CVE-2020-15999
published 2020-11-03CVE-2020-15999: Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML…
PriorityP188critical9.6CVSS 3.1
AVNACLPRNUIRSCCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2021-11-17
Exploited in the wild
EPSS
50.63%
98.8th percentile
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | freetype | < freetype 2.10.2+dfsg-4 (bookworm) | freetype 2.10.2+dfsg-4 (bookworm) |
| fedoraproject | fedora | — | — |
| freetype | freetype | >= 0 < 2.10.2+dfsg-4 | 2.10.2+dfsg-4 |
| freetype | freetype | >= 0 < 2.10.2+dfsg-4 | 2.10.2+dfsg-4 |
| freetype | freetype | >= 0 < 2.10.2+dfsg-4 | 2.10.2+dfsg-4 |
| freetype | freetype | >= 0 < 2.10.2+dfsg-4 | 2.10.2+dfsg-4 |
| freetype | freetype | >= 2.6.0 < 2.10.4 | 2.10.4 |
| android | — | — | |
| chrome | < 86.0.4240.111 | 86.0.4240.111 | |
| chrome | >= unspecified < 86.0.4240.111 | 86.0.4240.111 | |
| chrome_chrome | — | — | |
| mozilla | firefox | — | — |
| msrc | cbl2_freetype_2.11.1-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_1.0_arm | — | — |
| msrc | cbl_mariner_1.0_x64 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| msrc | cm1_freetype_2.11.1-1_on_cbl_mariner_1.0 | — | — |
| opensuse | backports_sle | — | — |
| platform | external_freetype | >= 10:0 < 10:2021-01-01 | 10:2021-01-01 |
| platform | external_freetype | >= 11:0 < 11:2021-01-01 | 11:2021-01-01 |
| platform | external_freetype | >= 8.0:0 < 8.0:2021-01-01 | 8.0:2021-01-01 |
| platform | external_freetype | >= 8.1:0 < 8.1:2021-01-01 | 8.1:2021-01-01 |
| platform | external_freetype | >= 9:0 < 9:2021-01-01 | 9:2021-01-01 |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2020-15999 (FreeType heap buffer overflow in Chrome) is chained with CVE-2020-17087 (Windows Kernel Cryptography Driver cng.sys privilege escalation) to escape the Chrome sandbox and gain administrative privileges ↗
- →Post-exploitation reconnaissance uses nltest to discover domain controllers — monitor for nltest execution on endpoints ↗
- →Post-exploitation domain enumeration uses 'net group /domain' — monitor for this command on endpoints ↗
- →Post-exploitation local admin discovery uses 'net localgroup' — monitor for this command on endpoints ↗
- →Post-exploitation service principal discovery uses setspn — monitor for setspn execution on endpoints ↗
- →Post-exploitation SMB share discovery uses 'net use' and 'net share' — monitor for these commands on endpoints ↗
- →The exploit targets the FreeType font rendering library included with Chrome; delivery vector is a crafted HTML page triggering heap corruption ↗
- →CVE-2020-17087 abuses the Windows Kernel Cryptography Driver (cng.sys) DeviceCNG device via IOCTL — monitor for unusual user-mode access to cng.sys ↗
- ·Exploit was observed in the wild as a zero-day prior to the Chrome 86.0.4240.111 patch; unpatched Chrome versions below this are vulnerable ↗
CVSS provenance
nvdv3.19.6CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
ghsa9.6CRITICAL
osv9.6CRITICAL
vulncheck9.6CRITICAL
cisa9.6CRITICAL
vendor_debian9.6CRITICAL
vendor_redhat9.6CRITICAL
vendor_msrc6.5MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Rockwell Automation Connected Components Workbench
cisa_ics·2023-09-21·CVSS 9.6
[CRITICAL] Rockwell Automation Connected Components Workbench
ICS Advisory
##
Rockwell Automation Connected Components Workbench
Release DateSeptember 21, 2023
Alert CodeICSA-23-264-05
## View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.6
- ATTENTION: Exploitable remotely/low attack complexity/public exploits are available/known public exploitation
- Vendor: Rockwell Automation
- Equipment: Connected Components Workbench
- Vulnerabilities: Use After Free, Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to exploit heap corruption via a crafted HTML.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Rockwell Automation Connected Components Workbench Smart Security Manager are affected:
