CISA adds 66 new flaws to the Known Exploited Vulnerabilities Catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-21999 | Local Privilege Escalation in Microsoft Windows Print Spooler (CISA KEV) CVE-2022-21999 is a privilege elevation vulnerability in the Windows Print Spooler service, caused by improper encapsulation of resources (CWE-40), which lets a local, limited-privilege user manipulate spooler resource handling and execute code with elevated rights. An attacker gains SYSTEM-level privileges on the affected Windows host after already obtaining some foothold locally, making it a common post-compromise escalation step rather than a remote entry point. Any Windows system with the Print Spooler service enabled — the default on most Windows desktop and server installations — is affected. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-03-25 with known ransomware use, and EPSS assigns a 41.7% chance of exploitation within 30 days (99th percentile), while the source data records no public proof-of-concept. Required action per CISA is to apply Microsoft updates per vendor instructions. Do: Apply the vendor security updates per Microsoft's instructions, as required by CISA's KEV listing; since the source data does not specify fixed versions, verify your current Windows build against Microsoft's advisory. As an interim mitigation, disable the Print Spooler service on hosts where local or shared printing is not required. Because the flaw is exploited in the wild and linked to ransomware, check spooler-related privilege escalation activity in logs and prioritize patching servers and workstations accessible to low-privileged users. | 7.8 | 42% | KEV ransomware |
| masshundreds of millions of Windows devices (Print Spooler enabled by default on most desktop/server installs) | |
| CVE-2022-26143 | Unauthenticated access flaw in Mitel MiCollab and MiVoice Business Express (TP-240) CVE-2022-26143 is a missing-authentication flaw (CWE-306) in the TP-240 (tp240dvr) component of Mitel MiCollab and MiVoice Business Express that allows any unauthenticated remote attacker to interact with the component over the network. By sending crafted requests, an attacker can obtain sensitive information and trigger performance degradation plus excessive outbound traffic from the appliance, with no privileges or user interaction required. The outbound-traffic behavior was abused in February and March 2022 in the TP240PhoneHome DDoS technique, in which vulnerable Mitel appliances were turned into powerful amplifiers, with public reporting describing amplification by a factor of roughly 4 billion. Organizations running MiCollab versions before 9.4 SP1 FP1 or MiVoice Business Express version 8.1 or earlier are affected, especially when the appliance is internet-reachable. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-03-25 and carries an EPSS of 87.2% (100th percentile). Do: Upgrade MiCollab to 9.4 SP1 FP1 (or later) and apply Mitel's current update for MiVoice Business Express 8.1, per vendor instructions as required by CISA's KEV catalog. Until patched, restrict internet exposure of the appliance and the TP-240/tp240dvr service via firewall rules or ACLs, and check logs for unexplained outbound traffic spikes or inbound probes to the component, which would indicate the system is being abused as a DDoS amplifier. | 9.8 | 87% | KEV PoC |
| largeon the order of 10,000+ internet-exposed Mitel appliances (public reporting of the 2022 abuse campaign indicated roughly 12,000 vulnerable devices were… | |
| CVE-2022-26318 | Unauthenticated RCE in WatchGuard Firebox and XTM Fireware OS CVE-2022-26318 (vendor tracker FBX-22786) is a critical (CVSS 9.8) unauthenticated arbitrary code execution vulnerability in Fireware OS running on WatchGuard Firebox and XTM security appliances. An unauthenticated remote attacker can trigger it by sending crafted requests to network-facing services on an affected appliance, requiring no credentials or user interaction. Successful exploitation allows execution of arbitrary code with high impact on confidentiality, integrity, and availability, typically yielding full control of the perimeter device and a foothold into the internal network behind it. Any organization running Fireware OS in the affected ranges — before 12.7.2_U2, 12.x before 12.1.3_U8, or 12.2.x through 12.5.x before 12.5.9_U2 — is exposed, a population dominated by SMB and mid-market perimeter firewall/VPN deployments. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-03-25, and press reporting of the period links Russian GRU (Sandworm) activity to exploitation of network edge devices of this kind. Do: Apply the vendor's updates per branch guidance: upgrade Fireware OS to 12.7.2_U2, 12.1.3_U8, or 12.5.9_U2 (or later) as applicable to your release train. Because the flaw is on CISA's KEV list, check whether the appliance's management or other interfaces are internet-exposed, review logs and configuration for signs of compromise, and consider a factory reset or re-image for appliances showing evidence of intrusion, since patching alone may not remove attacker persistence. Organizations in energy and other targeted sectors should prioritize remediation given reported GRU activity against edge devices. | 9.8 | 78% | KEV |
| mass~100,000-300,000 internet-exposed Firebox/XTM appliances per public scan counts; vendor-reported install base of 1M+ appliances |
Full article268 words · extracted from securityaffairs.com · click to collapse

The US Cybersecurity and Infrastructure Security Agency (CISA) added 66 new flaws to its Known Exploited Vulnerabilities Catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added 15 vulnerabilities to its Known Exploited Vulnerabilities Catalog.ⓘ
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
The new vulnerabilities added to the catalog have to be addressed by federal agencies by April 15, 2022.
The oldest flaws in the set of 66 recently added issues are dated back to 2005.
One of the 66 flaws added to the catalog is the recently discovered Windows CVE-2022-21999 vulnerability, which is a Windows Print Spooler Elevation of Privilege bug. Microsoft addressed this bug with the release of the February 2022 Patch Tuesday updates.
Another issue added to the catalog, tracked as CVE-2022-26318, is an arbitrary code execution in WatchGuard Firebox and XTM Appliances.
CISA also added the CVE-2022-26143 vulnerability affecting Mitel MiCollab and MiVoice Business Express that can be exploited by a threat actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.
The CISA Catalog has reached a total of 570 entries with the latest added issues.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, CISA)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/129502/hacking/cisa-known-exploited-vulnerabilities-catalog-66.html