ZeroHour
Cisco Talospublished ()ingested

Patch it up: Old vulnerabilities are everyone’s problems

highVulnerability exploited in the wildimportance 60CVE-2025-22224CVE-2024-4577

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-4577
OS Command Injection in Windows PHP-CGI Allows Remote Code Execution

CVE-2024-4577 is an OS command injection flaw (CWE-78) in Windows-based PHP when it runs in CGI mode, allowing arbitrary code execution on the server. It is triggered when attacker-supplied characters in HTTP requests are mishandled by Windows' character-encoding conversion as the OS invokes php-cgi, letting attackers inject command-line arguments to the PHP interpreter; this bypasses the decade-old fix for CVE-2012-1823. A successful attacker gains the ability to run arbitrary commands and code in the context of the web server. Affected systems are PHP running on Windows through the CGI interface; deployments that do not use PHP-CGI on Windows are not described as affected in the source data. Exploitation is active: the flaw was added to CISA KEV on 2024-06-12 with known ransomware use, and EPSS assigns roughly 100% probability of exploitation within 30 days.

Do: Per the CISA KEV required action, apply mitigations per vendor instructions or discontinue use: upgrade Windows PHP-CGI deployments to a PHP release that fixes CVE-2024-4577 per PHP Group advisories, or stop using CGI mode on Windows (e.g., switch to FastCGI) and apply any vendor-recommended workarounds. Given known ransomware abuse, review web server access logs for exploitation attempts (notably %AD-encoded soft hyphens and injected -d/-s arguments in php-cgi query strings) and prioritize patching internet-facing Windows hosts.

9.8100% KEV ransomware PoC ×11
  • PHP Group PHP
large≈10,000–100,000 internet-exposed Windows PHP-CGI systems
CVE-2025-22224
TOCTOU Out-of-Bounds Write in VMware ESXi and Workstation Enables Guest-to-Host Escape

VMware ESXi and Workstation contain a time-of-check to time-of-use (TOCTOU) race condition (CWE-367) that can lead to an out-of-bounds write in the virtual machine's VMX process. To trigger it, a malicious actor needs local administrative privileges inside a guest virtual machine, where the race condition between the host's check and use of a resource can be exploited. Successful exploitation executes code as the VMX process on the host - effectively a guest-to-host escape, since the VMX process runs with host-level privileges on ESXi - reflected in the CVSS 3.1 score of 8.2 with changed scope. Affected products per the available data are VMware ESXi and Workstation, plus VMware Cloud Foundation and VMware Telco Cloud Infrastructure/Platform, which bundle the affected components; specific affected or fixed version ranges are not stated in the provided data. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-04, confirming active in-the-wild exploitation (ransomware use is listed as unknown), though no public proof-of-concept code is known.

Do: Upgrade ESXi, Workstation, VMware Cloud Foundation, and Telco Cloud deployments to the patched releases identified in Broadcom's security advisory (fixed version numbers are not present in the provided data, so confirm them directly in the advisory); because the flaw is on CISA KEV, BOD 22-01-bound organizations must apply vendor mitigations or patches by the KEV deadline or discontinue use of the product. As an interim measure, restrict local administrative privileges inside guest VMs to trusted users only, since guest admin access is the prerequisite for exploitation. Prioritize hosts that are internet-reachable or multi-tenant, where untrusted users are more likely to hold guest admin rights.

8.22% KEV
  • VMware ESXi
  • VMware Workstation
  • VMware Cloud Foundation
  • +2 more
masson the order of 100,000+ internet-exposed ESXi hosts, with the total ESXi/Workstation install base plausibly in the hundreds of thousands to millions