- Connected Components Workbench: versions
CISA
Google Chrome FreeType Heap Buffer Overflow Vulnerability
cisa·2021-11-03·CVSS 9.6
CVE-2020-15999 [CRITICAL] CWE-787 Google Chrome FreeType Heap Buffer Overflow Vulnerability
Vulnerability: Google Chrome FreeType Heap Buffer Overflow Vulnerability
Affected: Google Chrome FreeType
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-15999
Remediation Due Date: 2021-11-17
Android
CVE-2020-15999: Android Security Bulletin 2021-01-01
CVE: CVE-2020-15999
Severity: MEDIUM
Type: RCE
Affected AOSP versions: 8
vendor_android·2021-01-01·CVSS 9.6
CVE-2020-15999 [CRITICAL] CVE-2020-15999: Android Security Bulletin 2021-01-01
CVE: CVE-2020-15999
Severity: MEDIUM
Type: RCE
Affected AOSP versions: 8
Android Security Bulletin 2021-01-01
CVE: CVE-2020-15999
Severity: MEDIUM
Type: RCE
Affected AOSP versions: 8.0, 8.1, 9, 10, 11
References: A-171232105
Microsoft
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
vendor_msrc·2020-11-10·CVSS 6.5
CVE-2020-15999 [CRITICAL] CWE-787 Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Marine
Ubuntu
FreeType vulnerability
vendor_ubuntu·2020-10-22
CVE-2020-15999 FreeType vulnerability
Title: FreeType vulnerability
Summary: FreeType could be made to crash or run programs as your login if it
opened a specially crafted file.
USN-4593-1 fixed a vulnerability in FreeType. This update provides
the corresponding update for Ubuntu 14.04 ESM.
Original advisory details:
Sergei Glazunov discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Chrome
Stable Channel Update for Desktop: CVE-2020-15999
vendor_chrome·2020-10-20·CVSS 9.6
CVE-2020-15999 [HIGH] Stable Channel Update for Desktop: CVE-2020-15999
Stable Channel Update for Desktop
CVE-2020-15999: Heap buffer overflow in Freetype. Reported by Sergei Glazunov of Google Project Zero on 2020-10-19 [$3000][ 1134960 ] Medium CVE-2020-16003: Use after free in printing
Reported by Khalil Zhani on 2020-10-04 We would also like to thank all security researchers that worked with us during the development cycle to prevent security bugs from ever reaching the stable channel
Severity: high
Ubuntu
FreeType vulnerability
vendor_ubuntu·2020-10-20
CVE-2020-15999 FreeType vulnerability
Title: FreeType vulnerability
Summary: FreeType could be made to crash or run programs as your login if it
opened a specially crafted file.
Sergei Glazunov discovered that FreeType did not correctly handle certain
malformed font files. If a user were tricked into using a specially crafted
font file, a remote attacker could cause FreeType to crash or possibly
execute arbitrary code with user privileges.
Instructions: After a standard system update you need to restart your session to make
all the necessary changes.
Red Hat
freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png
vendor_redhat·2020-10-19·CVSS 9.6
CVE-2020-15999 [CRITICAL] CWE-190 freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png
freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
A heap buffer overflow leading to out-of-bounds write was found in freetype. Memory allocation based on truncated PNG width and height values allows for an out-of-bounds write to occur in application memory when an attacker supplies a specially crafted TTF file.
Statement: Although firefox and thunderbird, as shipped with Red Hat Enterprise Linux 6, bundle a version (2.4.11) of freetype in gtk3-private, the version is not affected by this flaw because the vulnerable code was introduced in a subsequent version of freetype. The freetype package shipp
Debian
CVE-2020-15999: freetype - Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed...
vendor_debian·2020·CVSS 9.6
CVE-2020-15999 [CRITICAL] CVE-2020-15999: freetype - Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed...
