Adobe, Microsoft and Citrix vulnerabilities draw warnings from CISA
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-29298 | Unauthenticated Access Control Bypass in Adobe ColdFusion (Actively Exploited) CVE-2023-29298 is an improper access control flaw (CWE-284) in Adobe ColdFusion that lets a remote, unauthenticated attacker reach ColdFusion's administrative CFM and CFC endpoints, bypassing the access controls meant to protect them. It is triggered directly over the network with no user interaction and no privileges required (CVSS 3.1: 7.5, high confidentiality impact). An attacker gains access to administrative endpoints as a security feature bypass; in practice, Adobe patched this flaw in the same July 2023 out-of-band update as a critical, actively exploited ColdFusion RCE, and it can be used to reach the server's admin surface. All Adobe ColdFusion deployments running 2018 Update 16 (and earlier), 2021 Update 6 (and earlier), or 2023.0.0.330468 (and earlier) are affected. Exploitation is confirmed in the wild: CISA added it to the KEV on 2023-07-20 and EPSS assigns a 99.8% probability of exploitation within 30 days. Do: Apply Adobe's July 2023 out-of-band ColdFusion updates immediately - upgrade beyond the affected builds (ColdFusion 2018 later than Update 16, e.g. Update 17; 2021 later than Update 6, e.g. Update 7; and the patched 2023 hotfix newer than build 330468) or follow Adobe's advisory instructions, as CISA requires mitigations or discontinuation of use for KEV entries. Until patched, restrict network access to ColdFusion Administrator/CFIDE endpoints from untrusted networks. Because no authentication or interaction is required, review access logs for unauthenticated requests to admin CFM/CFC endpoints and assume possible compromise on unpatched, internet-facing servers. | 7.5 | 100% | KEV |
| largetens of thousands of internet-exposed ColdFusion servers (roughly 10k-100k instances) | |
| CVE-2023-3519 | Unauthenticated RCE in Citrix NetScaler ADC and NetScaler Gateway CVE-2023-3519 is a critical (CVSS 9.8) unauthenticated remote code execution flaw caused by improper code-injection handling (CWE-94) in Citrix NetScaler ADC and NetScaler Gateway. A remote attacker with no credentials can trigger it by sending crafted requests to an appliance configured as a Gateway (VPN/ICA proxy/RDP proxy) or AAA authentication virtual server, gaining arbitrary code execution on the appliance. Exploitation typically yields a foothold behind the VPN edge — access to internal networks, credential theft, and follow-on activity such as espionage or ransomware deployment. Any organization running unpatched NetScaler ADC/Gateway appliances, especially internet-facing remote-access endpoints, is affected; NetScaler is one of the most widely deployed enterprise VPN/ADC platforms. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2023-07-19 with known ransomware use, EPSS estimates a 99.7% exploitation probability, and researchers have linked activity to China-nexus espionage (Silk Typhoon) and ransomware operations. Do: Immediately upgrade internet-facing NetScaler ADC/Gateway appliances to the fixed builds in Citrix's advisory (14.1-8.50+, 13.1-49.13+, 13.0-82.45+, 12.1-55.300+, including FIPS/NDcPP equivalents) — per CISA KEV, apply these mitigations or discontinue use if patching is unavailable. Confirm whether each appliance is configured as a Gateway or AAA virtual server (only those are affected), and hunt for compromise — unexpected configuration changes, unfamiliar accounts, webshells, or anomalous VPN sessions — rotating credentials on any suspected compromise. | 9.8 | 100% | KEV ransomware PoC |
| largetens of thousands of internet-exposed NetScaler Gateway/ADC appliances (order 10k-100k at disclosure), serving hundreds of thousands to millions of downstream… | |
| CVE-2023-36884 | Race Condition RCE in Microsoft Windows Search CVE-2023-36884 is a race condition (TOCTOU) vulnerability in Microsoft Windows Search that permits remote code execution, rated 7.5 (high) on CVSS 3.1. It is triggered over the network with user interaction — for example, when a user opens or interacts with a specially crafted document that causes the vulnerable search code path to race, allowing arbitrary code execution in the context of the current user. An attacker gains code execution on the victim's Windows system, which the RomCom threat actor chained with Firefox flaws to deploy backdoors against political targets, and CISA notes known ransomware use. Virtually every supported Windows client and server release at the time is affected, spanning Windows 10 1507 through 22H2, Windows 11 21H2/22H2, and Windows Server 2008 through 2022. The flaw was actively exploited as a zero-day before being fixed in the July 2023 Patch Tuesday; it was added to the CISA KEV catalog on 2023-07-17 and carries a 98.9% EPSS score (100th percentile). Do: Apply the July 2023 Patch Tuesday Windows security updates to all Windows 10, Windows 11, and Windows Server systems, prioritizing high-value and frequently attacked endpoints since the bug was exploited as a zero-day by RomCom and carries a KEV deadline (US civilian agencies were directed to remediate by August 1, 2023). Because exploitation requires user interaction, caution users against opening untrusted documents, and verify patch status via your patch management or vulnerability scanner against the KEV requirement. If patching is not possible, follow vendor mitigations per CISA's required action or discontinue use. | 7.5 | 99% | KEV ransomware |
| mass≈1 billion+ Windows devices (Windows 10/11 installed base) plus the enterprise Windows Server estate | |