Indicators of compromiseAll →

TypeIndicatorContext
md52915b3f8b703eb744fc54c81f4a9c67fd393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f VirusTotal: https://www.virustotal.com/gui/file/9f1f11a708d
md571fea034b422e4a17ebb06022532fdde6b26fe18d9759a9392bce81ba379817c53a3a468fe9060a076f8ca MD5: 71fea034b422e4a17ebb06022532fdde VirusTotal: https://www.virustotal.com/gui/file/47ecaab5cd6
md57abf12ab98f4cbed63228bba977cea7ebfbdf20520a9e7705f60a54ff2d0a94d72e4c26fc2aee55a158a9f MD5: 7abf12ab98f4cbed63228bba977cea7e VirusTotal: https://www.virustotal.com/gui/file/9c60480afbb
md57bdbd180c081fa63ca94f9c22c45737683227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 VirusTotal: https://www.virustotal.com/gui/file/a31f222fc28
sha25647ecaab5cd6b26fe18d9759a9392bce81ba379817c53a3a468fe9060a076f8caoduct: N/A Detection Name: W32.9C60480AFB-95.SBX.TG SHA256: 47ecaab5cd6b26fe18d9759a9392bce81ba379817c53a3a468fe9060a076f8ca MD5: 71fea034b422e4a17ebb06022532fdde VirusTotal: https://w
sha2569c60480afbbfbdf20520a9e7705f60a54ff2d0a94d72e4c26fc2aee55a158a9fduct: N/A Detection Name: Win.Worm.Coinminer::1201 SHA 256: 9c60480afbbfbdf20520a9e7705f60a54ff2d0a94d72e4c26fc2aee55a158a9f MD5: 7abf12ab98f4cbed63228bba977cea7e VirusTotal: https://w
sha2569f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507ware files from Talos telemetry over the past week SHA 256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507 MD5: 2915b3f8b703eb744fc54c81f4a9c67f VirusTotal: https://w
sha256a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91N/A Detection Name: Coinminer:MBT.26mw.in14.Talos SHA 256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91 MD5: 7bdbd180c081fa63ca94f9c22c457376 VirusTotal: https://w
Full article990 words · extracted from blog.talosintelligence.com · click to collapse

Thursday, March 13, 2025 14:04

Welcome to this week’s edition of the Threat Source newsletter.

Let's pick up where we left off in my last newsletter. Please mark your calendars: The free support for Windows 10 will end on October 14, 2025.

When a software loses vendor support, it no longer receives patches or updates. As highlighted in my previous newsletter, the top method for initial access in the last quarter of 2024 was exploiting vulnerabilities in public-facing applications. While Windows 10 isn't typically (or shouldn't be) a public-facing application, unpatched client systems become prime targets for bad actors as they progress through the stages of an attack: Execution, Privilege Escalation, Defense Evasion, Credential Access, and Lateral Movement.

In last week’s newsletter, my colleague Martin asked, "Who is responsible, and does it matter?" As a thought exercise, let's flip the script and ask, "Where is the victim, and does it matter?" I often field questions about threats specific to countries, regions, or continents, but the reality is that software is largely the same regardless of physical location. Yes, there are different language packs, and yes, spam and phishing campaigns may use local languages. However, when it comes to software, operating systems, libraries, and drivers, we share code globally.

Remember Log4j and NotPetya? These vulnerabilities caused chaos around the globe. Both have CVEs listed in the Known Exploited Vulnerabilities (KEV) catalog, which is maintained by the Cybersecurity and Infrastructure Security Agency (CISA).

While researching the KEVs added in 2024, I discovered CVEs dating back to 2012, 2013, and 2014. This underscores that regardless of location, old vulnerabilities can remain relevant and dangerous years after their discovery.

Fast forward to 2025: CVE-2025-22224 was published on Mar. 4, 2025 and added to CISA's KEV Catalog less than two hours later. A week later, over 40,000 vulnerable instances were still detected globally, as shown on the Shadowserver dashboard:

Rather than solely focusing on geography, the global vulnerability landscape suggests we should ask ourselves:

·       "Am I running this software?"
·       “Is my software up to date?"
·       "How quickly can I fix it?"
·       Or, for the brave, "Am I prepared to take the risk?"

While more attributes for CVEs may be beneficial, I personally believe the absence of a geographic attribute is a good thing. Patching and updating software should be prioritized regardless of nationality or geographic context. When it comes to maintaining robust cybersecurity, the only good vulnerability is no vulnerability.

Remember: In the digital world, we're all neighbors. A vulnerability anywhere is a threat just around the corner.

The one big thing

Cisco Talos discovered malicious activities conducted by an unknown attacker as early as January 2025, predominantly targeting organizations in Japan. The attacker exploited a vulnerability, CVE-2024-4577, a remote code execution (RCE) flaw in the PHP-CGI implementation of PHP on Windows, to gain initial access to victim machines.

Why do I care?