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
Scope: local
bookworm: resolved (fixed in 2.10.2+dfsg-4)
bullseye: resolved (fixed in 2.10.2+dfsg-4)
forky: resolved (fixed in 2.10.2+dfsg-4)
sid: resolved (fixed in 2.10.2+dfsg-4)
trixie: resolved (fixed in 2.10.2+dfsg-4)
Mozilla
Mozilla Foundation Security Advisory 2020-52: CVE-2020-15999
vendor_mozilla·CVSS 9.6
CVE-2020-15999 [CRITICAL] Mozilla Foundation Security Advisory 2020-52: CVE-2020-15999
Mozilla Foundation Security Advisory 2020-52
CVE: CVE-2020-15999
Product: Thunderbird
Impact: high
Fixed in: Thunderbird 78.5
Mozilla
Mozilla Foundation Security Advisory 2020-50: CVE-2020-15999
vendor_mozilla·CVSS 9.6
CVE-2020-15999 [CRITICAL] Mozilla Foundation Security Advisory 2020-50: CVE-2020-15999
Mozilla Foundation Security Advisory 2020-50
CVE: CVE-2020-15999
Product: Firefox
Impact: high
Fixed in: Firefox 83
Mozilla
Mozilla Foundation Security Advisory 2020-51: CVE-2020-15999
vendor_mozilla·CVSS 9.6
CVE-2020-15999 [CRITICAL] Mozilla Foundation Security Advisory 2020-51: CVE-2020-15999
Mozilla Foundation Security Advisory 2020-51
CVE: CVE-2020-15999
Product: Firefox ESR
Impact: high
Fixed in: Firefox ESR 78.5
Project0
In-the-Wild Series: October 2020 0-day discovery - Project Zero
project_zero·2021-03-01·CVSS 9.6
CVE-2020-15999 [CRITICAL] In-the-Wild Series: October 2020 0-day discovery - Project Zero
Posted by Maddie Stone, Project Zero
In October 2020, Google Project Zero discovered seven 0-day exploits being actively used in-the-wild. These exploits were delivered via "watering hole" attacks in a handful of websites pointing to two exploit servers that hosted exploit chains for Android, Windows, and iOS devices. These attacks appear to be the next iteration of the campaign discovered in February 2020 and documented in this blog post series.
In this post we are summarizing the exploit chains we discovered in October 2020. We have already published the details of the seven 0-day vulnerabilities exploited in our root cause analysis (RCA) posts. This post aims to provide the context around these exploits.What happened
In October 2020, we discovered that the actor from the Feb
Project0
Déjà vu-lnerability - Project Zero
project_zero·2021-02-01
CVE-2014-9665 Déjà vu-lnerability - Project Zero
A Year in Review of 0-days Exploited In-The-Wild in 2020
Posted by Maddie Stone, Project Zero
2020 was a year full of 0-day exploits. Many of the Internet’s most popular browsers had their moment in the spotlight. Memory corruption is still the name of the game and how the vast majority of detected 0-days are getting in. While we tried new methods of 0-day detection with modest success, 2020 showed us that there is still a long way to go in detecting these 0-day exploits in-the-wild. But what may be the most notable fact is that 25% of the 0-days detected in 2020 are closely related to previously publicly disclosed vulnerabilities. In other words, 1 out of every 4 detected 0-day exploits could potentially have been avoided if a more thorough investigation and patching effort were explor
OSV
CVE-2020-15999: In Load_SBit_Png of pngshim
osv·2021-01-01
CVE-2020-15999 CVE-2020-15999: In Load_SBit_Png of pngshim
In Load_SBit_Png of pngshim.c, there is a possible out of bounds write due to a heap buffer overflow. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation.
OSV
CVE-2020-15999: Heap buffer overflow in Freetype in Google Chrome prior to 86
osv·2020-11-03·CVSS 9.6
CVE-2020-15999 [CRITICAL] CVE-2020-15999: Heap buffer overflow in Freetype in Google Chrome prior to 86
Heap buffer overflow in Freetype in Google Chrome prior to 86.0.4240.111 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
GHSA
Heap buffer overflow in CefSharp
ghsa·2020-10-27·CVSS 9.6
CVE-2020-15999 [CRITICAL] CWE-119 Heap buffer overflow in CefSharp
Heap buffer overflow in CefSharp
### Impact
A memory corruption bug(Heap overflow) in the FreeType font rendering library.
> This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images .
