HomeSecurityDLL vulnerabilities in Autodesk, Trend Micro and Kaspersky

DLL vulnerabilities in Autodesk, Trend Micro and Kaspersky

Researchers have uncovered a set of DLL security vulnerabilities in Autodesk, Trend Micro, and Kaspersky programs.

On Monday, SafeBreach Labs published three security advisories describing the bugs, which were privately reported to vendors before being made public.

The first vulnerability, reported as CVE-2019-15628, affects Trend Micro Maximum Security version 16.0.1221 and below. One of the software, the Trend Micro Solution Platform service, coreServiceShell.exe, runs as NT AUTHORITY\SYSTEM with elevated permission levels and was the executable that researchers found.

Once coreServiceShell.exe is executed, a library – paCoreProductAdaptor.dll – is loaded. However, one DLL is missing, the lack of safe DLL loading and signed validation meant that attackers could exploit this security hole by loading unrelated DLLs.

The ability to load and execute arbitrary DLL files with signed, highly privileged software could lead to application bypass, evasion of cybersecurity , and potentially privilege escalation, researchers say.

“The vulnerability allows attackers to load and execute malicious payloads in a persistent manner, every time the service is loaded,” says SafeBreach Labs. “This means that once an attacker drops a malicious DLL in a vulnerable path, the service will load the malicious code every time it is restarted.”

DLL vulnerabilities in Autodesk, Trend Micro and Kaspersky

The second vulnerability disclosed affects Kaspersky Secure Connection, a virtual private network (VPN) client deployed with Kaspersky Internet Security solutions to create a secure connection to the vendor's servers.

Tracked as CVE-2019-15689, this bug can only be exploited if a hacker has already gained administrator privileges on versions of the software below 4.0.

The Kaspersky Secure Connection service also runs as NT AUTHORITY\SYSTEM and in the same way as the aforementioned Trend Micro issue, the Kaspersky Secure Connection 3.0.0 (KSDE) service searches for missing DLLs, opening a path for abuse via uncontrolled search paths and no signature validation.

Potentially suitable as part of a post-exploit chain, the vulnerability allows arbitrary DLL loading that is signed by AO Kaspersky Lab and is capable of running with elevated privileges.

The latest vulnerability, CVE-2019-7365, was discovered in Autodesk’s desktop app. The desktop app – AdAppMgrSvc.exe – is associated with Autodesk software from 2017 to the present and operates in the NT AUTHORITY\SYSTEM mode. A missing “DLL call” in a companion library also allowed arbitrary DLLs to be loaded. Additionally, there is no digital certificate validation, so unsigned DLLs can be executed.

“Once an attacker gains access to a computer, they may have limited privileges, which can limit access to certain files and data,” the researchers say. “The service gives them the ability to run as NT AUTHORITY\SYSTEM, which is the most powerful user in Windows, so they can access almost every file and process owned by the user on the computer.”

The vulnerabilities were reported to Trend Micro, Kaspersky, and Autodesk in July, with each security flaw confirmed in the same month or in August.

Update 15.49 GMT: A Trend Micro spokesperson said: “Trend Micro has issued a patch for these vulnerabilities which is currently available through the product’s automatic ActiveUpdate feature for all affected products.

Trend Micro asked for time beyond the usual 90-day policy and after fixing the issue, it issued a security on November 25. Kaspersky patched the bug and issued a security advisory on December 2. Autodesk has yet to issue an advisory. A Kaspersky spokesperson told ZDNet:

“Kaspersky has fixed a security issue identified in Kaspersky Secure Connection that could potentially allow third parties to execute arbitrary code. To exploit this flaw, an attacker must have rights and full control over the computer.

This security issue was fixed by Patch 2020 E, which was delivered to users through Kaspersky's automatic update processes. A restart is required to apply these updates. "

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS