ZeroHour
Security Affairspublished ()ingested @securityaffairs1

CISA adds Android Pixel, Microsoft Windows, Progress Telerik Report Server bugs to its Known Exploited Vulnerabilities catalog

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-32896CVE-2024-26169CVE-2024-4358

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-26169
Local Privilege Escalation in Microsoft Windows Error Reporting Service (CVE-2024-26169)

Microsoft Windows Error Reporting Service contains an improper privilege management flaw (CWE-269) that allows an elevation of privilege, rated CVSS 3.1 7.8 with a local attack vector, low attack complexity, and no user interaction required. An attacker who can already execute code with low privileges on a vulnerable machine — e.g., after phishing, malware, or another exploit — can trigger the flaw to gain elevated rights, with high impact on confidentiality, integrity, and availability, a step CISA notes has known ransomware use. Any unpatched deployment of Windows 10 (1507, 1607, 1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server 2008/2012/2016/2019 is affected. CISA added the bug to its Known Exploited Vulnerabilities catalog on 2024-06-13, and related reporting links a Windows zero-day exploited before patching to Black Basta ransomware operations. EPSS estimates a 4.0% probability of exploitation within 30 days (90th percentile), and no public proof-of-concept code is known.

Do: Apply Microsoft's June 2024 security updates (the release that fixed this CVE) to all listed Windows 10, Windows 11, and Windows Server versions, per the KEV-required action to apply vendor updates or discontinue use. Because the flaw requires prior local code execution and CISA lists known ransomware use, treat unpatched Windows hosts as at risk and check them for post-exploitation signs such as unexpected SYSTEM-level process activity, new persistence, or ransomware staging.

7.84% KEV ransomware
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 21H2, 22H2, 23H2
  • Microsoft Windows Server 2008, 2012, 2016, 2019
mass≈1 billion+ unpatched Windows 10/11 and Windows Server installations worldwide
CVE-2024-32896
Local Privilege Escalation in Google Android Pixel Kernel

CVE-2024-32896 is a logic error (CWE-670/CWE-783) in Android code on Google Pixel devices that allows a bypass leading to local escalation of privilege. The flaw is triggered through local access with no additional execution privileges required, and user interaction is needed for exploitation to succeed. A successful attack yields high impact to confidentiality, integrity, and availability on the affected device (CVSS 3.1 base score 7.8), giving an attacker elevated control of the phone. Per CISA's advisory, only Google Pixel devices running Android are affected. The vulnerability is being exploited in the wild: it was added to CISA's KEV catalog on 2024-06-13, and news coverage describes limited, targeted exploitation of the Android kernel flaw as a zero-day, with users urged to install the latest security updates.

Do: Apply the latest Android security updates from Google (June 2024 security patch level or later) to all Pixel devices, per vendor instructions and CISA's required action. Users can verify their patch level under Settings > About phone > Android security update. Given reports of limited, targeted zero-day exploitation, prioritize patching high-risk users and treat the flaw as a post-compromise privilege-escalation risk.

7.83% KEV
  • google Android (Pixel)
masstens of millions of Pixel devices (estimated active Pixel install base; exact count unknown)
CVE-2024-4358
Authentication Bypass by Spoofing in Progress Telerik Report Server (IIS)

CVE-2024-4358 is a critical (CVSS 9.8) authentication bypass by spoofing (CWE-290) in Progress Telerik Report Server 2024 Q1 (10.0.24.305) and earlier when the server is deployed on IIS. The flaw is reachable over the network with no privileges and no user interaction, so a remote, unauthenticated attacker can spoof a valid session to reach Report Server functionality that should require sign-in; public reporting indicates this can be abused to create rogue administrator accounts and take over the instance. Access to restricted functionality and administrative control is the immediate gain, and per a released public proof of concept the bypass can be chained with the CVE-2024-1800 deserialization flaw to achieve unauthenticated remote code execution. Any organization running Telerik Report Server 2024 Q1 or earlier on IIS is affected. Exploitation is confirmed in the wild: CISA added the bug to the KEV catalog on 2024-06-13, and the 97.5% EPSS score (100th percentile) signals a very high likelihood of continued exploitation, though ransomware use is listed as unknown.

Do: Upgrade every Telerik Report Server instance to Progress' fixed release (2024 Q2, 10.0.24.414, or later per the vendor advisory); if prompt patching is not possible, CISA's required action is to apply vendor mitigations or discontinue use of the product. Audit the Users/Administrators list for rogue admin accounts, review IIS logs for unauthenticated requests to restricted endpoints, and inventory for any instances hosted on IIS. If your deployment is also exposed to CVE-2024-1800, patch that as well, since the public PoC chains the two flaws for unauthenticated RCE.

9.897% KEV
  • Progress (Telerik) Telerik Report Server 2024 Q1 (10.0.24.305) and all earlier versions, when running on IIS
moderate~1,000-10,000 deployments worldwide (estimate; only a minority are internet-exposed)
Full article218 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Android Pixel, Microsoft Windows, Progress Telerik Report Server bugs to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

  • CVE-2024-32896 Android Pixel Privilege Escalation Vulnerability
  • CVE-2024-26169 Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
  • CVE-2024-4358 Progress Telerik Report Server Authentication Bypass by Spoofing Vulnerability

CVE-2024-32896 is an elevation of privilege vulnerability in the Pixel Firmware, which has been exploited in the wild as a zero-day.

CVE-2024-26169 is an elevation of privilege issue in the Microsoft Windows Error Reporting Service that can be exploited to could gain SYSTEM privileges.

CVE-2024-4358 is an authentication bypass vulnerability that an unauthenticated attacker can exploit to gain access to Telerik Report Server restricted functionality.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by July 4, 2024.

Pierluigi Paganini

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

(SecurityAffairs – hacking, Android Pixel)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/164525/security/cisa-adds-android-pixel-microsoft-windows-progress-telerik-report-server-known-exploited-vulnerabilities-catalog.html