As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/
Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.
### Patches
Upgrade to 85.3.130 or higher
### References
- https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/
- https://www.zdnet.com/article/google-releases-chrome-security-update-to-patch-actively-exploited-zero-day/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999
- https://magpcss.org/ceforum/viewtopic.php?f=10&t=17942
To revi
OSV
Heap buffer overflow in CefSharp
osv·2020-10-27·CVSS 9.6
CVE-2020-15999 [CRITICAL] Heap buffer overflow in CefSharp
Heap buffer overflow in CefSharp
### Impact
A memory corruption bug(Heap overflow) in the FreeType font rendering library.
> This can be exploited by attackers to execute arbitrary code by using specially crafted fonts with embedded PNG images .
As per https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/
Google is aware of reports that an exploit for CVE-2020-15999 exists in the wild.
### Patches
Upgrade to 85.3.130 or higher
### References
- https://www.secpod.com/blog/chrome-zero-day-under-active-exploitation-patch-now/
- https://www.zdnet.com/article/google-releases-chrome-security-update-to-patch-actively-exploited-zero-day/
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-15999
- https://magpcss.org/ceforum/viewtopic.php?f=10&t=17942
To revi
VulnCheck
Google Chrome FreeType Heap Buffer Overflow Vulnerability
vulncheck·2020·CVSS 9.6
CVE-2020-15999 [CRITICAL] CWE-787 Google Chrome FreeType Heap Buffer Overflow Vulnerability
Google Chrome FreeType Heap Buffer Overflow Vulnerability
Google Chrome uses FreeType, an open-source software library to render fonts, which contains a heap buffer overflow vulnerability in the function Load_SBit_Png when processing PNG images embedded into fonts. This vulnerability is part of an exploit chain with CVE-2020-17087 on Windows and CVE-2020-16010 on Android.
Affected: Google Chrome FreeType
Required Action: Apply updates per vendor instructions.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://savannah.nongnu.org/bugs/?59308; https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html; https://googleprojectzero.github.io/0days-in-the-wild//0day-RCAs/2020/CVE-2020-16009.ht
Project0
Project Zero RCA: CVE-2020-16010: Chrome for Android ConvertToJavaBitmap Heap Buffer Overflow
project_zero·CVSS 9.6
CVE-2020-16010 [CRITICAL] Project Zero RCA: CVE-2020-16010: Chrome for Android ConvertToJavaBitmap Heap Buffer Overflow
# CVE-2020-16010: Chrome for Android ConvertToJavaBitmap Heap Buffer Overflow
*Mark Brand and Sergei Glazunov, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2021-02-04)*
## The Basics
**Disclosure or Patch Date:** 2 November 2020
**Product:** Google Chrome for Android
**Advisory:** https://chromereleases.googleblog.com/2020/11/chrome-for-android-update.html
**Affected Versions:** 86.0.4240.114 and previous
**First Patched Version:** 86.0.4240.185
**Issue/Bug Report:**
* Project Zero: https://bugs.chromium.org/p/project-zero/issues/detail?id=2112
* Chromium: https://bugs.chromium.org/p/chromium/issues/detail?id=1144368
**Patch CL:** https://chromium.googlesource.com/chromium/src.git/+/e598fc599bd920392256d05c61826466c73c8e
Project0
Project Zero RCA: CVE-2020-16009: Chrome Turbofan Type Confusion after Map Deprecation
project_zero·CVSS 8.8
CVE-2020-16009 [HIGH] Project Zero RCA: CVE-2020-16009: Chrome Turbofan Type Confusion after Map Deprecation
# CVE-2020-16009: Chrome Turbofan Type Confusion after Map Deprecation
*Samuel Groß, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2021-02-04)*
## The Basics
**Disclosure or Patch Date:** 2 November 2020
**Product:** Google Chrome
**Advisory:** https://chromereleases.googleblog.com/2020/11/stable-channel-update-for-desktop.html
**Affected Versions:** 86.0.4240.111 and previous
**First Patched Version:** 86.0.4240.183
**Issue/Bug Report:**
* Project Zero: https://bugs.chromium.org/p/project-zero/issues/detail?id=2106
* Chromium: https://bugs.chromium.org/p/chromium/issues/detail?id=1143772
**Patch CL:** https://chromium.googlesource.com/v8/v8.git/+/3ba21a17ce2f26b015cc29adc473812247472776
**Bug-Introducing CL:** N/A
**Re
Project0
Project Zero RCA: CVE-2020-17087: Windows pool buffer overflow in cng.sys IOCTL
