Exploited: Cisco, SharePoint, Chrome vulnerabilities
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-20377 | A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stor A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to the web-based management interface not properly validating user-supplied input. An attacker could exploit this vulnerability by by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the affected interface or access sensitive, browser-based information. NVD description · AI analysis pending | 5.4 | <1% |
| — | ||
| CVE-2024-20387 +1 in the same advisory: …20388 | A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in A vulnerability in the web-based management interface of Cisco FMC Software could allow an authenticated, remote attacker to store malicious content for use in XSS attacks. This vulnerability is due to improper input sanitization in the web-based management interface of Cisco FMC Software. An attacker could exploit this vulnerability by persuading a user to click a malicious link. A successful exploit could allow the attacker to conduct a stored XSS attack on an affected device. NVD description · AI analysis pending | 5.4 group max | <1% |
| — | ||
| CVE-2024-20481 | Unauthenticated Remote Access VPN DoS in Cisco ASA and FTD Software CVE-2024-20481 is a denial-of-service vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software, caused by resource exhaustion (CWE-772). An unauthenticated, remote attacker can trigger it by sending a large number of VPN authentication requests to an affected device, consistent with the large-scale VPN brute-force activity Cisco Talos has documented. A successful attack exhausts device resources and causes a denial of service of the RAVPN service, potentially requiring a device reload to restore VPN service, though non-VPN functionality is unaffected. Only ASA and FTD devices with the RAVPN service enabled are affected. The flaw is under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-24, and trade press reports Cisco issued urgent fixes for this actively exploited bug. Do: Apply the fixed ASA/FTD Software releases specified in Cisco's advisory for CVE-2024-20481, or apply Cisco's documented mitigations (such as rate-limiting/throttling VPN authentication attempts) if patching is not immediately possible. Check RAVPN devices for bursts of failed or unusual VPN authentication requests consistent with brute-forcing, and restrict or disable internet-exposed RAVPN where it is not needed. Per CISA KEV guidance, apply vendor mitigations or discontinue use of the product if mitigations are unavailable. | 5.8 | 16% | KEV |
| masshundreds of thousands of internet-exposed Cisco ASA/FTD appliances, of which the RAVPN-enabled subset is directly vulnerable | |
| CVE-2024-38094 | Authenticated deserialization RCE in Microsoft SharePoint Server CVE-2024-38094 is a deserialization of untrusted data flaw (CWE-502) in on-premises Microsoft SharePoint Server, rated 7.2 (high) on CVSS 3.1 and classified by Microsoft as a remote code execution vulnerability. The CVSS vector (AV:N/AC:L/PR:H/UI:N) indicates the attack is network-reachable but requires an attacker who already holds high-privileged access, such as site collection or farm administrator credentials, to submit maliciously crafted serialized data to the server. Successful exploitation yields remote code execution on the SharePoint server with high impact to confidentiality, integrity, and availability, giving attackers a foothold for follow-on activity such as ransomware deployment. Any organization running on-premises SharePoint Server is potentially affected, while SharePoint Online in Microsoft 365 is a separate cloud service. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-10-22 with known ransomware use, and the EPSS of 50.9% (99th percentile) signals a high probability of continued exploitation, although no public proof-of-concept is known. Do: Apply Microsoft's vendor-supplied mitigations and security updates for SharePoint Server as soon as possible; CISA's required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Limit internet exposure of SharePoint front-ends, review high-privileged site and farm administrator accounts for compromise or unusual activity, and prioritize patching given the confirmed ransomware use. No public PoC is known, but the 50.9% EPSS and KEV listing indicate attackers are actively working this flaw. | 7.2 | 51% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed SharePoint Server deployments (roughly 10k-100k servers) | |
| CVE-2024-4947 | V8 Type Confusion in Google Chrome Actively Exploited by Lazarus Group CVE-2024-4947 is a type-confusion flaw (CWE-843) in the V8 JavaScript engine of Google Chrome, rated High by Chromium with a CVSS 3.1 score of 9.6. An attacker triggers it by luring a user to a crafted HTML page, causing V8 to misinterpret object types and enabling execution of arbitrary code inside the Chrome sandbox. Exploitation of the V8 bug alone keeps the attacker sandboxed, but it is a typical first stage of a browser exploit chain and can be paired with sandbox-escape techniques for broader system access. All Google Chrome installations prior to 125.0.6422.60 are affected, as are Fedora's packaged builds of Chrome/Chromium carrying the vulnerable V8 code. The vulnerability was added to CISA's KEV on 2024-05-20, has a public PoC referenced in Google's issue tracker, and public reporting ties its in-the-wild use to the North Korean Lazarus Group, which deployed the FudModule rootkit against infected Chrome users. Do: Upgrade Google Chrome to 125.0.6422.60 or later on all endpoints, and install the updated chromium packages published for Fedora, prioritizing this patch because the flaw is CISA KEV-listed with a mandatory mitigation deadline. Because Lazarus Group is exploiting this in the wild via crafted web pages, review endpoint telemetry for suspicious browser-borne activity and warn users against opening links from untrusted or decoy game/job-lure sites. | 9.6 | 15% | KEV PoC |
| masson the order of billions of Chrome installations (Chrome is the world's dominant desktop browser with roughly 65% market share and a multi-billion active… |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | detankzone.com | the Google Chrome web browser originating from the website detankzone[.]com,” the researchers explained . “On the surface, this websi |
Full article668 words · extracted from helpnetsecurity.com · click to collapse
Threat actors have been leveraging zero and n-day vulnerabilities in Cisco security appliances (CVE-2024-20481), Microsoft Sharepoint (CVE-2024-38094), and Google’s Chrome browser (CVE-2024-4947).
