gevaren zijn als er gebruik wordt gemaakt van Shadow IT. Duidelijk moet zijn waarom bepaalde apparaten en applicaties gevaarlijk zijn en waarom ze niet gebruikt mogen worden.

Het is essentieel om toezicht te houden op internetverkeer en logging. Continue monitoring kan helpen in het signaleren en daarna voorkomen van het installeren en gebruik van onbekende, ongeautoriseerde applicaties of software.

Zorgen voor veilige alternatieven is cruciaal. Zorg voor een volledig en duidelijk IT-landschap waarin medewerkers ontzorgd worden en geschikte oplossingen ter beschikken hebben.

Wanneer medewerkers ontevreden zijn of tegen problemen aanlopen, is het belangrijk om te zorgen voor een open cultuur waarin medewerkers oplossingen kunnen aandragen. Zo blijven de medewerkers tevreden en zorg je dat jouw organisatie efficiënter gaat werken en productiever wordt. Hiervoor dien je wel een helder en duidelijk proces te hebben.

Samengevat kun je de volgende maatregelen nemen:

  • Zorg voor beleid en procedures met betrekking tot Shadow IT;
  • Creëer bewustzijn voor medewerkers over Shadow IT;
  • Controleer internetverkeer en logging om Shadow IT te voorkomen;
  • Zorg voor een compleet en veilig IT-landschap;
  • Geef ruimte voor nieuwe ideeën en een open cultuur.

Shadow IT is een kans om je organisatie te verbeteren

Tegenwoordig wordt het steeds lastiger om Shadow IT te voorkomen. Het is daarom erg belangrijk om vooraf na te denken over hoe het te beheersen en onnodige risico’s te voorkomen. Door de behoefte aan Shadow IT te achterhalen en te begrijpen wat de impact kan zijn op je organisatie, kun je uitdagingen oplossen en een cultuur creëren waarom medewerkers zichzelf en hun productie kunnen verbeteren. Hiervoor dien je op strategisch niveau om te gaan met de ontdekking van Shadow IT, het verbinden van alle teams en afdelingen en het creëren van openheid om technische innovatie teweeg te brengen. Uiteindelijk zullen, door op een positieve manier om te gaan met Shadow IT, medewerkers tevredener zijn met de te gebruiken IT-middelen wat zal zorgen voor een positief effect op producten, klanten en groei van je organisatie.

Webinar: Data is het nieuwe goud!

Ontdek de kracht van dataclassificatie en versterk jouw cybersecurity!

In de digitale wereld is data helaas een lucratief doelwit voor cybercriminelen. Het darkweb staat vol gestolen gegevens, verhandeld tegen lucratieve prijzen. Bescherm jezelf met de sleutel tot gedegen informatiebeveiliging: dataclassificatie. Ontdek tijdens dit webinar hoe je data prioriteert en gerichte beveiligingsmaatregelen daarop neemt.

Pentest

Daarnaast zullen we toekomstige uitdagingen van post quantum computing voor dataclassificatie behandelen en hoe je jouw organisatie daarop kunt voorbereiden. Maar dat is niet alles! Leer ook hoe je het management van jouw organisatie betrekt en welke belangen zij hebben bij dataclassificatie.

Schrijf je hieronder in om de opgenomen versie te bekijken:

"*" geeft vereiste velden aan

Wil je meer weten of een advies op maat? Neem dan contact met ons op voor een vrijblijvend advies gesprek.

Arthur van Vliet

Sales Manager

06 – 53 93 88 38

arthur.vanvliet@pinewood.nl

Pinewood Security Bulletin – Vulnerability in Ivanti Endpoint Manager Mobile (EPMM) / MobileIron Core

For English, see below.

Beschrijving

Er is een kwetsbaarheid ontdekt in Ivanti Endpoint Manager Mobile (EPMM), voorheen MobileIron Core, welke een ongeautoriseerde aanvaller in staat stelt om via het internet toegang te krijgen tot gebruikersdata, waaronder persoonsgegevens. Daarnaast kan de aanvaller de kwetsbaarheid misbruiken om een beheeraccount aan te maken en hiermee configuratiewijzigingen door te voeren. De kwetsbaarheid, bekend als CVE-2023-35078, zit in een API end-point van EPMM.