project_zero·CVSS 7.8
CVE-2020-17087 [HIGH] Project Zero RCA: CVE-2020-17087: Windows pool buffer overflow in cng.sys IOCTL
# CVE-2020-17087: Windows pool buffer overflow in cng.sys IOCTL
*Mateusz Jurczyk, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2021-02-04)*
## The Basics
**Disclosure or Patch Date:**
* Disclosure: 30 October 2020 by Google Project Zero
* Patch Date: 10 November 2020
**Product:** Microsoft Windows
**Advisory:** https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2020-17087
**Affected Versions:** For Windows 10 2004, [KB4579311](https://support.microsoft.com/en-us/help/4579311) and previous
**First Patched Version:** For Windows 10 2004, [KB4586781](https://support.microsoft.com/en-us/help/4586781/windows-10-update-kb4586781)
**Issue/Bug Report:** https://bugs.chromium.org/p/project-zero/issues/detail?id=2104
Project0
Project Zero RCA: CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png
project_zero·CVSS 9.6
CVE-2020-15999 [CRITICAL] Project Zero RCA: CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png
# CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png
*Sergei Glazunov, Project Zero (Originally posted on [Project Zero blog](https://googleprojectzero.blogspot.com/p/rca.html) 2021-02-04)*
## The Basics
**Disclosure or Patch Date:** 19 October 2020
**Product:** Google Chrome/ Freetype
**Advisory:** https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.html
**Affected Versions:** 86.0.4240.80 and previous
**First Patched Version:** 86.0.4240.111
**Issue/Bug Report:**
* Project Zero: https://bugs.chromium.org/p/project-zero/issues/detail?id=2103
* Chromium: https://bugs.chromium.org/p/chromium/issues/detail?id=1139963
* FreeType: https://savannah.nongnu.org/bugs/?59308
**Patch CL:**
* Chromium: https://chromium.googlesource.com/chromium/src
No detection rules found.
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
blogs_qualys·2022-02-23
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys
#### Table of Contents
- Situation
- Directive Scope
- CISA Catalog of Known Exploited Vulnerabilities
- Detect CISA Vulnerabilities Using Qualys VMDR
- CISA Exploited RTI
- Detailed Operational Dashboard
- Remediation
- Federal Enterprises and Agencies Can Act Now
- Summary
- Getting Started
CISA released a directive in November 2021, recommending urgent and prioritized remediation of actively exploited vulnerabilities. Both government agencies and corporations should heed this advice. This blog outlines how Qualys Vulnerability Management, Detection & Response can be used by any organization to respond to this directive efficiently and effectively.
## Situation
Last November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) released a Binding Operational Directiv
Sentinelone
6 Real-World Threats to Chromebooks and ChromeOS
blogs_sentinelone·2022-01-26·CVSS 9.6
[CRITICAL] 6 Real-World Threats to Chromebooks and ChromeOS
Chromebooks and ChromeOS have earned themselves a deserved reputation for being more secure than many other devices and operating systems, so much so that “Chromebooks don’t get viruses” is the new “Macs don’t get viruses”. But as many Mac users of the past will now tell you today, complacency in taking proper security measures is the first step on the path to compromise.
The popularity of Chromebooks among students and in educational institutions means they provide an enticing target to threat actors looking to scoop up PII for sale, or credentials to leverage in targeted attacks. Chromebooks may not have the same kind or number of security problems as, say, Windows devices, but that’s not to say there are not genuine threats that ChromeOS users need to be aware of.
## 1. Actors Activel
Sentinelone
6 Real-World Threats to Chromebooks and ChromeOS
blogs_sentinelone·2022-01-26·CVSS 9.6
[CRITICAL] 6 Real-World Threats to Chromebooks and ChromeOS
Chromebooks and ChromeOS have earned themselves a deserved reputation for being more secure than many other devices and operating systems, so much so that “Chromebooks don’t get viruses” is the new “Macs don’t get viruses”. But as many Mac users of the past will now tell you today , complacency in taking proper security measures is the first step on the path to compromise.
