ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Microsoft Outlook, Sophos XG Firewall, and other flaws to its Known Exploited Vulnerabilities catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-15069
Unauthenticated Buffer Overflow RCE in Sophos XG Firewall

CVE-2020-15069 is a critical buffer overflow (CWE-120) in the HTTP/S Bookmarks feature used for clientless access in Sophos XG Firewall, affecting firmware versions 17.x through v17.5 MR12. The flaw is reachable over the network without credentials or user interaction, so an unauthenticated attacker can trigger it by sending crafted requests to the exposed bookmarks functionality. Successful exploitation yields remote code execution on the firewall with high impact on confidentiality, integrity, and availability. Any organization running Sophos XG Firewall 17.x through v17.5 MR12 is affected, especially firewalls with the clientless-access feature enabled or management interfaces reachable from the internet. Sophos published hotfix HF062020.1 for all firewalls running v17.x, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-06, indicating confirmed in-the-wild exploitation (EPSS puts the 30-day exploitation probability at about 10.7%).

Do: Apply hotfix HF062020.1, which Sophos published for all firewalls running v17.x, or upgrade to a current supported release, prioritizing internet-exposed devices. Verify the hotfix is actually installed rather than assuming auto-update succeeded, and disable or restrict the clientless HTTP/S Bookmarks feature as interim mitigation. Review firewall logs for signs of unexpected access or compromise, since exploitation has been confirmed in the wild.

9.811% KEV
  • sophos XG Firewall firmware 17.x through v17.5 MR12
mass≈ hundreds of thousands of firewall deployments, with likely tens of thousands still running unpatched v17.x (internet-wide scans have historically shown…
CVE-2020-29574
Unauthenticated SQL Injection in Sophos CyberoamOS WebAdmin

CVE-2020-29574 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in the WebAdmin management console of Sophos CyberoamOS (CROS), the operating system of Cyberoam network security appliances acquired by Sophos. An unauthenticated remote attacker can send crafted requests to the exposed WebAdmin interface and execute arbitrary SQL statements against the backend database, with no credentials or user interaction required. Successful exploitation can reveal or alter firewall management data and facilitate further compromise; CISA notes it is being used in ransomware operations. Any organization still running a CyberoamOS appliance is affected, and CISA flags the product as end-of-life/end-of-service, so no current support exists. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06; no public PoC is known, but exploitation in the wild is confirmed.

Do: Because CyberoamOS is end-of-life/end-of-service, CISA's required action is to discontinue use: migrate Cyberoam appliances to a currently supported Sophos Firewall release or retire them. Until migration, restrict WebAdmin access to trusted management networks rather than the public internet, review appliance logs for unexpected administrative or database activity, and hunt for signs of compromise given the known ransomware use.

9.85% KEV ransomware
  • Sophos CyberoamOS (CROS) - WebAdmin all versions through 2020-12-04 (CISA date-based range); product is EoL/EoS
largetens of thousands of deployed appliances (installed-base estimate; internet-exposed WebAdmin consoles likely in the low thousands)
CVE-2022-23748
DLL Sideloading Vulnerability in Audinate Dante Discovery (mDNSResponder.exe)

Audinate Dante Discovery's mDNSResponder.exe executable improperly specifies how, from which folder, and under what conditions it loads DLLs, enabling a DLL sideloading attack (CWE-114/CWE-426). An attacker who can place a crafted malicious DLL where the legitimate executable searches for libraries can trigger it to be loaded when the binary runs; the CVSS vector (AV:L, UI:R) indicates local access and some user interaction are required to start the vulnerable process. Because the malicious code executes under the cover of a valid, legitimate executable, the attacker gains code execution with high impact on confidentiality, integrity, and availability. The flaw affects Windows hosts running Audinate's Dante Discovery component, which ships with Dante software tooling and the Dante Application Library used in professional audio networking deployments. It was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 9.1% (95th percentile), no public PoC is known, and ransomware use is unknown.

Do: Apply Audinate's mitigations or upgrade Dante Discovery / Dante Application Library to the latest vendor-recommended release per the CISA KEV required action, and discontinue use of the affected component if mitigations are unavailable. On Windows hosts, check for unexpected or unrecognized DLL files in the directory from which mDNSResponder.exe runs (and its DLL search paths), and restrict write permissions on the application folder to prevent malicious DLL placement. Given the KEV listing and 95th-percentile EPSS, prioritize patching internet-relevant and audio-control workstations in broadcast, live production, and installed-sound environments.

