CISA adds JetBrains TeamCity and Windows flaws to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-28229 | Windows CNG Key Isolation Service Local Privilege Escalation (CVE-2023-28229) CVE-2023-28229 is an elevation-of-privilege vulnerability in the Windows CNG Key Isolation Service (KeyIso), the component that isolates and protects private keys used for cryptographic operations on Windows. A local attacker with low privileges can trigger the flaw inside the service under specific conditions (CVSS attack complexity is high); no user interaction is required. Successful exploitation grants elevated privileges with high impact on confidentiality, integrity, and availability, effectively full control of the affected host, and is typically used to strengthen a low-privileged foothold already gained via another flaw. All supported Windows 10 releases (1507 through 22H2), Windows 11 21H2 and 22H2, and Windows Server 2008, 2012, 2016, and 2019 are affected. CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2023-10-04, indicating active exploitation; no public proof-of-concept is known and ransomware use is listed as unknown. Do: Apply Microsoft's October 2023 security updates (or later cumulative updates) on all affected Windows 10, Windows 11, and Windows Server systems, prioritizing multi-user hosts such as RDS/VDI servers and endpoints used by potentially compromised accounts, since exploitation requires local access. Verify patch status via your patch-management inventory and hunt for signs of local privilege escalation on hosts missing the fix. Note that the related KEV batch also flagged JetBrains TeamCity (CVE-2023-42793), which should be patched separately if deployed. | 7.0 | 2% | KEV |
| mass1 billion+ Windows devices (essentially the entire supported Windows 10/11 client base plus Windows Server 2008-2019) | |
| CVE-2023-4211 | Use-After-Free in Arm Mali GPU Kernel Driver (Actively Exploited) CVE-2023-4211 is a use-after-free (CWE-416) in Arm's Mali GPU kernel drivers, covering the Midgard, Bifrost, Valhall and 5th Gen GPU Architecture product lines. A local, non-privileged attacker triggers the flaw by issuing improper GPU memory processing operations, causing the driver to access memory that has already been freed. Successful exploitation exposes already-freed kernel memory to the attacker (high confidentiality impact per the CVSS score), which on mobile devices can be chained into broader local information-gathering or privilege attacks. Any system running the affected Mali kernel drivers is exposed — in practice this is overwhelmingly Android smartphones, tablets and embedded devices whose SoCs integrate Mali GPUs. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-03, indicating confirmed in-the-wild exploitation; Arm has issued updated drivers, but patch availability varies by device vendor. Do: Determine whether devices in your fleet use Mali GPUs and obtain updated Mali GPU kernel drivers from Arm via your device vendor's security updates (OEM/Android updates issued from October 2023 onward), since Arm fixes are distributed through device vendors rather than a standalone Arm patch channel. Until devices are patched, limit local, unprivileged access on affected systems to trusted users and monitor vendor bulletins for availability. Per the CISA KEV required action, apply vendor mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. | 5.5 | 1% | KEV |
| mass≈1 billion+ devices (Mali GPUs are integrated in a very large share of Android smartphones, tablets and embedded devices) | |
| CVE-2023-42793 | Authentication bypass in JetBrains TeamCity enables unauthenticated RCE JetBrains TeamCity Server, a widely used CI/CD build server, contains an authentication bypass vulnerability (CWE-288) that lets a remote, unauthenticated attacker gain administrative access without valid credentials. By sending crafted requests to the TeamCity server over the network, the attacker bypasses authentication and can then execute arbitrary code on the server via administrative and build features, achieving full remote code execution. An attacker gains control of the build server and, with it, access to source code, build artifacts, stored secrets and credentials, and a foothold for lateral movement or ransomware deployment. Any organization running an affected TeamCity Server is affected, especially instances reachable from the internet. Exploitation is confirmed in the wild: CISA added the flaw to its KEV catalog on 2023-10-04 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days. Do: Upgrade TeamCity Server to 2023.05.4 or later per JetBrains' instructions, or apply vendor mitigations or discontinue use if patching is not possible (per the CISA KEV required action). Also take unpatched instances off the public internet, and hunt for signs of compromise such as unauthorized administrator accounts, unexpected changes in audit logs and build configurations, and stored secrets or tokens that may have been stolen, given known ransomware exploitation. | 9.8 | 100% | KEV ransomware PoC ×2 |
| largeTens of thousands of TeamCity Server deployments, of which several thousand are internet-exposed |
Full article284 words · extracted from securityaffairs.com · click to collapse

The U.S. CISA added JetBrains TeamCity and Windows vulnerabilities to its Known Exploited Vulnerabilities Catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the JetBrains TeamCity flaw CVE-2023-42793 (CVSS score: 9.8) and Windows bug CVE-2023-28229 (CVSS score: 7.0) to its Known Exploited Vulnerabilities Catalog.
Below are the descriptions of the two vulnerabilities:
- CVE-2023-42793 JetBrains TeamCity Authentication Bypass Vulnerability. The vulnerability is an authentication bypass issue affecting the on-premises version of TeamCity. An attacker can exploit the flaw to steal source code and stored service secrets and private keys of the target organization. By injecting malicious code, an attacker can also compromise the integrity of software releases and impact all downstream users.
- CVE-2023-28229 Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability. At the end of August a cybersecurity researcher released the details, and a proof-of-concept (PoC) exploit for this vulnerability. The vulnerability, which has a CVSS score of 7.0, could allow an attacker to gain specific limited SYSTEM privileges.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this flaw by October 25, 2023.
This week the US CISA also added a Use-After-Free Vulnerability, tracked as CVE-2023-4211, in Arm Mali GPU Kernel Driver to the Catalog. CISA orders federal agencies to fix this flaw by October 24, 2023.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Known Exploited Vulnerabilities catalog)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/152020/hacking/cisa-known-exploited-vulnerabilities-catalog-jetbrains-teamcity-and-windows.html