The popularity of Chromebooks among students and in educational institutions means they provide an enticing target to threat actors looking to scoop up PII for sale, or credentials to leverage in targeted attacks. Chromebooks may not have the same kind or number of security problems as, say, Windows devices, but that’s not to say there are not genuine threats that ChromeOS users need to be aware of .
## 1. Actors Activ
Krebs
Patch Tuesday, November 2020 Edition
blogs_krebs·2020-11-11·CVSS 9.6
[CRITICAL] Patch Tuesday, November 2020 Edition
Adobe and Microsoft each issued a bevy of updates today to plug critical security holes in their software. Microsoft’s release includes fixes for 112 separate flaws, including one zero-day vulnerability that is already being exploited to attack Windows users. Microsoft also is taking flak for changing its security advisories and limiting the amount of information disclosed about each bug.
Some 17 of the 112 issues fixed in today’s patch batch involve “critical” problems in Windows, or those that can be exploited by malware or malcontents to seize complete, remote control over a vulnerable Windows computer without any help from users.
Most of the rest were assigned the rating “important,” which in Redmond parlance refers to a vulnerability whose exploitation could “compromise the confiden
Trendmicro
November Patch Tuesday Fixes Exchange, NFS Vulns
blogs_trendmicro·2020-11-11·CVSS 9.6
[CRITICAL] November Patch Tuesday Fixes Exchange, NFS Vulns
Exploits & Vulnerabilities
# November Patch Tuesday Fixes Exchange, NFS Vulns
Comparing to last month’s update, which saw a noticeable drop to over 80 fixes, the total number of patches for this month increased again, with over a hundred patches released.
By: Trend Micro
2020/11/11
Read time: ( words)
Save to Folio
Microsoft’s Patch Tuesday for November had 112 patches, with 17 categorized as critical. Compared to last month’s update, which saw a noticeable drop to over 80 fixes, the total number of patches for this month increased again, with over a hundred patches released. Six of the vulnerabilities came through the Zero Day Initiative program. Details on the patches can be viewed on Microsoft’s Security Update Guide page.
Patch for recently disclosed zero-day CVE-2020-17087
Thi
Tenable
Microsoft’s November 2020 Patch Tuesday Addresses 112 CVEs including CVE-2020-17087
blogs_tenable·2020-11-10·CVSS 7.8
[HIGH] Microsoft’s November 2020 Patch Tuesday Addresses 112 CVEs including CVE-2020-17087
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Patch Tuesday, November 2020 Edition
blogs_krebs·2020-11-10·CVSS 9.6
[CRITICAL] Patch Tuesday, November 2020 Edition
Adobe and Microsoft each issued a bevy of updates today to plug critical security holes in their software. Microsoft’s release includes fixes for 112 separate flaws, including one zero-day vulnerability that is already being exploited to attack Windows users. Microsoft also is taking flak for changing its security advisories and limiting the amount of information disclosed about each bug.
Some 17 of the 112 issues fixed in today’s patch batch involve “critical” problems in Windows, or those that can be exploited by malware or malcontents to seize complete, remote control over a vulnerable Windows computer without any help from users.
Most of the rest were assigned the rating “important,” which in Redmond parlance refers to a vulnerability whose exploitation could “compromise the confiden
Sentinelone
Privilege Escalation Using CVE-2020-17087 & CVE-2020-15999
blogs_sentinelone·2020-11-04·CVSS 9.6
CVE-2020-15999 [CRITICAL] Privilege Escalation Using CVE-2020-17087 & CVE-2020-15999
A pair of zero-day vulnerabilities in Google Chrome (CVE-2020-15999) and Microsoft Windows (CVE-2020-17087) are being chained together and exploited to perform privilege escalation and gain administrator access to a system.
CVE-2020-15999 involves a type of memory-corruption vulnerability called a heap buffer overflow in Freetype, a popular open-source software development library for rendering fonts included with standard Chrome distributions.
