ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Cisco, Hitachi, Microsoft, and Progress Flaws Actively Exploited—CISA Sounds Alarm

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-8639
Kernel-mode privilege escalation in Microsoft Windows Win32k

CVE-2018-8639 is an improper resource shutdown or release flaw (CWE-404) in the Windows Win32k kernel component. A local, authenticated attacker can trigger the faulty resource handling and leverage it to execute arbitrary code in kernel mode, the highest privilege level on a Windows system. Successful exploitation effectively yields full system control (SYSTEM-equivalent), making it useful both for escalating from a low-privileged foothold and as a step in post-compromise activity, including ransomware operations. All Microsoft Windows versions covered by the vendor's advisory for this CVE are affected; the source data does not specify exact version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2025-03-03 with known ransomware use, and EPSS estimates a 22.2% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

Do: Apply Microsoft's security updates for all affected Windows releases immediately per vendor instructions, prioritizing servers, shared workstations, and systems where untrusted users can run code, since the flaw is in the CISA KEV catalog with known ransomware use. Follow applicable BOD 22-01 guidance for cloud services, or discontinue use where mitigations are unavailable. Until patched, restrict local code execution by untrusted accounts and monitor for unusual privilege-escalation activity.

7.822% KEV ransomware
  • Microsoft Windows
masswell over 1 billion Windows installations worldwide
CVE-2022-43939
+1 in the same advisory: …43769
Authorization Bypass in Hitachi Vantara Pentaho Business Analytics Server

Hitachi Vantara Pentaho Business Analytics (BA) Server versions before 9.4.0.1 and 9.3.0.2, including all 8.3.x releases, enforce security restrictions using non-canonical URL checks (CWE-647), so an attacker can circumvent authentication and authorization with crafted, non-canonical URL variants. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1 score of 9.8), meaning a remote unauthenticated attacker can reach protected functionality simply by sending specially formed URLs to the server. A public proof-of-concept (published on Packet Storm) demonstrates the authentication bypass chained with server-side template injection (SSTI) to achieve code execution. Organizations running affected Pentaho BA Server versions — typically enterprises using the platform for BI reporting and analytics — are affected, particularly where the server is reachable from untrusted networks. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, confirming exploitation in the wild, and EPSS assigns it a 92.3% probability of exploitation within 30 days (100th percentile).

Do: Upgrade Pentaho BA Server to 9.4.0.1 or 9.3.0.2 or later; 8.3.x deployments are also affected and must move to a fixed release per Hitachi Vantara's guidance. Federal agencies must apply the required BOD 22-01 mitigations per the KEV listing (or discontinue use if mitigations are unavailable). All defenders should identify internet-exposed Pentaho instances, restrict access to trusted networks where possible, and hunt for indicators of the authentication bypass/SSTI exploitation chain.

9.8
group max
92% KEV PoC
  • Hitachi Vantara Pentaho Business Analytics (BA) Server All versions before 9.4.0.1 and before 9.3.0.2, including all 8.3.x releases
moderate≈1,000–10,000 deployments (estimate; no authoritative install count available)
CVE-2023-20118
Authenticated Command Injection in Cisco Small Business RV Series Routers

CVE-2023-20118 is a command injection flaw (CWE-77) in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers, caused by improper validation of user input within incoming HTTP packets. An authenticated remote attacker who already holds valid administrative credentials sends a crafted HTTP request to the management interface and can execute arbitrary commands with root-level privileges, gaining full device control and access to unauthorized data. All organizations running these six small-business router models are affected, and Cisco has stated it will not release any software update, leaving only a workaround. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, carries a high EPSS score of 54.1%, and news reporting around that period describes campaigns (e.g., ViciousTrap, which built a global honeypot from roughly 5,300 compromised devices) abusing Cisco router flaws, with botnet operators such as PolarEdge also targeting Cisco small-business routers. These end-of-service devices are therefore under active, in-the-wild exploitation and should be treated as high-priority for mitigation.

Do: No firmware fix will ever be released, so apply Cisco's workaround by disabling the affected feature or restricting the web management interface to trusted management hosts only (disable remote/internet-facing management). Check device logs and configurations for signs of compromise, including unexpected configuration changes or outbound connections indicating botnet implants. Because these routers are end-of-service, plan migration to supported models and, for federal agencies, follow BOD 22-01 mitigation guidance or discontinue use.