We reported an increasing trend of threat actors exploiting vulnerable public facing applications for initial access in our quarterly Talos Incident Response report for Q4 2024, and this intrusion highlights this ongoing activity. In this case, the attacker establishes persistence by modifying registry keys, adding scheduled tasks, and creating malicious services using the plugins of the Cobalt Strike kit called “TaoWu.”

So now what?

This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see the National Vulnerability Database. Here are the Snort SIDs for this threat:

·       Snort 2: 64632, 64633, 64630, 64631
·       Snort 3: 301157, 301156

Top security headlines of the week

· The Bluetooth “backdoor” that wasn’t. The original title, “Undocumented backdoor found in Bluetooth chip used by a billion devices,” was updated to a more precise description: “Undocumented commands found in Bluetooth chip used by a billion devices.” (Bleepingcomputer) (Darkmentor)

· A ransomware gang leveraged a vulnerable IP camera in an attack, effectively circumventing Endpoint Detection and Response (EDR). The “Mr. Monk” in me wants to point out that while the article title says “webcam” — which, in my definition, is a camera connected internally or via USB to a PC — the article discusses Linux and SMB shares, which suggests it is an IP camera.  (Bleepingcomputer)

· Massive alleged cyber attack against X (formerly Twitter). This past Monday, a series of outages left X unavailable for thousands of users for at least one hour. Not all details are currently known to the public. (Securityweek)

Can’t get enough Talos?


Cascading Style Sheets (CSS) are ever present in modern day web browsing, however it's far from their own use. Read our latest blog on Abusing with style: Leveraging cascading style sheets for evasion and tracking.

Cisco Talos discovered malicious activities conducted by an unknown attacker since as early as January 2025, predominantly targeting organizations in Japan. Read the full blog here: Unmasking the new persistent attacks on Japan

Upcoming events where you can find Talos

· DEVCORE (March 15, 2025) Taipei, Taiwan. Ashley Shen will give a talk on exploit hunting.
· RSA (April 28-May 1, 2025)  San Francisco, CA
· PIVOTcon (May 7-May 9, 2025) Malaga, Spain. Ashley Shen and Vitor Ventura will present "Redefining IABs: Impacts of Compartmentalization on Threat Tracking & Modeling."
· CTA TIPS 2025 (May 14-15, 2025) Arlington, VA 
· Cisco Live U.S. (June 8 – 12, 2025) San Diego, CA 

Most prevalent malware files from Talos telemetry over the past week

SHA 256: 9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
MD5: 2915b3f8b703eb744fc54c81f4a9c67f
VirusTotal: https://www.virustotal.com/gui/file/9f1f11a708d393e0a4109ae189bc64f1f3e312653dcf317a2bd406f18ffcc507
Typical Filename: VID001.exe
Claimed Product: N/A
Detection Name: Win.Worm.Coinminer::1201

SHA 256: 9c60480afbbfbdf20520a9e7705f60a54ff2d0a94d72e4c26fc2aee55a158a9f
MD5: 7abf12ab98f4cbed63228bba977cea7e
VirusTotal:  https://www.virustotal.com/gui/file/9c60480afbbfbdf20520a9e7705f60a54ff2d0a94d72e4c26fc2aee55a158a9f
Typical Filename: pdfzonepro.msi
Claimed Product: N/A
Detection Name: W32.9C60480AFB-95.SBX.TG

 SHA256: 47ecaab5cd6b26fe18d9759a9392bce81ba379817c53a3a468fe9060a076f8ca
MD5: 71fea034b422e4a17ebb06022532fdde
VirusTotal: https://www.virustotal.com/gui/file/47ecaab5cd6b26fe18d9759a9392bce81ba379817c53a3a468fe9060a076f8ca/details
Typical Filename: VID001.exe
Claimed Product: N/A
Detection Name: Coinminer:MBT.26mw.in14.Talos

SHA 256: a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91
MD5: 7bdbd180c081fa63ca94f9c22c457376
VirusTotal: https://www.virustotal.com/gui/file/a31f222fc283227f5e7988d1ad9c0aecd66d58bb7b4d8518ae23e110308dbf91
Typical Filename: c0dwjdi6a.dll
Claimed Product: N/A
Detection Name: Trojan.GenericKD.33515991

Text extracted automatically; images, tables and formatting may be missing. Original: https://blog.talosintelligence.com/patch-it-up-old-vulnerabilities-are-everyones-problems/