CVE-2020-17087 involves the Windows Kernel Cryptography Driver (cng.sys) exposing a DeviceCNG device to user-mode programs and supports a variety of IOCTLs with non-trivial input structures. It constitutes a locally accessible attack surface that attackers can exploit for privilege escalation (such as sandbox escape).
Attackers can chain together
Sentinelone
Privilege Escalation Using CVE-2020-17087 & CVE-2020-15999
blogs_sentinelone·2020-11-04·CVSS 9.6
CVE-2020-17087 [CRITICAL] Privilege Escalation Using CVE-2020-17087 & CVE-2020-15999
A pair of zero-day vulnerabilities in Google Chrome (CVE-2020-15999) and Microsoft Windows (CVE-2020-17087) are being chained together and exploited to perform privilege escalation and gain administrator access to a system.
CVE-2020-15999 involves a type of memory-corruption vulnerability called a heap buffer overflow in Freetype, a popular open-source software development library for rendering fonts included with standard Chrome distributions.
CVE-2020-17087 involves the Windows Kernel Cryptography Driver (cng.sys) exposing a DeviceCNG device to user-mode programs and supports a variety of IOCTLs with non-trivial input structures. It constitutes a locally accessible attack surface that attackers can exploit for privilege escalation (such as sandbox escape).
Attackers can chain together
Tenable
CVE-2020-15999, CVE-2020-17087: Google Chrome FreeType and Microsoft Windows Kernel Zero Days Exploited in the Wild
blogs_tenable·2020-11-02·CVSS 9.6
[CRITICAL] CVE-2020-15999, CVE-2020-17087: Google Chrome FreeType and Microsoft Windows Kernel Zero Days Exploited in the Wild
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Checkpoint
26th October – Threat Intelligence Bulletin
blogs_checkpoint·2020-10-26
CVE-2020-3118 26th October – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 26th October – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 26th October 2020, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
Voter database in Hall Country, Georgia, used to verify voter signatures, has been breached by ransomware, alongside other government systems. This might be the first official election resource to be hit by ransomware. The ‘DoppelPaymer’ gang has claimed responsibility for the attack.
US officials warn against a R
Qualys
Vulnerability Detection Pipeline | Qualys
blogs_qualys·2020-09-16·CVSS 9.6
[CRITICAL] Vulnerability Detection Pipeline | Qualys
#### Table of Contents
- Browse, Filter and Search
- Detection Status
- Using the Detections Pipeline
- Whats Next
Update February 3, 2021: The Vulnerability Detection Pipeline is now GA (generally available). Results include a “last updated” timestamp.
Update October 22, 2020: The Vulnerability Detection Pipeline has been updated to include detections of all severities. It now gives visibility into upcoming and recently published detections with severity 3, 2 and 1 in addition to severity 5 and 4.
The pipeline also supports a URL parameter that identifies a specific CVE, e.g. https://community.qualys.com/vulnerability-detection-pipeline/#CVE-2020-15999. This is helpful if you want to share a specific entry with a colleague. The parameter must be in standard CVE format.
If a search on
Qualys
Vulnerability Detection Pipeline
blogs_qualys·2020-09-16·CVSS 9.6
[CRITICAL] Vulnerability Detection Pipeline
## Table of Contents
Browse, Filter and Search
Detection Status
Using the Detections Pipeline
Whats Next
Update February 3, 2021 : The Vulnerability Detection Pipeline is now GA (generally available). Results include a “last updated” timestamp.
Update October 22, 2020 : The Vulnerability Detection Pipeline has been updated to include detections of all severities. It now gives visibility into upcoming and recently published detections with severity 3, 2 and 1 in addition to severity 5 and 4.
The pipeline also supports a URL parameter that identifies a specific CVE, e.g. https://community.qualys.com/vulnerability-detection-pipeline/#CVE-2020-15999 . This is helpful if you want to share a specific entry with a colleague. The parameter must be in standard CVE format.
If a search on the
Sentinelone
Protecting Domain Controllers from CVE-2020-1472 ZeroLogon and Other Zero-Day Vulnerabilities
blogs_sentinelone·2020-09-16·CVSS 5.5
CVE-2020-1472 [MEDIUM] Protecting Domain Controllers from CVE-2020-1472 ZeroLogon and Other Zero-Day Vulnerabilities
Secura researchers have disclosed a vulnerability, CVE-2020-1472 Zerologon , that affects all Microsoft Windows Server versions, allowing attackers unauthenticated access to domain controllers, and has given it a CVSS score of 10.0.
