News

Attackers exploited a 0-day iTunes vulnerability to spread ransomware

MorphiSec specialists found that BitPaymer ransomware operators use the 0-day vulnerability in iTunes for Windows to distribute their malware, which allows them to trick anti-virus solutions on infected hosts.

The problem was discovered after studying the attack on an unnamed automobile industry enterprise that suffered from BitPaymer in August this year.

“We have identified the abuse of an Apple zero-day vulnerability in the Apple Software Update utility that comes packaged with iTunes for Windows. The Windows exploit is important to note given Apple is sunsetting iTunes for Macs with the release of macOS Catalina this week, while Windows users will still need to rely on iTunes for the foreseeable future”, — report MorphiSec experts.

Apple engineers have already fixed the problem by introducing updated versions of iTunes for Windows and iCloud for Windows this week.

The root of the vulnerability was the Bonjour update component, which comes with both products.

The bug allowed cybercriminals to launch Bonjour, and then interfere with its operation, forging the execution path so that it pointed to BitPaymer, instead of the necessary files. Although this vulnerability did not allow obtaining administrator rights, it successfully helped to deceive the installed locally protected software.

“The adversaries abused an unquoted path vulnerability. The unquoted path vulnerability is rarely seen in the wild, yet it is a well-known bug that has previously been identified by other vendors for more than 15 years. It is so thoroughly documented that you would expect programmers to be well aware of the vulnerability. But that is not that case, and this Apple zero-day is evidence”, — write MorphiSec researchers.

Apple Software Update, the mechanism that Apple uses to deliver future updates, includes one of these paths without quotes.

Solution:

At the same time, researchers warn that simply updating iTunes for Windows and iCloud for Windows may not be enough. The fact is that the Bonjour component remains installed on Windows even after iTunes or iCloud for Windows is completely uninstalled.

Read also: Researchers say about growing activity of TFlower, another ransomware that uses RDP

That is, users who previously used these applications, but then deleted them, are still vulnerable to a fresh 0-day vulnerability. To fix the problem, you will have to either remove Bonjour manually, or install the latest, safe version of iTunes for Windows to accurately update the old version of the component.

Polina Lisovskaya

I works as a marketing manager for years now and loves searching for interesting topics for you

Recent Posts

Remove Keyapp.monster Pop-up Ads

About Keyapp.monster Keyapp.monster pop-ups can not open out of nowhere. If you have actually clicked…

11 mins ago

Remove Withblaockbr.org Pop-up Ads

About Withblaockbr.org Withblaockbr.org pop-ups can not open out of nowhere. If you have clicked some…

12 mins ago

Remove Janorfeb.xyz Pop-up Ads

About Janorfeb.xyz Janorfeb.xyz pop-ups can not open out of nowhere. If you have clicked on…

24 hours ago

Remove Re-captha-version-3-263.buzz Pop-up Ads

About Re-captha-version-3-263.buzz Re-captha-version-3-263.buzz pop-ups can not launch out of the blue. If you have actually…

24 hours ago

Remove Usavserver.com Pop-up Ads

About Usavserver.com Usavserver.com pop-ups can not expose out of the blue. If you have clicked…

24 hours ago

Remove Yourgiardiablog.com Pop-up Ads

About Yourgiardiablog.com Yourgiardiablog.com pop-ups can not expose out of the blue. If you have actually…

1 day ago