Week in review: F5 BIG-IP RCE exploitation, URL spoofing flaws in Zoom, Google Docs
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-1388 | Unauthenticated RCE in F5 BIG-IP via Missing Authentication F5 BIG-IP contains a critical missing-authentication flaw (CWE-306) in its iControl REST control plane: an unauthenticated attacker with network reachability to the management interface, or to self IPs exposing the REST service on TCP 443, can bypass authentication completely. By sending specially crafted HTTP requests, the attacker gains the ability to execute arbitrary code, create or delete files, and disable services, effectively achieving full takeover of the load balancer or security appliance and the traffic it handles. All F5 BIG-IP deployments running unpatched software are affected; the provided data does not enumerate exact version ranges, which are listed in F5's May 2022 security advisory. The flaw was added to CISA's KEV catalog on 2022-05-10 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile), indicating active in-the-wild exploitation. No public proof-of-concept is catalogued in the provided data, but the KEV listing and known ransomware use confirm real-world attacks. Do: Upgrade affected F5 BIG-IP systems to the fixed releases listed in F5's May 2022 security advisory (K23605340) immediately, prioritizing appliances whose management interface or self IPs on TCP 443 are reachable from untrusted networks; as an interim mitigation, block untrusted access to the management interface and the iControl REST service. Because this flaw is in CISA's KEV catalog with known ransomware use, also hunt for signs of compromise (unexpected files, disabled services, unknown persistence) on any system that was exposed before patching. | 9.8 | 100% | KEV ransomware PoC ×4 |
| large~10,000 internet-exposed BIG-IP systems (public scans at disclosure counted 8k-10k+), with a far larger installed base behind firewalls | |
| CVE-2022-22713 | Windows Hyper-V Denial of Service Vulnerability Windows Hyper-V Denial of Service Vulnerability NVD description · AI analysis pending | 5.6 | <1% |
| — | ||
| CVE-2022-26925 | Spoofing Flaw in Windows LSA (CVE-2022-26925) Exploited Against Domain Controllers CVE-2022-26925 is a spoofing vulnerability in the Windows Local Security Authority (LSA) that lets an unauthenticated network attacker make a spoofed call to LSA on a remote Windows host. It is triggered over the network with no user interaction, typically by coercing a Windows system—most critically a domain controller—into authenticating via NTLM to an attacker-controlled machine, in the manner of the PetitPotam forced-authentication attacks referenced in CISA's catalog update. By spoofing the client when LSA processes that authentication, the attacker undermines NTLM's authentication guarantees and, when chained with relay techniques, can authenticate to a domain controller with elevated privileges, which is reflected in the CVSS high-integrity impact. Any organization running affected Windows clients or Windows Server versions is exposed, with domain controllers the highest-value targets. The flaw was exploited as a zero-day before Microsoft's June 2022 Patch Tuesday fixes and is now listed in CISA's Known Exploited Vulnerabilities catalog, with CISA ordering federal agencies to patch. Do: Apply Microsoft's June 2022 Patch Tuesday updates (per CISA's guidance for the June Microsoft patch, https://www.cisa.gov/guidance-applying-june-microsoft-patch) across all affected Windows versions, prioritizing domain controllers; systems that cannot yet patch should be protected with NTLM-related mitigations (e.g., enforced SMB signing, LDAP signing/channel binding, and restricting or auditing NTLM use) per CISA/Microsoft remediation guidance. Check whether domain controllers are internet-exposed or reachable from untrusted networks, and hunt for signs of forced-authentication/relay activity. Note that a related PetitPotam KEV entry was superseded, so ensure this newer LSA fix—not just the older PetitPotam patch—is deployed. | 5.9 | 11% | KEV |
| mass≈1 billion+ Windows installations worldwide (essentially every Windows environment, and domain controllers at virtually every Windows-running organization) | |
| CVE-2022-29972 | An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 An argument injection vulnerability in the browser-based authentication component of the Magnitude Simba Amazon Redshift ODBC Driver (1.4.14 through 1.4.21.1001 and 1.4.22 through 1.4.x before 1.4.52) may allow a local user to execute arbitrary code. NVD description · AI analysis pending | 7.8 | 4% |
| — | ||
| CVE-2022-30525 | OS Command Injection in Zyxel Firewalls Enables Remote Command Execution CVE-2022-30525 is an OS command injection vulnerability (CWE-78) in the CGI program of certain Zyxel firewall firmware versions. By sending crafted requests to the vulnerable CGI program, an attacker can modify specific files on the appliance and inject and execute operating system commands. Successful exploitation yields command execution on the firewall itself, allowing an attacker to alter device files/configuration and potentially pivot into the protected network — the class of edge-device flaw commonly targeted by ransomware operators (ransomware use in this case is not yet confirmed). Organizations running affected Zyxel firewalls, particularly those with management interfaces reachable from the internet, are at risk. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2022-05-16, EPSS assigns a 99.9% 30-day exploitation probability (100th percentile), and no public PoC is catalogued yet. Do: Apply Zyxel's fixed firmware per the vendor's instructions immediately, as required by the CISA KEV listing. Until patched, restrict HTTP/HTTPS management access to the firewall to trusted source addresses only. Because exploitation is confirmed in the wild, prioritize internet-facing Zyxel firewalls and review devices for indicators of compromise such as modified configurations or unexpected administrative changes. | 9.8 | 100% | KEV PoC ×3 |
| large≈ tens of thousands of internet-exposed Zyxel firewall management interfaces (order of magnitude 10k–100k devices) |
Full article936 words · extracted from helpnetsecurity.com · click to collapse

Here’s an overview of some of last week’s most interesting news, articles and interviews:
Microsoft patches Windows LSA spoofing zero-day under active attack (CVE-2022-26925)
May 2022 Patch Tuesday is here, and Microsoft has marked it by releasing fixes for 74 CVE-numbered vulnerabilities, including one zero-day under active attack (CVE-2022-26925) and two publicly known vulnerabilities (CVE-2022-29972 and CVE-2022-22713).
