CVE-2020-1599
published 2020-11-11CVE-2020-1599: Windows Spoofing Vulnerability Windows Spoofing Vulnerability
medium5.5CVSS 3.1
AVLACLPRLUINSUCNIHAN
ITWVulnCheck KEVRansomware
Exploited in the wild
EPSS
19.12%
97.0th percentile
Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
Affected
39 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_version_1507 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1607 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1803 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1809 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_32-bit_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_arm64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1903_for_x64-based_systems | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_1909 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_10_version_20h2 | >= 10.0.0 < publication | publication |
| microsoft | windows_7 | >= 6.1.0 < publication | publication |
| microsoft | windows_7_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_8.1 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.0 < publication | publication |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.0 < publication | publication |
| microsoft | windows_server_2012 | >= 6.2.0 < publication | publication |
| microsoft | windows_server_2012_r2 | >= 6.3.0 < publication | publication |
| microsoft | windows_server_2016 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_2019 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_2004 | >= 10.0.0 < publication | publication |
| microsoft | windows_server_version_20h2 | >= 10.0.0 < publication | publication |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1803 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect mshta.exe being invoked with a DLL file (e.g., appContast.dll or reboot.dll) as a parameter — this is the exploitation mechanism for CVE-2020-1599, where a Microsoft-signed PE file has a VBScript/JavaScript payload appended to its signature section and is executed via mshta.exe. ↗
- →Alert on regsvr32.exe spawning from or being chained after mshta.exe, particularly loading DLLs from %appdata% — indicative of Zloader payload execution following CVE-2020-1599 abuse. ↗
- →Monitor for msiexec.exe making outbound network connections — Zloader injects into msiexec.exe which then beacons to the C2. ↗
- →Detect WScriptSleeper.vbs being written to the %temp% directory — a staging artifact specific to this Zloader campaign. ↗
- →Flag auto.bat placed in the Startup folder that invokes mshta.exe with a DLL parameter — persistence mechanism for this campaign. ↗
- →Detect modification of HKCU\Software\Microsoft\Windows\CurrentVersion\Run to execute regsvr32.exe with a DLL from a newly created %appdata% subfolder — Zloader run-key persistence. ↗
- →Inspect PE files for appended data beyond the Authenticode signature boundary (modified file checksum and signature size fields) — the core technique exploited by CVE-2020-1599 to maintain a valid signature on a tampered file. ↗
- ·The campaign payload DLL (9092.dll) changes hash every few days via a server-side check.php script, making hash-based detection unreliable for this family. ↗
- ·zoom.dll referenced in the persistence chain was missing at time of analysis, indicating the campaign was still under active development and additional components may appear. ↗
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
cvelistv55.5MEDIUM
vulncheck5.5MEDIUM
vendor_msrc5.5MEDIUM
vendor_redhat3.3LOW
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CVEList
Windows Spoofing Vulnerability
cvelistv5·2020-11-11·CVSS 5.5
CVE-2020-1599 [MEDIUM] Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
VulnCheck
Windows Spoofing Vulnerability
vulncheck·2020·CVSS 5.5
CVE-2020-1599 [MEDIUM] Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
Affected: Microsoft Windows
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://blogs.vmware.com/security/2022/11/batloader-the-evasive-downloader-malware.html
Red Hat
libsolv: Heap overflow
vendor_redhat·2022-02-21·CVSS 3.3
CVE-2021-44574 [LOW] CWE-787 libsolv: Heap overflow
libsolv: Heap overflow
[REJECTED CVE] A heap-overflow vulnerability exists in openSUSE libsolv through 13 Dec 2020 in the resolve_jobrules function at src/solver.c at line 1599.
Statement: This flaw was found to be a duplicate of CVE-2021-3200. Please see https://access.redhat.com/security/cve/CVE-2021-3200 for information about affected products and security errata.
