LastPass Fixes Ormandy RCE Bug; Two Outstanding Vulnerabilities Remain

LastPass Fixes Ormandy RCE Bug; Two Outstanding Vulnerabilities Remain

LastPass has reportedly fixed a remote code execution in the password manager that could have allowed for the proxying of internal Remote Procedure Ca

Inside the CCleaner Backdoor Attack
Motivation Mystery Behind WannaCry, ExPetr
“Lawful Intercept” Pegasus Spyware Found Deployed In 45 Countries

LastPass has reportedly fixed a remote code execution in the password manager that could have allowed for the proxying of internal Remote Procedure Call (RPC) commands.

The issue is one of three vulnerabilities–the other two remain unpatched–discovered in the service during the past week by Google Project Zero researcher Tavis Ormandy.

Ormandy said Tuesday night on Twitter that he uncovered a different bug in LastPass that allows for the theft of passwords for any domain. Little is known about the vulnerability other than it exists in version 4.1.35 and is unpatched.

LastPass, for its part, acknowledged Ormandy’s remote code execution bug early Tuesday morning and said it had put a workaround in place. It said it resolved the bug later yesterday morning and that it was working on a blog post to recap additional details around the vulnerability.

Ormandy sent details of an exploit he wrote for the vulnerability, just two lines of JavaScript, to LastPass on Monday. While the exploit was written to work without prompts, he said on Twitter it could be adapted to work on other platforms such as Linux.

The researcher said he discovered the bug, which affects version 4.1.42 of the service on Chrome and Firefox, after noticing an entry in the service’s websiteconnector.js content script that can proxy unauthenticated window messages to the extension.

The researcher said that on its own, the bug could allow for the access of internal privileged RPCs, something that could in turn allow “complete control of the LastPass extension, including stealing passwords.” If a user had Binary Component installed, an attacker could use “openattach” to run arbitrary code.

Ormandy warned of another vulnerability–the third for those keeping track–that affects version 3.3.2 of LastPass’ Firefox add-on last Wednesday. Details around the bug aren’t public yet, but Ormandy posted a redacted screenshot of the exploit last week when he tweeted about the vulnerability.

It took a few days but the company confirmed it was aware of a vulnerability that affected a Firefox add-on, presumably the same issue Ormandy raised to the company, on Tuesday night.

If the company addresses the other two bugs as quickly as it addressed the first, users should expect a fix fairly soon, sometime this week.

As Ormandy pointed out on Twitter Tuesday, Firefox add-ons customarily have to undergo a review by Mozilla before they’re pushed live, something which could be holding up the fix.

That said, it’s unclear exactly when the company plans on fixing the Firefox add-on issue, publishing details around the RCE vulnerability, or acknowledging the bug Ormandy found in 4.1.35. LastPass did not immediately return a request for comment on Wednesday morning.

Since LastPass patched the issue, details around the bug, including a link to Ormandy’s exploit, were made public by Google’s Project Zero on Tuesday. Under Project Zero guidelines, Google releases bug reports either 90 days after a private disclosure, or after a patch has been made broadly available.

Tod Beardsley, research director at Rapid7 thought releasing details around the bug so quickly after disclosing it to the company was a head scratcher however.

“It’s a little puzzling why Google publicly disclosed this issue merely 37 hours after the initial private disclosure to LastPass,” Beardsley said Wednesday, “The issue doesn’t appear to be so grave as to warrant a fast track to disclosure, and even if it was, I would generally expect at least a couple days’ of grace period to allow for a more coordinated disclosure.”

Regardless, the issues appear to be the latest among several bumps in the road for the password manager, especially when it comes to bugs identified by the Project Zero researcher. Ormandy made headlines last summer after he said on Twitter that he had found “a bunch of obvious critical problems” in the service. LastPass was quick to fix the most concerning issue, which like this week’s, could have allowed access to privileged LastPass RPCs, but also led to a complete remote compromise.

Go to Source