7.254% KEV
  • Cisco RV016 Router (firmware) all firmware versions; no patched release available
  • Cisco RV042 Router (firmware) all firmware versions; no patched release available
  • Cisco RV042G Router (firmware) all firmware versions; no patched release available
  • +3 more
largetens of thousands of internet-exposed devices (order-of-magnitude estimate; at least ~5,300 already confirmed compromised in one reported campaign)
CVE-2024-4885
Unauthenticated Path Traversal RCE in Progress WhatsUp Gold

CVE-2024-4885 is an unauthenticated path traversal vulnerability (CWE-22) in the WhatsUp.ExportUtilities.Export.GetFileWithoutZip function of Progress WhatsUp Gold, a network monitoring platform. An attacker can send a crafted request to the affected export/file-retrieval functionality to traverse outside the intended directory, which leads to execution of commands on the server. Successful exploitation yields remote code execution running with the privileges of the iisapppool\mconsole application pool identity, giving control of the WhatsUp Gold monitoring server and, potentially, a foothold in the network. All WhatsUp Gold versions released before 2023.1.3 are affected, meaning any organization running an unpatched on-premises deployment is exposed, especially if the web interface is reachable from untrusted networks. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-03, and its 99.3% EPSS probability reflects very high expected exploitation; no public PoC is known, though headlines indicate exploitation followed shortly after a proof-of-concept for this WhatsUp Gold flaw.

Do: Upgrade WhatsUp Gold to version 2023.1.3 or later, per Progress's advisories (which shipped patches for this and several related WhatsUp Gold flaws). Until patched, restrict access to the WhatsUp Gold web interface to trusted networks and review logs for unexpected requests to the export utility; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the KEV due date. Because the flaw is unauthenticated and exploited in the wild, treat any internet-facing, unpatched instance as compromised until verified.

9.899% KEV
  • progress whatsup gold all versions released before 2023.1.3
moderatelow thousands of internet-exposed WhatsUp Gold servers; total on-prem deployments plausibly in the tens of thousands

Indicators of compromiseAll →

TypeIndicatorContext
ipv49.3.0.2authorization decisions (Fixed in August 2024 with versions 9.3.0.2 and 9.4.0.1) CVE-2022-43769 (CVSS score: 8.8) - A special e
ipv49.4.0.1n decisions (Fixed in August 2024 with versions 9.3.0.2 and 9.4.0.1) CVE-2022-43769 (CVSS score: 8.8) - A special element injec
Full article444 words · extracted from thehackernews.com · click to collapse

The Hacker NewsMar 04, 2025Cyber Attack / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added five security flaws impacting software from Cisco, Hitachi Vantara, Microsoft Windows, and Progress WhatsUp Gold to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The list of vulnerabilities is as follows -

  • CVE-2023-20118 (CVSS score: 6.5) - A command injection vulnerability in the web-based management interface of Cisco Small Business RV Series routers that allows an authenticated, remote attacker to gain root-level privileges and access unauthorized data (Unpatched due to the routers reaching end-of-life status)
  • CVE-2022-43939 (CVSS score: 8.6) - An authorization bypass vulnerability in Hitachi Vantara Pentaho BA Server that stems from the use of non-canonical URL paths for authorization decisions (Fixed in August 2024 with versions 9.3.0.2 and 9.4.0.1)
  • CVE-2022-43769 (CVSS score: 8.8) - A special element injection vulnerability in Hitachi Vantara Pentaho BA Server that allows an attacker to inject Spring templates into properties files, allowing for arbitrary command execution (Fixed in August 2024 with versions 9.3.0.2 and 9.4.0.1)
  • CVE-2018-8639 (CVSS score: 7.8) - An improper resource shutdown or release vulnerability in Microsoft Windows Win32k that allows for local, authenticated privilege escalation, and running arbitrary code in kernel mode (Fixed in December 2018)
  • CVE-2024-4885 (CVSS score: 9.8) - A path traversal vulnerability in Progress WhatsUp Gold that allows an unauthenticated attacker to achieve remote code execution (Fixed in version 2023.1.3 in June 2024)

There are little-to-no reports about how some of the aforementioned flaws are weaponized in the wild, but French cybersecurity company Sekoia revealed last week that threat actors are abusing CVE-2023-20118 to rope susceptible routers into a botnet called PolarEdge.

As for CVE-2024-4885, the Shadowserver Foundation said it had observed exploitation attempts against the flaw as of August 1, 2024. Data from GreyNoise shows that as many as eight unique IP addresses from Hong Kong, Russia, Brazil, South Korea, and the United Kingdom are linked to the malicious exploitation of the vulnerability.

Lastly, the exploitation of CVE-2018-8639 was highlighted in early 2023 by AhnLab, attributing it to a Chinese hacking group named Dalbit (aka m00nlight) that leveraged the flaw for privilege escalation after gaining access to South Korean target networks by abusing flaws in SQL servers and dropping web shells for persistence.

In light of active exploitation, Federal Civilian Executive Branch (FCEB) agencies are urged to apply the necessary mitigations by March 24, 2025, to secure their networks.

Found this article interesting? This article is a contributed piece from one of our valued partners. Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/03/cisco-hitachi-microsoft-and-progress.html