Ivanti heeft aangegeven dat de kwetsbaarheid op beperkte schaal actief gebruikt wordt. De verwachting is echter dat er binnenkort aanvalscode beschikbaar wordt gemaakt en de kwetsbaarheid op grotere schaal misbruikt zal worden.

Kwetsbare versies

De volgende versies van Ivanti EPMM zijn kwetsbaar:

  • Ivanti EPMM 11.10
  • Ivanti EPMM 11.9
  • Ivanti EPMM 11.8
  • Oudere Ivanti EPMM versies die niet meer ondersteund worden

Oplossingen en tijdelijke mitigaties

Ivanti adviseert om zo snel mogelijk de meest recente versie van Ivanti EPMM te installeren:

  • Ivanti EPMM 11.10.0.2 (of hoger)
  • Ivanti EPMM 11.9.1.1 (of hoger)
  • Ivanti EPMM 11.8.1.1 (of hoger)

Gedetailleerde informatie over hoe u de patch installeert, vindt u in Ivanti’s Knowledge Base-artikel.

Naast het verhelpen van de kwetsbaarheid is het advies om kwetsbare servers te onderzoeken op sporen van misbruik. Op dit moment is er weinig bekend over de sporen die een geslaagde aanval achterlaten. Zodra hier meer over bekend wordt, adviseren wij u de betreffende systemen te controleren.

Pinewood Security Operations Center (SOC)

Het Pinewood SOC blijft de situatie monitoren en zal detectie instellen als er IOC’s beschikbaar worden.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met het Pinewood Security Operations Center. Het SOC is bereikbaar via +31 (0)15 750 13 31 en via soc@pinewood.nl.

===== ENGLISH =====

Description

A vulnerability has been discovered in Ivanti Endpoint Manager Mobile (EPMM), formerly MobileIron Core, which would allow an unauthorized remote attacker to gain access to user data, including users’ personal identifiable information. In addition, the attacker could exploit the vulnerability to create an administration account and use it to make configuration changes. The vulnerability, known as CVE-2023-35078, appears to be in an API endpoint.

Ivanti has indicated that the vulnerability is being actively used on a limited scale. However, exploit code is expected to be made available soon and the vulnerability will be more widely exploited.

Vulnerable versions

The following versions of Ivanti EPMM are vulnerable:

  • EPMM 11.10
  • EPMM 11.9
  • EPMM 11.8
  • Older EPMM versions that are no longer supported

Solutions and workarounds

Ivanti recommends installing the latest version of Ivanti EPMM as soon as possible:

  • EPMM 11.10.0.2 (or higher)
  • EPMM 11.9.1.1 (or higher)
  • EPMM 11.8.1.1 (or higher)

Detailed information on how to install the patch can be found in Ivanti’s Knowledge Base article.

In addition to fixing the vulnerability, the advice is to examine vulnerable servers for signs of abuse. Currently, little is known about the traces left by a successful attack. As soon as more becomes known about this, we recommend that you check the affected systems.

Pinewood Security Operations Center (SOC)

The Pinewood SOC continues to monitor the situation and will setup detection when IOCs become available.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Center. The SOC can be contacted at +31 (0)15 750 13 31 and via soc@pinewood.nl.

Pinewood Security Bulletin – Security Updates available for Adobe ColdFusion

For English, see below.

Beschrijving

Adobe ColdFusion bevat kritieke kwetsbaarheden die kunnen leiden tot willekeurige uitvoering van code en omzeiling van beveiligingsfuncties. De kwetsbaarheden omvatten:

  • CVE-2023-38204: Deserialisatie-fout – Een kritieke fout waarmee een aanvaller zonder authenticatie willekeurige code kan uitvoeren.
  • CVE-2023-38205: Onjuist toegangsbeheer – Een andere kritieke kwetsbaarheid waarmee een aanvaller beveiligingsfuncties kan omzeilen.
  • CVE-2023-38206: Onjuist toegangsbeheer – Deze kwetsbaarheid stelt een aanvaller in staat om specifieke beveiligingscontroles te omzeilen.

Van deze kwetsbaarheden is CVE-2023-38205 actief misbruikt bij beperkte aanvallen gericht op Adobe ColdFusion. Belangrijk is dat het hier andere kwetsbaarheden betreft dan gemeld in ons bulletin van maandag 17 juli; dit betekent ook dat de updates die n.a.v. dit bulletin zijn doorgevoerd, geen bescherming bieden tegen deze nieuwe kwetsbaarheden.