Package: libsolv (Red Hat Enterprise Linux 7) - Not affected
Package: libsolv (Red Hat Enterprise Linux 8) - Not affected
Package: libsolv (Red Hat Enterprise Linux 9) - Not affected
Package: libsolv (Red Hat Satellite 6) - Not affected
Package: libsolv (Red Hat Update Infrastructure 3 for Cloud Providers) - Will not fix
Microsoft
Windows Spoofing Vulnerability
vendor_msrc·2020-11-10·CVSS 5.5
CVE-2020-1599 [MEDIUM] Windows Spoofing Vulnerability
Windows Spoofing Vulnerability
Microsoft Windows: Microsoft Windows
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Spoofing
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586785
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586793
Reference: https://support.microsoft.com/help/4586793
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586786
Reference: https://support.microsoft.com/help/4586786
Reference: https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4586781
Reference: https://support.microsoft.com/help/4586781
Reference: ht
Suricata
ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1599)
suricata·2014-11-25·CVSS 9.8
CVE-2013-1599 [CRITICAL] ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1599)
ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1599)
Rule: alert http $EXTERNAL_NET any -> $HTTP_SERVERS any (msg:"ET EXPLOIT D-Link IP Camera Vulnerable HTTP Request (CVE-2013-1599)"; flow:established,to_server; http.method; content:"GET"; http.uri; content:"/cgi-bin/rtpd.cgi?"; fast_pattern; reference:url,www.coresecurity.com/advisories/d-link-ip-cameras-multiple-vulnerabilities; classtype:attempted-admin; sid:2019801; rev:4; metadata:created_at 2014_11_25, cve CVE_2013_1599, signature_severity Major, updated_at 2020_09_28;)
No public exploits indexed.
Checkpoint
Can You Trust a File’s Digital Signature? New Zloader Campaign exploits Microsoft’s Signature Verification putting users at risk
blogs_checkpoint·2022-01-05
CVE-2020-1599 Can You Trust a File’s Digital Signature? New Zloader Campaign exploits Microsoft’s Signature Verification putting users at risk
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
AI Research 2
Android Malware 23
Artificial Intelligence 4
ChatGPT 3
Check Point Research Publications 455
Cloud Security 1
CPRadio 44
Crypto 2
Data & Threat Intelligence 2
Data Analysis 0
Demos 22
Global Cyber Attack Reports 408
How To Guides 13
Ransomware 5
Russo-Ukrainian War 1
Security Report 1
Threat and data analysis 0
Threat Research 174
Web 3.0 Security 11
Wipers 0
## Can You Trust a File’s Digital Signature? New Zloader Campaign exploits Microsoft’s Signature Verification putting users at risk
## Research by: Golan Cohen
## Introduction
Last seen i
arXiv
On the Abuse and Detection of Polyglot Files
arxiv_fulltext·2024-07-01
On the Abuse and Detection of Polyglot Files
Notice: This manuscript has been authored [or, co-authored] by UT-Battelle, LLC, under contract DE-AC05-00OR22725 with the US Department of Energy (DOE). The US government retains and the publisher, by accepting the article for publication, acknowledges that the US government retains a nonexclusive, paid-up, irrevocable, worldwide license to publish or reproduce the published form of this manuscript, or allow others to do so, for US government purposes. DOE will provide public access to these results of federally sponsored research in accordance with the DOE Public Access Plan (http://energy.gov/downloads/doe-public-access-plan).
## Abstract
A polyglot is a file that is valid in two or more formats. Polyglot files pose a problem for malware detection systems that route files
to format-sp
Bugzilla
CVE-2021-44574 libsolv: Heap overflow
bugzilla·2022-02-22·CVSS 3.3
CVE-2021-44574 [LOW] CVE-2021-44574 libsolv: Heap overflow
CVE-2021-44574 libsolv: Heap overflow
A heap-overflow vulnerability exists in openSUSE libsolv through 13 Dec 2020 in the resolve_jobrules function at src/solver.c at line 1599.
https://github.com/openSUSE/libsolv/issues/429
https://github.com/yangjiageng/PoC/blob/master/libsolv-PoCs/resolve_jobrules-1599
Discussion:
Created libsolv tracking bugs for this issue:
Affects: fedora-all [bug 2056778]
Bugzilla
CVE-2019-13135 ImageMagick: a "use of uninitialized value" vulnerability in the function ReadCUTImage leading to a crash and DoS
bugzilla·2019-07-02·CVSS 8.8
CVE-2019-13135 [HIGH] CVE-2019-13135 ImageMagick: a "use of uninitialized value" vulnerability in the function ReadCUTImage leading to a crash and DoS
CVE-2019-13135 ImageMagick: a "use of uninitialized value" vulnerability in the function ReadCUTImage leading to a crash and DoS
ImageMagick before 7.0.8-50 has a "use of uninitialized value" vulnerability in the function ReadCUTImage in coders/cut.c.
Upstream Issue:
https://github.com/ImageMagick/ImageMagick/issues/1599
Discussion:
Created ImageMagick tracking bugs for this issue:
Affects: fedora-all [bug 1726108]
---
Upstream patch:
https://github.com/ImageMagick/ImageMagick/commit/cdb383749ef7b68a38891440af8cc23e0115306d
---
ImageMagick6 commit:
https://github.com/ImageMagick/ImageMagick6/commit/1e59b29e520d2beab73e8c78aacd5f1c0d76196d
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2020:1180 https://access.redhat.com/errat
2020-11-11
Published
Exploited in the wild