U.S. CISA adds Microsoft Windows Kernel, Mozilla Firefox and SolarWinds Web Help Desk bugs to its Known Exploited Vulnerabilities catalog
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-28987 | Hardcoded Credential in SolarWinds Web Help Desk Allows Unauthenticated Access SolarWinds Web Help Desk (WHD) contains hard-coded credentials (CWE-798): fixed, built-in authentication material embedded in the shipped software. Because the same credentials exist on every WHD installation, a remote attacker who knows them can authenticate to WHD without any user account, with no privileges or user interaction required (CVSS 3.1 9.1, AV:N/AC:L/PR:N/UI:N). Successful use grants access to internal WHD functionality and the ability to modify data, with high confidentiality and integrity impact but no availability impact. Any organization running an unpatched WHD instance is affected, particularly internet-exposed deployments such as those operated by managed service providers and enterprise IT service desks. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-15 (ransomware use not yet reported), EPSS assigns a 93.2% probability of exploitation within 30 days (100th percentile), and no public proof-of-concept was known at the time of this record. Do: Upgrade all WHD instances to the patched SolarWinds release that includes the October 2024 fix for CVE-2024-28987 (check the SolarWinds PSIRT advisory for the exact fixed version, e.g., WHD 12.8.4 or later); the required KEV action applies, and U.S. federal agencies must remediate by November 5, 2024. Prioritize internet-exposed WHD servers: restrict network access to the help desk interface/API until patched and review logs for unauthenticated access using built-in credentials, since exploitation is confirmed in the wild. If patching is not possible, apply mitigations per vendor instructions or discontinue use of the product, as CISA recommends. | 9.1 | 93% | KEV |
| moderate≈ a few thousand internet-exposed WHD instances, with total deployments likely in the low tens of thousands worldwide (estimate) | |
| CVE-2024-30088 | Microsoft Windows Kernel TOCTOU Race Condition Privilege Escalation (CVE-2024-30088) CVE-2024-30088 is a time-of-check to time-of-use (TOCTOU) race condition in the Microsoft Windows kernel (CWE-367) that allows a local, low-privileged attacker to elevate to SYSTEM-level privileges. Because it is a timing race with high attack complexity, exploitation requires locally executing crafted code that repeatedly races the kernel's validation of a resource, but no user interaction is needed and the attacker only needs the ability to already run code on the target. Successful exploitation grants full control of the local machine (high confidentiality, integrity, and availability impact), which attackers typically chain after initial access or another flaw to gain complete host compromise. Virtually all supported Windows 10 and Windows 11 client releases and Windows Server 2016 through 2022 23H2 are affected if unpatched. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, Iran-linked OilRig used it in an espionage campaign targeting UAE and Gulf governments, and EPSS assigns a ~68% probability of exploitation within 30 days (99th percentile). Do: Apply the Windows cumulative security update for CVE-2024-30088 from Microsoft's advisory on every affected Windows 10, Windows 11, and Windows Server release (the fix shipped in Microsoft's June 2024 monthly security updates; confirm your build number against the advisory). Prioritize multi-user hosts, RDP/jump servers, and endpoints where untrusted users or code run, since this is a local privilege escalation used post-compromise — check endpoint logs for suspicious local process activity coinciding with privilege changes. Consistent with the CISA KEV required action (added 2024-10-15), patch promptly per vendor instructions or discontinue use of affected builds if patching is not possible. | 7.0 | 68% | KEV ransomware |
| mass≈1 billion+ Windows 10/11 client devices and hundreds of thousands to millions of Windows Server hosts (unpatched installed base) | |
| CVE-2024-9680 | Use-After-Free in Mozilla Firefox Animation Timelines Allows Code Execution Mozilla Firefox and Firefox ESR contain a use-after-free (CWE-416) in the browser's animation timelines component, which CISA describes as allowing code execution in the content process. The flaw is reachable through malicious web content: a crafted page can manipulate animation timelines so that an in-use object is freed, producing exploitable memory corruption. A successful attacker gains code execution in the content process, the sandboxed process that renders web pages, on the machine of the user who loaded the content. All users of Firefox and Firefox ESR are affected by the flaw itself. It is being actively exploited: the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, and EPSS assigns it a 23.2% probability of exploitation in the next 30 days (98th percentile). Do: Apply Mozilla's patched Firefox/Firefox ESR release immediately and verify the running version via the browser's About Firefox dialog, since many installs only pick up auto-updates after a restart (per CISA's required action: apply mitigations per vendor instructions or discontinue use). Given the known ransomware use, prioritize enterprise ESR rollout and check for managed-update failures, auto-update-disabled installs, or unmanaged Firefox copies on user machines. Note that no public proof-of-concept is known, but KEV listing confirms exploitation, so patching should not wait for PoC availability. | 9.8 | 23% | KEV ransomware |
| masshundreds of millions of users (Firefox's global desktop user base of roughly 150-200M active users, plus enterprise Firefox ESR deployments) |
Full article347 words · extracted from securityaffairs.com · click to collapse

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Windows Kernel, Mozilla Firefox and SolarWinds Web Help Desk bugs to its Known Exploited Vulnerabilities catalog.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog:
- CVE-2024-30088 (CVSS score 7.0) Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
- CVE-2024-9680 Mozilla Firefox Use-After-Free Vulnerability
- CVE-2024-28987 (CVSS score 9.1) SolarWinds Web Help Desk Hardcoded Credential Vulnerability
An attacker could exploit the vulnerability CVE-2024-30088 to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition.
Last week Mozilla released an emergency security update for the Firefox browser to address the critical use-after-free vulnerability CVE-2024-9680, which is actively exploited in attacks.
The flaw CVE-2024-9680 resides in Animation timelines. Firefox Animation Timelines is a feature in the Firefox Developer Tools suite that allows developers to inspect, edit, and debug animations directly within the browser. It provides a visual interface for managing animations, including CSS animations and transitions, as well as those created with the Web Animations API.
An attacker could exploit this vulnerability to achieve code execution in the content process.
SolarWinds addressed the CVE-2024-28987 flaw in August, it could allow remote unauthenticated attackers to gain unauthorized access to vulnerable instances.
SolarWinds describes WHD as an affordable Help Desk Ticketing and Asset Management Software that is widely used by large enterprises and government organizations.
“The SolarWinds Web Help Desk (WHD) software is affected by a hardcoded credential vulnerability, allowing remote unauthenticated user to access internal functionality and modify data.” reads the advisory published by the company.
According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.
Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.
CISA orders federal agencies to fix this vulnerability by November 5, 2024.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CISA)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/169882/hacking/u-s-cisa-microsoft-windows-kernel-mozilla-firefox-solarwinds-web-help-desk-bugs-known-exploited-vulnerabilities-catalog.html