CVE-2024-20481 (Cisco ASA/FTD)
In the past few days, Cisco has released fixes for a slew of vulnerabilities affecting the software powering its security appliances.
Among them several are of particular note:
- CVE-2024-20481, a vulnerability in the Remote Access VPN (RAVPN) service of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software, which could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the RAVPN service.
- CVE-2024-20377, CVE-2024-20387 and CVE-2024-20388, affecting Cisco Secure Firewall Management Center (FMC) Software, may allow attackers to conduct cross-site scripting (XSS) attacks or access sensitive information on an affected device.
CVE-2024-20481 has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, a decision that’s likely based on Cisco confirming that they are aware of malicious use of the flaw.
Information included in the security advisory points to the attackers having inadvertently triggered the flaw as they were performing password spraying attacks.
According to a Cisco Talos report covering Q3 2024, the group “has responded to a growing number of engagements in which adversaries have leveraged password-spraying campaigns to obtain valid usernames and passwords to facilitate initial access.”
CVE-2024-20377, CVE-2024-20387 and CVE-2024-20388 are not under active exploitation, but Cisco’s Product Security Incident Response Team is aware that proof-of-concept exploit code is available for them.
CVE-2024-38094 (Microsoft Sharepoint)
SharePoint is Microsoft’s enterprise-grade solution for content/knowledge management that can be used as part of Microsoft 365 (as a cloud-based service) or run as on-premises software.
CVE-2024-38094 is a data deserialization vulnerability that allows an authenticated attacker with Site Owner permissions to inject arbitrary code and execute it in the context of SharePoint Server.
The vulnerability was fixed by Microsoft in July 2024.
CISA has added CVE-2024-38094 to its KEV catalog, but details about the attacks are currently unavailable.
Proof-of-concept exploits for this particular flaw are publicly available.
CVE-2024-4947 (Google Chrome)
Kaspersky researchers have shared how North Korean threat actors exploited CVE-2024-4947, a type confusion vulnerability Chrome’s JavaScript engine, to target individuals in the cryptocurrency space via a clever social engineering campaign and compromise them with a custom backdoor (“Manyscrypt”).
“On May 13, 2024, our consumer-grade product Kaspersky Total Security detected a new Manuscrypt infection on the personal computer of a person living in Russia. Since Lazarus rarely attacks individuals, this piqued our interest and we decided to take a closer look. We discovered that prior to the detection of Manuscrypt, our technologies also detected exploitation of the Google Chrome web browser originating from the website detankzone[.]com,” the researchers explained.
“On the surface, this website resembled a professionally designed product page for a decentralized finance (DeFi) NFT-based (non-fungible token) multiplayer online battle arena (MOBA) tank game, inviting users to download a trial version. But that was just a disguise. Under the hood, this website had a hidden script that ran in the user’s Google Chrome browser, launching a zero-day exploit and giving the attackers complete control over the victim’s PC. Visiting the website was all it took to get infected — the game was just a distraction.”
CVE-2024-4947 was quickly reported to and fixed by Google.
According to Kaspersky, the attackers also exploited an additional security bug – a V8 sandbox bypass – to effect the compromise.
“This issue (330404819) was submitted and fixed in March 2024. It is unknown whether it was a bug collision and the attackers discovered it first and initially exploited it as a 0-day vulnerability, or if it was initially exploited as a 1-day vulnerability.”
UPDATE (November 4, 2024, 05:25 a.m. ET):
Rapid7 says attackers have used the SharePoint vulnerability (CVE-2024-38094) to gain access to a vulnerable server and drop a webshell on the system. They used a publicly available proof-of-concept exploit for the attack.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2024/10/25/cve-2024-20481-cve-2024-38094-cve-2024-4947/