Attackers are attempting to exploit critical F5 BIG-IP RCE
Researchers have developed PoC exploits for CVE-2022-1388, a critical remote code execution bug affecting F5 BIG-IP multi-purpose networking devices/modules.
Researchers uncover URL spoofing flaws on Zoom, Box, Google Docs
Researchers have discovered several URL spoofing bugs in Box, Zoom and Google Docs that would allow phishers to generate links to malicious content and make it look like it’s hosted by an organization’s SaaS account.
Critical flaw in Zyxel firewalls grants access to corporate networks (CVE-2022-30525)
A critical vulnerability (CVE-2022-30525) affecting several models of Zyxel firewalls has been publicly revealed, along with a Metasploit module that exploits it.
Data centers on steel wheels: Can we trust the safety of the railway infrastructure?
In this interview for Help Net Security, Dimitri van Zantvliet Rozemeijer, CISO at Nederlandse Spoorwegen (Dutch Railways), talks about railway cybersecurity and the progresses this industry has made to guarantee safety.
Google Drive emerges as top app for malware downloads
Netskope published a research which found that phishing downloads saw a sharp increase of 450% over the past 12 months, fueled by attackers using search engine optimization (SEO) techniques to improve the ranking of malicious PDF files on popular search engines, including Google and Bing.
The role of streaming machine learning in encrypted traffic analysis
Organizations now create and move more data than at any time ever before in human history. Network traffic continues to increase, and global internet bandwidth grew by 29% in 2021, reaching 786 Tbps.
Password reuse is rampant among Fortune 1000 employees
SpyCloud published an annual analysis of identity exposure among employees of Fortune 1000 companies in key sectors such as technology, finance, retail and telecommunications.
How to set up a powerful insider threat program
Security spend continues to focus on external threats despite threats often coming from within the organization. A recent Imperva report (by Forrester Research) found only 18 percent prioritized spend on a dedicated insider threat program (ITP) compared to 25 percent focused on external threat intelligence.
Is that health app safe to use? A new framework aims to provide an answer
A new framework for assessing the privacy, technical security, usability and clinical assurance and safety of digital health technologies has been created by the American College of Physicians (ACP), the American Telemedicine Association (ATA) and ORCHA, the Organization for the Review of Care and Health Applications.
An offensive mindset is crucial for effective cyber defense
As ransomware attacks continue to increase and cybercriminals are becoming more sophisticated, the federal government has implemented a more proactive approach when it comes to cybersecurity.
How to avoid headaches when publishing a CVE
Finding a CVE (Common Vulnerabilities and Exposures) is the first step in a process which starts with the identification of a zero-day and could end with fame and glory – if the discovery is significant enough.
A 10-point plan to improve the security of open source software
The Linux Foundation and the Open Source Software Security Foundation, with input provided by executives from 37 companies and many U.S. government leaders, delivered a 10-point plan to broadly address open source and software supply chain security, by securing open source security production, improving vulnerability discovery and remediation, and shortening the patching response time of the ecosystem.
The SaaS-to-SaaS supply chain is a wild, wild mess
The SaaS-to-SaaS supply chain continues to grow uninhibited, without alerting security teams on new risks and connections created by non-human identities that cannot be resolved using traditional security controls designed for human-to-app interactions.
Funding women-led cybersecurity startups: Where are we at?
In this video for Help Net Security, Lisa Xu, CEO at NopSec, talks about the cybersecurity funding landscape and its lack of diversity.
Threats to hardware security are growing
In this video for Help Net Security, Jason Oberg, CTO at Tortuga Logic, talks about the growing hardware security threats.
Ransomware works fast, you need to be faster to counter it
In this video for Help Net Security, Chuck Everette, Director of Cybersecurity Advocacy at Deep Instinct, talks about the ransomware threat, the speed at which ransomware attacks unfold, and offers advice on how to mitigate the associated risk.
Shrinking healthcare cybersecurity gaps between hospitals and manufacturers
In this video for Help Net Security, Christopher Gates, Director of Product Security at Velentium, talks about the gaps in healthcare cybersecurity, as well as the new FDA premarket cybersecurity guidance for medical device manufacturers and Health Sector Coordinating Council’s model contract language template.
Why are DDoS attacks so easy to launch and so hard to defend against?
In this video for Help Net Security, Ivan Shefrin, Executive Director at Comcast Business, talks about how businesses can monitor for and mitigate against DDoS attacks.
Welcome “Frappo” – Resecurity identified a new Phishing-as-a-Service
The Resecurity HUNTER unit identified a new underground service called “Frappo”, which is available on the Dark Web.
Download guide: Evaluating third-party security platforms
A comprehensive third-party security program can align your vendor’s security with your internal security controls and risk appetite. Such a program can also help you remediate risk if your vendors fall short.
New infosec products of the week: May 13, 2022
Here’s a look at the most interesting products from the past week, featuring releases from Cohesity, ForgeRock, iDenfy, Nasuni, Orca Security, SecureAge, and Sonatype.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2022/05/15/week-in-review-f5-big-ip-rce-exploitation-url-spoofing-flaws-in-zoom-google-docs/