| CVE-2023-38203 | Unauthenticated Deserialization RCE in Adobe ColdFusion (Actively Exploited) CVE-2023-38203 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in Adobe ColdFusion that can lead to arbitrary code execution. It is triggered over the network when an affected ColdFusion server processes crafted untrusted serialized data, and exploitation requires no authentication and no user interaction. A successful attacker gains arbitrary code execution with high impact on confidentiality, integrity, and availability of the host. Organizations running ColdFusion 2018 (Update 17 or earlier), ColdFusion 2021 (Update 7 or earlier), or ColdFusion 2023 (Update 1 or earlier) are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-08 with known ransomware use, EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile), and Adobe has shipped out-of-band patches in response. Do: Upgrade all ColdFusion 2018, 2021, and 2023 installations beyond the affected levels (at least past 2018u17, 2021u7, and 2023u1, using the latest update Adobe provides in its advisory). If patching must be delayed, apply the mitigations per Adobe's instructions, restrict or remove internet exposure of ColdFusion servers, and prioritize internet-facing hosts. Because exploitation is confirmed with known ransomware use, review ColdFusion logs and affected hosts for signs of exploitation, webshells, or follow-on malware, and discontinue use of the product if mitigations are unavailable per CISA's required action. | 9.8 | 97% | KEV ransomware |
| large~tens of thousands of internet-facing ColdFusion servers (order of 10,000-100,000 exposed instances); total install base including internal deployments is… |
Full article869 words · extracted from therecord.media · click to collapse
Products from Adobe, Microsoft and Citrix are being exploited by hackers, the Cybersecurity and Infrastructure Security Agency warned this week. In advisories and messages to the cybersecurity community, CISA urged users and administrators to apply the necessary patches as soon as possible due to confirmed reports that the vulnerabilities are being used in cyberattacks. The Adobe issues center around a product called ColdFusion, a popular commercial rapid web-application development computing platform. Cybersecurity experts at Rapid7 — who have been responding to multiple security incidents involving the bugs — initially discovered a bug labeled as CVE-2023-29298 before Adobe released a patch for the issue on July 11. By July 13, the researchers began to see exploitation of the bug alongside another vulnerability, later classified as CVE-2023-38203. Adobe patched CVE-2023-38203 on July 14 and CISA released a warning about the issue on July 18, warning that “an attacker can exploit some of these vulnerabilities to take control of an affected system.” “CISA encourages users and administrators to review the Adobe security release APSB23-41 and apply the necessary updates,” CISA said. But on Monday evening, Rapid7 said it discovered that the patch for CVE-2023-29298 is incomplete and that a “trivially modified exploit still works against the latest version of ColdFusion (released July 14).” An Adobe spokesperson told Recorded Future News that the company is aware the patch for the vulnerability can be bypassed and that developers are currently working on “a more comprehensive resolution.” “Our team will release an update as soon as it is available,” the spokesperson said. Rapid7 noted that the observed attacks involve both CVE-2023-29298 and CVE-2023-38203, so patching CVE-2023-38203 will protect against the exploit chain overall. Andrew Barratt, vice president of cybersecurity firm Coalfire, said those kinds of bugs are challenging to manage while patches are still under development because there are no direct workarounds. This means that other inline defenses, such as web application firewalls, will need to be tuned to the specific attack profile and signatures, which can be unreliable, Barratt said. The issue affecting Microsoft software — CVE-2023-36884 — has caused widespread concern within the cybersecurity community since it was announced by the company on July 11. Discovered by researchers from Google’s Threat Analysis Group and Volexity, the vulnerability does not have a patch yet but there are several mitigations that can be taken to protect against it. Microsoft confirmed that the bug has already been exploited in attacks, noting that it was used to target defense and government entities in Europe and North America through lures related to the Ukrainian World Congress. “Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents. An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim,” the tech giant said. “However, an attacker would have to convince the victim to open the malicious file. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This might include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs.” The vulnerability was used by a Russian cybercriminal group named RomCom that is exploiting it in advance of “opportunistic ransomware and extortion-only operations, as well as targeted credential-gathering campaigns likely in support of intelligence operations.” While no patch is available, Microsoft provided several mitigations to help protect against the bug’s exploitation. Action1’s Mike Walters said the vulnerability affects all versions of Windows Server from 2008 onwards; Windows 10; and Microsoft Word and Microsoft Office versions 2013 and later. “Given Microsoft’s confirmation of active exploitation and the absence of available workarounds, it is crucial to prioritize updating systems to address this vulnerability promptly,” Walters said. Other experts, like Immersive Labs’ Kev Breen, warned that the mitigations provided by Microsoft are “no substitute for patching, as attackers can find ways to bypass AV detections.” Microsoft did not respond to requests for comment about when a patch would be released. CISA is giving federal civilian agencies until August 7 to patch the vulnerability. Cloud computing giant Citrix released an urgent advisory on Tuesday about three vulnerabilities affecting a line of networking products named NetScaler ADC and NetScaler Gateway. The most serious vulnerability, CVE-2023-3519, has already been exploited in the wild, according to incident responders from Rapid7. The vulnerability carries a CVSS score of 9.8 and Citrix confirmed that exploits of it “on unmitigated appliances have been observed.” “Cloud Software Group strongly urges affected customers of NetScaler ADC and NetScaler Gateway to install the relevant updated versions as soon as possible,” the company said on Tuesday, a message echoed by CISA in an email to administrators. BleepingComputer reported that a zero-day vulnerability for Citrix ADC was being sold on an unnamed hacker forum earlier this month.Adobe ColdFusion issues
Microsoft Office vulnerability
Citrix zero-day
No previous article
No new articles
Jonathan Greig
is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-warnings-adobe-microsoft-citrix-vulnerabilities