{"id":102538,"date":"2022-04-21T11:32:09","date_gmt":"2022-04-21T13:32:09","guid":{"rendered":"https:\/\/teknomers.com\/fr\/hotpatch-damazon-pour-log4j-flaw-trouve-vulnerable-au-bogue-descalade-de-privileges\/"},"modified":"2022-04-21T11:32:15","modified_gmt":"2022-04-21T13:32:15","slug":"hotpatch-damazon-pour-log4j-flaw-trouve-vulnerable-au-bogue-descalade-de-privileges","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/hotpatch-damazon-pour-log4j-flaw-trouve-vulnerable-au-bogue-descalade-de-privileges\/","title":{"rendered":"Hotpatch d&#8217;Amazon pour Log4j Flaw trouv\u00e9 vuln\u00e9rable au bogue d&#8217;escalade de privil\u00e8ges"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>Le &#8220;hotpatch&#8221; publi\u00e9 par Amazon Web Services (AWS) en r\u00e9ponse aux vuln\u00e9rabilit\u00e9s Log4Shell pourrait \u00eatre exploit\u00e9 pour l&#8217;\u00e9chappement du conteneur et l&#8217;escalade des privil\u00e8ges, permettant \u00e0 un attaquant de prendre le contr\u00f4le de l&#8217;h\u00f4te sous-jacent.<\/p>\n<p>&#8220;Outre les conteneurs, les processus non privil\u00e9gi\u00e9s peuvent \u00e9galement exploiter le correctif pour augmenter les privil\u00e8ges et obtenir l&#8217;ex\u00e9cution du code racine&#8221;, a d\u00e9clar\u00e9 Yuval Avrahami, chercheur \u00e0 l&#8217;unit\u00e9 42 de Palo Alto Networks. <a rel=\"nofollow noopener\" href=\"https:\/\/unit42.paloaltonetworks.com\/aws-log4shell-hot-patch-vulnerabilities\/\" target=\"_blank\">mentionn\u00e9<\/a> dans un rapport publi\u00e9 cette semaine.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/backhub-dm3\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Les-logiciels-malveillants-piratant-les-medias-sociaux-se-propagent-via.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>Les probl\u00e8mes &#8211; <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-3100\" target=\"_blank\">CVE-2021-3100<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-3101\" target=\"_blank\">CVE-2021-3101<\/a>, <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-0070\" target=\"_blank\">CVE-2022-0070<\/a>et <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-0071\" target=\"_blank\">CVE-2022-0071<\/a> (scores CVSS : 8,8) \u2014 affectent la <a rel=\"nofollow noopener\" href=\"https:\/\/alas.aws.amazon.com\/announcements\/2021-001.html\" target=\"_blank\">solutions de correctifs<\/a> livr\u00e9s par AWS, et d\u00e9coulent du fait qu&#8217;ils sont con\u00e7us pour rechercher des processus Java et les corriger \u00e0 la vol\u00e9e contre la faille Log4j, mais sans garantir que les nouveaux processus Java sont ex\u00e9cut\u00e9s dans les limites impos\u00e9es au conteneur.<\/p>\n<p><iframe loading=\"lazy\" title=\"AWS Log4Shell Hot Patch Exploit Demo\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/jK9a7IoMu5I?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>&#8220;Tout processus ex\u00e9cutant un binaire nomm\u00e9 &#8216;java&#8217; &#8211; \u00e0 l&#8217;int\u00e9rieur ou \u00e0 l&#8217;ext\u00e9rieur d&#8217;un conteneur &#8211; est consid\u00e9r\u00e9 comme un candidat pour le hot patch&#8221;, a expliqu\u00e9 Avrahami.  &#8220;Un conteneur malveillant aurait donc pu inclure un binaire malveillant nomm\u00e9 &#8216;java&#8217; pour tromper la solution de patch \u00e0 chaud install\u00e9e en l&#8217;invoquant avec des privil\u00e8ges \u00e9lev\u00e9s.&#8221;<\/p>\n<p>Dans l&#8217;\u00e9tape suivante, les privil\u00e8ges \u00e9lev\u00e9s pourraient \u00eatre militaris\u00e9s par le processus &#8216;java&#8217; malveillant pour \u00e9chapper au conteneur et prendre le contr\u00f4le total du serveur compromis.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/crowdsec-tour-d\" target=\"_blank\" title=\"CyberSecurity\"><img loading=\"lazy\" decoding=\"async\" alt=\"La cyber-s\u00e9curit\u00e9\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/04\/1650021915_454_Haskers-Gang-donne-gratuitement-le-logiciel-malveillant-ZingoStealer-a-dautres.jpg\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Un processus malveillant non privil\u00e9gi\u00e9, de la m\u00eame mani\u00e8re, aurait pu cr\u00e9er et ex\u00e9cuter un binaire malveillant nomm\u00e9 &#8220;java&#8221; pour inciter le service hotpatch \u00e0 l&#8217;ex\u00e9cuter avec des privil\u00e8ges \u00e9lev\u00e9s.<\/p>\n<p>Les utilisateurs sont <a rel=\"nofollow noopener\" href=\"https:\/\/aws.amazon.com\/security\/security-bulletins\/AWS-2022-006\/\" target=\"_blank\">conseill\u00e9<\/a> de mettre \u00e0 niveau vers la version corrig\u00e9e \u00e0 chaud d\u00e8s que possible pour emp\u00eacher toute exploitation potentielle, mais uniquement apr\u00e8s avoir donn\u00e9 la priorit\u00e9 aux correctifs contre les failles Log4Shell activement exploit\u00e9es.<\/p>\n<p>&#8220;Les conteneurs sont souvent utilis\u00e9s comme fronti\u00e8re de s\u00e9curit\u00e9 entre les applications ex\u00e9cut\u00e9es sur la m\u00eame machine&#8221;, a d\u00e9clar\u00e9 Avrahami.  &#8220;Une fuite de conteneur permet \u00e0 un attaquant d&#8217;\u00e9tendre une campagne au-del\u00e0 d&#8217;une seule application et de compromettre les services voisins.&#8221;<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/04\/amazons-hotpatch-for-log4j-flaw-found.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Le &#8220;hotpatch&#8221; publi\u00e9 par Amazon Web Services (AWS) en r\u00e9ponse aux vuln\u00e9rabilit\u00e9s Log4Shell pourrait \u00eatre exploit\u00e9 pour l&#8217;\u00e9chappement du conteneur et l&#8217;escalade des privil\u00e8ges, permettant \u00e0 un attaquant de prendre le contr\u00f4le de l&#8217;h\u00f4te sous-jacent. &#8220;Outre les conteneurs, les processus non privil\u00e9gi\u00e9s peuvent \u00e9galement exploiter le correctif pour augmenter les privil\u00e8ges et obtenir l&#8217;ex\u00e9cution du [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":102539,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[6813,4168,4158,4165,4161,15112,28044,53445,53444,4157,4159,4171,4170,28860,4167,4160,4163,4162,185,53446,4172,4169,1677,4166,4164,4891],"class_list":["post-102538","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-bogue","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-damazon","tag-descalade","tag-flaw","tag-hotpatch","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-log4j","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-pour","tag-privileges","tag-securite-informatique","tag-securite-internet","tag-trouve","tag-violation-de-donnees","tag-vulnerabilite-logicielle","tag-vulnerable"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/102538","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=102538"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/102538\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/102539"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=102538"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=102538"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=102538"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}