Kwetsbare versies

De volgende versies van Adobe ColdFusion zijn kwetsbaar:

  • ColdFusion 2023: Update 2 en eerdere versies
  • ColdFusion 2021: Update 8 en eerdere versies
  • ColdFusion 2018: Update 18 en eerdere versies

Oplossingen en tijdelijke mitigaties

Adobe heeft beveiligingsupdates uitgebracht om de kwetsbaarheden in ColdFusion te verhelpen. Gebruikers wordt sterk aangeraden hun installaties bij te werken naar de volgende versies:

  • ColdFusion 2023: Update 3
  • ColdFusion 2021: Update 9
  • ColdFusion 2018: Update 19

Naast het installeren van de laatste ColdFusion-update, is het ook van belang om de laatste JDK/JRE-versie op het ColdFusion-systeem te installeren. Adobe waarschuwt dat het alleen installeren van de ColdFusion-update onvoldoende beveiliging biedt. Daarnaast is het van belang om de juiste JVM-flag in te stellen via het startscript van de applicatieserver. Hoe dit moet, is afhankelijk van de gebruikte applicatieserver; raadpleeg hiervoor het Adobe Security Bulletin.

Meer informatie

Voor aanvullende informatie verwijzen we naar het officiële Adobe-beveiligingsbulletin:

https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met de Pinewood Servicedesk. De servicedesk is bereikbaar via +31 15 251 36 33 en via support@pinewood.nl.

===== ENGLISH =====

Description

Adobe ColdFusion has been identified with critical vulnerabilities that may lead to arbitrary code execution and security feature bypass. The vulnerabilities include:

  • CVE-2023-38204: Deserialization issue – A critical flaw that allows an attacker to execute arbitrary code.
  • CVE-2023-38205: Improper Access Control – Another critical vulnerability, enabling an attacker to bypass security features.
  • CVE-2023-38206: Improper Access Control – This flaw allows an attacker to bypass specific security controls.

Among these, CVE-2023-38205 has been actively exploited in the wild in limited attacks targeting Adobe ColdFusion. Note that the vulnerabilities described are different from the vulnerabilities that we reported in our security bulletin of Monday 17 July; as a result, updates that were installed as a follow-up to this bulletin, do not fix the issues that are reported in this latest bulletin.

Vulnerable versions

The following versions of Adobe ColdFusion are affected:

  • ColdFusion 2023: Update 2 and earlier
  • ColdFusion 2021: Update 8 and earlier
  • ColdFusion 2018: Update 18 and earlier

Solutions and workarounds

Adobe has released security updates to address the vulnerabilities in ColdFusion. Users are strongly advised to update their installations to the following fixed versions:

  • ColdFusion 2023: Update 3
  • ColdFusion 2021: Update 9
  • ColdFusion 2018: Update 19

Next to installing the latest ColdFusion update, organisations should also install the latest JDK/JRE version on the ColdFusion-system. Adobe warns that applying the ColdFusion update without a corresponding JDK update will not secure the server. Also make sure that the right JVM flag is set via the startup script of the application server; see the Adobe Security Bulletin(s) on how this should be done for the different application servers supported.

More information

We refer to the official Adobe bulletin for additional information:

https://helpx.adobe.com/security/products/coldfusion/apsb23-47.html

Questions

For questions about this security bulletin, please contact the Pinewood Service desk. The service desk can be contacted at +31 15 251 36 33 and via support@pinewood.nl.

Pinewood Security Bulletin – Multiple vulnerabilities in Adobe ColdFusion

For English, see below.

Beschrijving

Adobe heeft recent updates uitgebracht voor ernstige kwetsbaarheden in Adobe ColdFusion, een platform voor het ontwikkelen en aanbieden van dynamische webapplicaties. Voor één van de kwetsbaarheden (CVE-2023-38203) bracht Adobe op zaterdag 15 juli 2023 een noodpatch uit nadat proof-of-concept code voor de kwetsbaarheid online werd gepubliceerd. Deze noodpatch volgde kort op een reguliere security-update (op 11 juli 2023) waarin ook al een (vergelijkbare) ernstige kwetsbaarheid werd verholpen (CVE-2023-29300) en waar inmiddels ook proof-of-concept code voor publiek is gemaakt. In beide gevallen gaat het om een “deserialisatie”-kwetsbaarheid, waarbij een aanvaller malafide code kan uitvoeren door het proces te misbruiken waarbij ColdFusion een geserialiseerd Java-object omzet in de oorspronkelijke vorm.

