Vulnerabilities associated with ransomware increased 4.5% in Q3 2021
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2009-3960 | Information Disclosure in Adobe BlazeDS (Used by LiveCycle and ColdFusion) CVE-2009-3960 is an information disclosure vulnerability in Adobe BlazeDS, the Java-based remoting and messaging layer that ships with Adobe LiveCycle and is available with Adobe ColdFusion. An attacker can trigger the flaw by sending crafted requests to an application running an affected BlazeDS deployment, gaining access to information that should not be exposed. Successful exploitation can leak sensitive data and, as observed in the Cring ransomware campaign against unpatched ColdFusion servers, can serve as an initial foothold that leads to further compromise and ransomware deployment. Organizations running BlazeDS as part of LiveCycle or ColdFusion deployments are affected. The flaw has been exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, with ransomware use explicitly confirmed and a very high EPSS of 90%. Do: Apply updates per vendor instructions as required by CISA, upgrading BlazeDS, LiveCycle, and ColdFusion to the patched releases specified in Adobe's advisory. Prioritize internet-facing ColdFusion and LiveCycle servers, verify BlazeDS-related endpoints are patched, and check for signs of compromise given known ransomware use. Until patched, restrict external access to BlazeDS/ColdFusion endpoints where feasible. | — | 90% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed ColdFusion/LiveCycle servers plausibly affected | |
| CVE-2010-2861 | Directory Traversal in Adobe ColdFusion Administrator Console CVE-2010-2861 is a directory traversal flaw (CWE-22) in the administrator console of Adobe ColdFusion that allows remote attackers to read arbitrary files on the server. It is triggered by sending crafted path-traversal input to the ColdFusion Administrator web interface, letting the attacker walk outside the intended directory. By reading sensitive files such as the server's configuration and administrator credential files, an attacker can obtain ColdFusion admin credentials and frequently escalate to broader system access. Any organization running an affected Adobe ColdFusion release is exposed, especially servers with the CFIDE administrator interface reachable from the internet. The flaw is actively exploited: it is in CISA's KEV (added 2022-03-25) with known ransomware use (including by the Cring gang), and EPSS puts 30-day exploitation probability at 99.7%. Do: Apply the ColdFusion updates per Adobe/vendor instructions as required by CISA, and if patching must wait, restrict or firewall access to the CFIDE administrator console (IP allowlisting or VPN only). Review web logs for path-traversal requests against the administrator console and check hosts for signs of ransomware or unauthorized changes, since exploitation is actively used for ransomware. | — | 100% | KEV ransomware |
| largetens of thousands of internet-exposed ColdFusion servers |
Full article656 words · extracted from helpnetsecurity.com · click to collapse
Ransomware groups are continuing to grow in sophistication, boldness, and volume, with numbers up across the board since Q2 2021, a report by Ivanti, Cyber Security Works and Cyware reveals.

This last quarter saw a 4.5% increase in CVEs associated with ransomware, a 4.5% increase in actively exploited and trending vulnerabilities, a 3.4% increase in ransomware families, and a 1.2% increase in older vulnerabilities tied to ransomware compared to Q2 2021.
12 new vulnerabilities tied to ransomware uncovered
The analysis uncovered 12 new vulnerabilities tied to ransomware in Q3 2021, bringing the total number of vulnerabilities associated with ransomware to 278. Out of the 12 vulnerabilities newly associated with ransomware, five are capable of remote code execution attacks and two are capable of exploiting web applications and being manipulated to launch denial-of-service attacks.
The report also revealed that ransomware groups are continuing to find and leverage zero-day vulnerabilities, even before the CVEs are added to the National Vulnerability Database and patches are released. For example, the REvil group discovered and exploited a vulnerability in Kaseya VSA software as the security team at the company was actively working on a patch.
The report also identified six new active and trending vulnerabilities associated with ransomware, bringing the total to 140, and five new ransomware families, bringing the total to 151. And these new ransomware groups quickly capitalized on some of the most dangerous vulnerabilities trending in the wild, such as PrintNightmare, PetitPotam and ProxyShell, in Q3.
Ransomware groups leveraging newer, more sophisticated techniques
The analysis also revealed that ransomware groups are leveraging newer, more sophisticated techniques, such as dropper-as-a-service and trojan-as-a-service, in attacks. Dropper-as-a-service allows newbie threat actors to distribute malware through programs that, when run, can execute a malicious payload onto a victim’s computer. Trojan-as-a-service, also called malware-as-a-service, enables anyone with an internet connection to obtain and deploy customized malware in the cloud, with zero installation.
Additionally, the report revealed three vulnerabilities belonging to 2020 or earlier became newly associated with ransomware in Q3 2021, bringing the total count of older vulnerabilities associated with ransomware to 258 – a whopping 92.4% of all vulnerabilities tied to ransomware. In Q3, the Cring ransomware group targeted two older vulnerabilities, CVE-2009-3960 and CVE-2010-2861, that have had patches for over a decade.
Srinivas Mukkamala, SVP of Security Products at Ivanti, said: “Ransomware groups continue to mature their tactics, expand their attack arsenals, and target unpatched vulnerabilities across enterprise attack surfaces. With this report, we aim to help organizations realize the security risk and vulnerability exposure of their environments and endpoints and provide actionable intelligence to remediate faster.
“It’s critical that organizations take a proactive, risk-based approach to patch management and leverage automation technologies to reduce the mean time to detect, discover, remediate, and respond to ransomware attacks and other cyber threats.”
Anuj Goel, CEO at Cyware said, “This research underscores that ransomware is continuing to evolve and is becoming more dangerous based on the catastrophic damage it can inflict on target organizations. What is more complex for many organizations is the inability of vertical industries to rapidly share specific IOC’s irrespective of their industry, in a way that is easy to curate, operationalize and disseminate to take action before an attack hits.
“Managing organizational risk means companies should be looking to a collective defense strategy to have continuously visibility into the attack and risk surfaces respectively, to reduce huge losses to reputation, customers, and finances. The more that cyber teams can tie into IT automation and processes, the better and more efficient they’ll be in countering ransomware.”
Aaron Sandeen, CEO of Cyber Security Works, said, “We continued to see ransomware attacks aggressively increase in sophistication and frequency in Q3. We also saw our customers increase their cyber security maturity and reduce their risks by working with us to continuously assess their vulnerabilities, incorporate our threat intelligence into their daily operations and decrease the time to complete remediation.”
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2021/11/10/vulnerabilities-associated-with-ransomware/