Article Details

Scrape Timestamp (UTC): 2024-02-13 04:57:13.381

Source: https://thehackernews.com/2024/02/alert-cisa-warns-of-active-roundcube.html

Original Article Text

Click to Toggle View

Alert: CISA Warns of Active 'Roundcube' Email Attacks - Patch Now. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a medium-severity security flaw impacting Roundcube email software to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The issue, tracked as CVE-2023-43770 (CVSS score: 6.1), relates to a cross-site scripting (XSS) flaw that stems from the handling of linkrefs in plain text messages. "Roundcube Webmail contains a persistent cross-site scripting (XSS) vulnerability that can lead to information disclosure via malicious link references in plain/text messages," CISA said. According to a description of the bug on NIST's National Vulnerability Database (NVD), the vulnerability impacts Roundcube versions before 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3. The flaw was addressed by Roundcube maintainers with version 1.6.3, which was released on September 15, 2023. Zscaler security researcher Niraj Shivtarkar has been credited with discovering and reporting the vulnerability. It's currently not known how the vulnerability is being exploited in the wild, but flaws in the web-based email client have been weaponized by Russia-linked threat actors like APT28 and Winter Vivern last year. U.S. Federal Civilian Executive Branch (FCEB) agencies have been mandated to apply vendor-provided fixes by March 4, 2024, to secure their networks against potential threats. ⚡ Free Risk Assessment from Vanta Generate a gap assessment of your security and compliance posture, discover shadow IT, and more.

Daily Brief Summary

CYBERCRIME // U.S. CISA Flags Actively Exploited Roundcube Email Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in Roundcube, a popular email software, to its list of actively exploited flaws.

The vulnerability, identified as CVE-2023-43770, is a medium-severity cross-site scripting (XSS) issue discovered by a Zscaler researcher, Niraj Shivtarkar.

Attackers exploit this flaw by manipulating 'linkrefs' in plain text emails, leading to potential information disclosure.

Roundcube has released patches for the affected versions (prior to 1.4.14, 1.5.x before 1.5.4, and 1.6.x before 1.6.3) with the latest update being version 1.6.3 on September 15, 2023.

Though specific exploitation methods are not detailed, similar vulnerabilities have previously been exploited by Russia-linked threat actors such as APT28 and Winter Vivern.

CISA has mandated U.S. Federal Civilian Executive Branch (FCEB) agencies to implement the necessary patches by March 4, 2024, to mitigate risks from this threat.

Organizations are urged to update their Roundcube software immediately to prevent exploitation and secure their email communications.