Gezien de ernst van de kwetsbaarheden, de beschikbaarheid van proof-of-concept code en het feit dat deze kwetsbaarheden mogelijk zonder gebruikersauthenticatie misbruikt kunnen worden, raadt Pinewood aan zo snel mogelijk de beschikbaar gestelde updates van ColdFusion te installeren. Houd daarbij ook rekening met eventuele kwetsbare ColdFusion-installaties die leveranciers gebruiken voor het ondersteunen van webapplicaties van de organisatie.

Kwetsbare versies

Adobe heeft updates uitgebracht voor ColdFusion 2018, 2021 en 2023. Onderstaande versies van Adobe ColdFusion zijn hierbij kwetsbaar:

  • Adobe ColdFusion 2018 Update 17 (en eerdere versies)
  • Adobe ColdFusion 2021 Update 7 (en eerdere versies)
  • Adobe ColdFusion 2023 Update 1 (en eerdere versies)

Oplossingen

Adobe raadt aan zo snel mogelijk de onderstaande updates van ColdFusion te installeren op kwetsbare servers:

  • Adobe ColdFusion 2018 Update 18
  • Adobe ColdFusion 2021 Update 8
  • Adobe ColdFusion 2023 Update 2

Naast het installeren van de laatste ColdFusion-update, is het ook van belang om de laatste JDK/JRE-versie op het ColdFusion-systeem te installeren. Adobe waarschuwt dat het alleen installeren van de ColdFusion-update onvoldoende beveiliging biedt. Daarnaast is het van belang om de juiste JVM-flag in te stellen via het startscript van de applicatieserver. Hoe dit moet, is afhankelijk van de gebruikte applicatieserver; raadpleeg hiervoor het Adobe Security Bulletin.

Meer informatie

Vragen

Voor vragen over deze security bulletin kunt u contact opnemen met de Pinewood Security Operations Centre (SOC). De servicedesk is bereikbaar via +31 15 251 36 33 en via soc@pinewood.nl.

===== ENGLISH =====

Description

Adobe recently released updates for critical vulnerabilities in Adobe ColdFusion, a platform used for developing and running dynamic web applications. One of these vulnerabilities (CVE-2023-38203) was fixed by an emergency patch on Saturday 15 July 2023 which was released after proof-of-concept code for the vulnerability was published online. This emergency patch quickly followed a regular security update (on 11 July 2023) which resolved a (similar) critical vulnerability and for which proof-of-concept code is also available. In both cases, the vulnerability is caused by a “deserialisation”-issue whereby an attacker can execute arbitrary code by exploiting the process of turning a serialised Java-object into its original form.

Given the criticality of the vulnerabilities, the fact that proof-of-concept code is publicly available and that the vulnerabilities may be exploited without user authentication, Pinewood advises to install the ColdFusion updates as soon as possible. Also consider vendors that might run ColdFusion to support web applications of the organization.

Vulnerable versions

Adobe released security updates for ColdFusion 2018, 2021 and 2023. The following versions of Adobe ColdFusion are vulnerable:

  • Adobe ColdFusion 2018 Update 17 (and earlier versions)
  • Adobe ColdFusion 2021 Update 7 (and earlier versions)
  • Adobe ColdFusion 2023 Update 1 (and earlier versions)

Solutions

Adobe advises to install the following updates for ColdFusion as soon as possible:

  • Adobe ColdFusion 2018 Update 18
  • Adobe ColdFusion 2021 Update 8
  • Adobe ColdFusion 2023 Update 2

Next to installing the latest ColdFusion update, organisations should also install the latest JDK/JRE version on the ColdFusion-system. Adobe warns that applying the ColdFusion update without a corresponding JDK update will not secure the server. Also make sure that the right JVM flag is set via the startup script of the application server; see the Adobe Security Bulletin(s) on how this should be done for the different application servers supported.

More information

Questions

For questions about this security bulletin, please contact the Pinewood Security Operations Centre (SOC). The service desk can be contacted at +31 15 251 36 33 and via soc@pinewood.nl.