They also published a technical analysis of the exploit, Proof of Concept (POC) code in a GitHub repository, that demonstrates a Netlogon authentication bypass. Essentially, the attack allows an external threat actor or malicious insider on the local network to compromise the Windows domain controller without any user authentication credentials.
The POC code requires passing the domain controller name and domain controller IP address to launch an attack.
./zerologon_tester.py EXAMPLE-DC 1.2.3.4
Attackers inside the network need to perform reconnaissance to
Bugzilla
CVE-2020-15999 freetype: heap-based buffer overflow via malformed ttf files [fedora-all]
bugzilla·2020-10-21·CVSS 9.6
CVE-2020-15999 [CRITICAL] CVE-2020-15999 freetype: heap-based buffer overflow via malformed ttf files [fedora-all]
CVE-2020-15999 freetype: heap-based buffer overflow via malformed ttf files [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple support
Bugzilla
CVE-2020-15999 freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png
bugzilla·2020-10-21·CVSS 9.6
CVE-2020-15999 [CRITICAL] CVE-2020-15999 freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png
CVE-2020-15999 freetype: Heap-based buffer overflow due to integer truncation in Load_SBit_Png
A flaw was found in freetype in the way it processes PNG images embedded into fonts. A crafted TTF file can lead to heap-based buffer overflow due to integer truncation in Load_SBit_Png function.
Reference:
https://savannah.nongnu.org/bugs/?59308
Upstream patch:
https://git.savannah.gnu.org/cgit/freetype/freetype2.git/commit/?id=a3bab162b2ae616074c8877a04556932998aeacd
Discussion:
Created freetype tracking bugs for this issue:
Affects: fedora-all [bug 1890211]
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 6 Supplementary
Via RHSA-2020:4351 https://access.redhat.com/errata/RHSA-2020:4351
---
This bug is now closed. Further updates for individual
Bugzilla
Heap buffer overflow due to integer truncation in FreeType
bugzilla·2020-10-20
Heap buffer overflow due to integer truncation in FreeType
Heap buffer overflow due to integer truncation in FreeType
Created attachment 9182663
crbug1139963.html
The Google Chrome team is fixing a heap buffer overflow in freetype. Although our library is called FreeType2 the affected code appears the same. I have not yet tested this in an ASAN build to verify if we are affected, but according to Google Project Zero they have found this being exploited in the wild (against Chrome, presumably)
Calling this sec-critical for now assuming we're affected, and setting the security group to the least-restrictive "Release Track" so it's visible to more people if we have to chemspill.
CREDIT: Sergei Glazunov of Google Project Zero
> * We have evidence that this bug is being used in the wild. *
> * Therefore, this bug is subject to a 7 day disclosure d
http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.htmlhttp://seclists.org/fulldisclosure/2020/Nov/33https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.htmlhttps://crbug.com/1139963https://googleprojectzero.blogspot.com/p/rca-cve-2020-15999.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7/https://security.gentoo.org/glsa/202011-12https://security.gentoo.org/glsa/202012-04https://security.gentoo.org/glsa/202401-19https://www.debian.org/security/2021/dsa-4824http://lists.opensuse.org/opensuse-security-announce/2020-11/msg00016.htmlhttp://seclists.org/fulldisclosure/2020/Nov/33https://chromereleases.googleblog.com/2020/10/stable-channel-update-for-desktop_20.htmlhttps://crbug.com/1139963https://googleprojectzero.blogspot.com/p/rca-cve-2020-15999.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/J3QVIGAAJ4D62YEJAJJWMCCBCOQ6TVL7/https://security.gentoo.org/glsa/202011-12https://security.gentoo.org/glsa/202012-04https://security.gentoo.org/glsa/202401-19https://security.netapp.com/advisory/ntap-20240812-0001/https://www.debian.org/security/2021/dsa-4824https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-15999
2020-11-03
Published
2021-11-03
Added to CISA KEV
Exploited in the wild