In this week's Security Advisory:
Our Threat Intelligence team has observed an uptick in attackers focusing on Palo Alto's GlobalProtect VPN service to exploit authentication weaknesses. Organizations that apply Multi-Factor Authentication (MFA) only to the GlobalProtect Portal, while neglecting to enforce it on the Gateway, are susceptible to this attack. This misconfiguration can allow attackers to bypass MFA checks by directly connecting to the Gateway using open-source VPN clients. Successful exploitation grants threat actors unauthorized access to the internal network. Customers must implement MFA consistently across both Portals and Gateways in GlobalProtect to mitigate risks associated with authentication bypass attempts.
Mitigation
More Reading/Information
A high-severity vulnerability has been discovered in the OpenSSH Server (sshd) that impacts versions bundled with Red Hat Enterprise Linux, Identified as CVE-2024-6409 with a CVSS score of 7.0, this flaw enables attackers to execute remote code as an unprivileged user. Customers should update to the latest security patch released by Red Hat. It's worth noting that CVE-2024-6409 is a separate vulnerability to the previously released advisory regarding CVE-2024-6387 from earlier last week.
More Reading/Information
Security researchers have discovered a critical vulnerability in the RADIUS protocol, a widely used authentication an authorization protocol in network devices. The vulnerability has been given the name "BlastRADIUS" and allows attackers to intercept and modify access-request packets that can bypass multi-factor authentication (MFA) through Man-in-the-Middle attacks. Successful exploitation can allow a threat actor to authenticate any user to the local network. Researchers have already developed a proof-of-concept (POC) and a public release is expected soon.
More Reading/Information
This month's Patch Tuesday includes fixes for over one hundred and forty-two (142) vulnerabilities, including two (2) actively exploited zero-days. CVE-2024-38080 is a privilege escalation vulnerability within Windows Hyper-V that can allow an attacker to gain SYSTEM level privileges, while CVE-2024-38112 is a spoofing vulnerability within the MSHTML platform.
Patch Tuesday also includes updates to address five (5) critical remote code execution flaws affecting Microsoft SharePoint, Windows Imaging Component, Windows Desktop Licensing Service and Remote Desktop.
More Reading/Information
Mozilla released security updates to address vulnerabilities in several of its products that could lead to arbitrary code execution. There was a total of twenty-one (21) vulnerabilities affecting Firefox and Firefox ESR, with five (5) receiving a severity rating of "High." These affect Firefox versions prior to 115.13 and Firefox ESR versions prior to 128.
Adobe has released patches for seven (7) vulnerabilities, six (6) of which are rated as "Critical" and allow for arbitrary code execution. These vulnerabilities impact Adobe Premiere Pro, InDesign, and Bridge.
More Reading/Information
Please review your environment to ensure the above-mentioned issues are patched in a timely manner. It is security best practice to regularly update and/or patch software to the latest versions. The vulnerabilities above highlight the security benefits of limiting deployed software to "vendor-supported versions" only. This dramatically increases the likelihood that new vulnerabilities have a patch issued for them. Likewise, Cybersafe strongly encourages maintaining an inventory of current software in your environment, which helps ensure and inform your patch and vulnerability management program.