"CISA Warns of Attacks Exploiting Cisco, Gigabyte Vulnerabilities"

The US Cybersecurity and Infrastructure Security Agency (CISA) has added two Cisco and four Gigabyte product flaws to its Known Exploited Vulnerabilities catalog.  Only one of the Gigabyte vulnerabilities was previously mentioned as being involved in attacks.  The Cisco product vulnerabilities are CVE-2020-3433 and CVE-2020-3153, impacting the AnyConnect Secure Mobility Client for Windows.  CISA noted that they can be exploited by a local, authenticated attacker to execute arbitrary code and copy files to arbitrary locations with elevated privileges.  Cisco’s advisories for CVE-2020-3433 and CVE-2020-3153 claim that the company is unaware of malicious exploitation.  However, CISA clarified in the past that it only adds vulnerabilities to its catalog if it has reliable evidence of exploitation.  CISA noted that given that the two security holes can only be exploited by an authenticated attacker, they are likely leveraged as part of a complex, multi-stage attack.  As for the Gigabyte vulnerabilities, they impact GPCIDrv and GDrv low-level drivers in the Gigabyte App Center, the Aorus graphics engine, the Xtreme gaming engine, and the OC Guru utility.  The vulnerabilities are tracked as CVE-2018-19323, CVE-2018-19322, CVE-2018-19321, and CVE-2018-19320.  The vulnerabilities can allow a local attacker to escalate privileges and potentially take complete control of the system.  While the bugs have a 2018 CVE, Gigabyte initially told the researchers who discovered them that its products were not impacted.  The motherboard manufacturer changed course in 2020 and took action to address the issues.  However, by the time Gigabyte released a security advisory for the vulnerabilities, Sophos had reported that a Gigabyte driver affected by CVE-2018-19320 had been exploited by Robinhood ransomware to remove security products from targeted devices before encrypting files.  CISA noted that there do not appear to be any other reports describing the exploitation of the Gigabyte driver vulnerabilities, but technical details, PoC exploits, and documents explaining how they can be weaponized are publicly available.
 

SecurityWeek reports: "CISA Warns of Attacks Exploiting Cisco, Gigabyte Vulnerabilities"

Submitted by Anonymous on