Microsoft warns of MysterySnail on October Patch Tuesday
Summary
Windows users are on the trail of a MysterySnail as Microsoft patches a newly discovered zero-day under active exploitation that is being used to deliver a remote access trojan (RAT) to targets across multiple industries in a nation state-linked cyber espionage campaign. The vulnerability surfaced in late summer when Kaspersky’s automated detection technology thwarted a series of attacks using an elevation-of-privilege exploit on Microsoft Windows Server to try to deliver the MysterySnail malware. Tenable staff research engineer Satnam Narang drew attention to CVE-2021-39670, a spoofing vulnerability in Windows Print Spooler. “The severity is mitigated by the fact that attacks are limited to a ‘logically adjacent topology’, meaning that it cannot be exploited directly over the public internet. Both affect relatively new versions of Windows and are considered critical, allowing a VM to escape from guest to host by triggering a memory allocation error, allowing it to read kernel memory in the host.” Despite the headline bugs, October’s Patch Tuesday was notably lighter on both total and critical vulnerabilities, said Eric Feldman, senior product marketing manager at Automox.