7.89% KEV
  • Audinate Dante Discovery (Dante Application Library component, mDNSResponder.exe)
large≈ hundreds of thousands of Windows hosts running Audinate Dante software (Dante Controller/Discovery and Dante Application Library deployments)
CVE-2024-21413
Improper Input Validation RCE in Microsoft Outlook (MonikerLink)

CVE-2024-21413 is an improper input validation flaw (CWE-20) in Microsoft Outlook, publicly dubbed "MonikerLink", in which Outlook mishandles a specially crafted hyperlink (a file:// moniker link) and bypasses the security prompt normally applied before opening such links. The flaw is triggered when a user opens or clicks a maliciously crafted link in an email, causing Outlook to invoke the target outside its protected handling. A successful attack can leak the user's NTLM credentials and can achieve remote code execution in the context of the current user; the flaw carries a critical CVSS 3.1 score of 9.8. Anyone running affected Outlook clients — Microsoft 365 Apps, Office 2016, Office 2019, and Office LTSC — is exposed, and the issue was fixed in Microsoft's February 2024 Patch Tuesday release. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-06, EPSS assigns a ~95% exploitation probability (100th percentile), and a public PoC is available.

Do: Apply Microsoft's February 2024 (or later) security updates for Microsoft 365 Apps, Office 2016, Office 2019, and Office LTSC, and verify Outlook builds are current, per the KEV required action to apply vendor mitigations or discontinue use. As interim mitigation, restrict outbound SMB/NTLM from endpoints (e.g., block outbound port 445 or disable NTLM where feasible) to blunt credential leakage from crafted file:// links. Hunt for signs of exploitation, such as unexpected outbound SMB connections or NTLM authentication events following users clicking links in email.

9.895% KEV PoC
  • Microsoft 365 Apps (Outlook)
  • microsoft Office 2016 (Outlook) all builds prior to the February 2024 security updates
  • microsoft Office 2019 (Outlook) all builds prior to the February 2024 security updates
  • +1 more
masshundreds of millions of users
CVE-2025-0411
Mark-of-the-Web Bypass in 7-Zip Enables Code Execution via Crafted Archives

CVE-2025-0411 is a protection-mechanism bypass in 7-Zip's handling of archived files: when extracting a crafted archive that carries the Mark-of-the-Web, 7-Zip fails to propagate the MotW flag to the extracted files. Exploitation requires user interaction, as the target must visit a malicious page or open a malicious archive. Because the extracted files lose their MotW designation, Windows skips its usual security prompts on attacker-supplied executables or scripts, allowing arbitrary code execution in the context of the current user. Anyone running affected 7-Zip installations is exposed, including NetApp Active IQ Unified Manager deployments that incorporate 7-Zip. The flaw was exploited as a zero-day — Russian cybercrime groups and SmokeLoader campaigns, notably targeting Ukrainian organizations, abused it — and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-06.

Do: Upgrade 7-Zip to the latest patched release per vendor guidance, and for NetApp Active IQ Unified Manager apply the update specified in NetApp's security advisory; the CISA KEV required action is to apply vendor mitigations or discontinue use. Until patched, treat archives from untrusted sources with caution and verify extracted executables manually, since MotW prompts will not fire on extracted files. Hunt for signs of SmokeLoader-style post-extraction execution in user workstations.

7.067% KEV
  • 7-Zip
  • NetApp Active IQ Unified Manager
masstens of millions of users (7-Zip is among the most widely deployed Windows archive utilities, plus NetApp-bundled deployments)
Full article252 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini February 06, 2025

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Outlook, Sophos XG Firewall, and other flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:

The vulnerability CVE-2024-21413 (CVSS score of 9.8) is a Remote Code Execution flaw in Microsoft Outlook. An attacker can exploit this vulnerability to gain high privileges, which include read, write, and delete functionality.

“Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode.” reads the advisory published by Microsoft.

The vulnerability CVE-2020-15069 (CVSS score of 9.8) is a buffer overflow issue in Sophos XG Firewall 17.x to 17.5 MR12.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by February 27, 2025.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA Known Exploited Vulnerabilities catalog)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/173949/hacking/u-s-cisa-adds-microsoft-outlook-sophos-xg-firewall-and-other-flaws-to-its-known-exploited-vulnerabilities-catalog.html