Google Reports 75 Zero-Days Exploited in 2024 — 44% Targeted Enterprise Security Products
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2024-21887 +1 in the same advisory: …46805 | Command Injection RCE in Ivanti Connect Secure and Policy Secure Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available. Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories. | 9.1 group max | 100% | KEV ransomware PoC |
| largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher) | |
| CVE-2024-21338 | Local Privilege Escalation in Microsoft Windows Kernel via Exposed IOCTL (CVE-2024-21338) CVE-2024-21338 is a local privilege escalation flaw in the Microsoft Windows kernel caused by an exposed IOCTL with insufficient access control (CWE-822): a low-privileged process running locally can issue specially crafted requests to a kernel interface without proper authorization checks. Public research (including Avast's analysis of Lazarus Group's FudModule rootkit) ties the vulnerable component to the Windows AppLocker/AppID driver and shows the bug was exploited as an admin-to-kernel zero-day, letting an attacker with a foothold on a machine gain kernel-level privileges and full control of the host. Because it requires only local access, it is typically chained after initial access or malware delivery, and CISA notes known ransomware use alongside exploitation by North Korea's Lazarus Group. Any organization or device running Windows 10 (1809, 21H2, 22H2), Windows 11 (21H2, 22H2, 23H2), or Windows Server 2019/2022 (including 2022 23H2) is affected until patched. The bug was added to the CISA Known Exploited Vulnerabilities catalog on 2024-03-04 after in-the-wild exploitation and was fixed in Microsoft's March 2024 Patch Tuesday release; EPSS places the 30-day exploitation probability at roughly 60% (99th percentile). Do: Apply Microsoft's March 2024 (or later) cumulative security updates to every listed Windows 10, Windows 11, and Windows Server 2019/2022 system, and verify the installed build includes the March 2024 fixes before closing the KEV entry; if patches are unavailable, follow CISA's required action to apply vendor mitigations or discontinue use. Because this is a local-only escalation commonly chained after initial access, prioritize workstations and servers where untrusted users or code run locally. Hunt for Lazarus/FudModule and BYOVD-related indicators per Avast's published research on hosts of interest. | 7.8 | 60% | KEV ransomware PoC ×3 |
| masson the order of 1 billion devices (essentially the entire supported Windows 10/11 and Windows Server 2019/2022 installed base) | |
| CVE-2024-29748 +1 in the same advisory: …29745 | Local Privilege Escalation in Google Pixel (Android), Exploited in the Wild Google Pixel devices running affected Android software contain a privilege escalation flaw (CVE-2024-29748) caused by a logic error that allows a security bypass. Exploitation is local to the device and requires user interaction, but the attacker needs no additional execution privileges to complete the escalation. A successful exploit grants the attacker elevated privileges on the device with high impact on confidentiality, integrity, and availability. All unpatched Google Android Pixel devices are affected; the source data does not specify exact affected version ranges. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2024-04-04, and press reporting describes Google patching actively exploited Pixel zero-day flaws, with reporting tying the exploitation to forensic/phone-cracking companies. Do: Update Pixel devices with Google's latest Android security update and verify the Android security patch level is April 2024 or later in Settings > About phone; this is a CISA KEV entry, so apply vendor mitigations promptly or discontinue use per the KEV required action. Because exploitation requires local access and user interaction, restrict device access to untrusted parties and avoid side-loading untrusted apps on unpatched devices. No public proof-of-concept is known, but active exploitation means patching should not wait. | 7.8 group max | <1% | KEV |
| mass≈tens of millions of Pixel smartphones (estimated active install base; only devices not yet on the vendor's security update are exploitable) | |
| CVE-2024-32896 | Local Privilege Escalation in Google Android Pixel Kernel CVE-2024-32896 is a logic error (CWE-670/CWE-783) in Android code on Google Pixel devices that allows a bypass leading to local escalation of privilege. The flaw is triggered through local access with no additional execution privileges required, and user interaction is needed for exploitation to succeed. A successful attack yields high impact to confidentiality, integrity, and availability on the affected device (CVSS 3.1 base score 7.8), giving an attacker elevated control of the phone. Per CISA's advisory, only Google Pixel devices running Android are affected. The vulnerability is being exploited in the wild: it was added to CISA's KEV catalog on 2024-06-13, and news coverage describes limited, targeted exploitation of the Android kernel flaw as a zero-day, with users urged to install the latest security updates. Do: Apply the latest Android security updates from Google (June 2024 security patch level or later) to all Pixel devices, per vendor instructions and CISA's required action. Users can verify their patch level under Settings > About phone > Android security update. Given reports of limited, targeted zero-day exploitation, prioritize patching high-risk users and treat the flaw as a post-compromise privilege-escalation risk. | 7.8 | 3% | KEV |
| masstens of millions of Pixel devices (estimated active Pixel install base; exact count unknown) | |
| CVE-2024-38178 | Unauthenticated RCE via Memory Corruption in Microsoft Windows Scripting Engine CVE-2024-38178 is a memory corruption flaw (CWE-843 type confusion) in the Microsoft Windows Scripting Engine that allows an unauthenticated attacker to execute arbitrary code. Exploitation is triggered when a user is lured into opening a specially crafted URL, so no prior authentication or network access to the target is required. A successful attack gains remote code execution, typically in the context of the fooled user's privileges. Any supported Microsoft Windows system with the scripting engine is affected, per CISA's listing of 'Microsoft Windows'. The vulnerability is confirmed to be exploited in the wild: CISA added it to the KEV catalog on 2024-08-13, coinciding with Microsoft's August 2024 Patch Tuesday, and EPSS assigns a high 41.4% probability of exploitation in the next 30 days. Do: Apply Microsoft's August 2024 Windows cumulative security updates immediately, prioritizing internet-facing and high-value systems, and verify patch levels against the KBs released 2024-08-13. As interim mitigation, limit user exposure to untrusted links and consider restricting or disabling legacy scripting/IE-mode rendering where business needs allow. No public PoC is known, but KEV listing confirms active exploitation, so hunt for anomalous process spawns from browsing/link-opening activity and apply CISA's required action of vendor mitigations or discontinuing use. | 7.5 | 41% | KEV |
| masshundreds of millions of Windows devices worldwide | |
| CVE-2024-44308 +1 in the same advisory: …44309 | Arbitrary Code Execution via Crafted Web Content in Apple Safari, iOS, macOS and visionOS CVE-2024-44308 is a code execution vulnerability in the web content processing engine used by Safari and Apple's operating systems, which Apple addressed with improved checks in emergency updates released in November 2024. It is triggered when a device processes maliciously crafted web content, for example when a user is lured to an attacker-controlled webpage, and requires user interaction (CVSS 3.1: AV:N/UI:R). Successful exploitation yields arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Users of Safari before 18.1.1, iOS and iPadOS before 17.7.2 and 18.1.1, macOS Sequoia before 15.1.1, and visionOS before 2.1.1 are affected; Debian Linux is also listed in the CPE data but no Debian-specific fix version was provided in the source. Apple reported active exploitation, specifically on Intel-based Mac systems, and CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2024-11-21; EPSS assigns a 9.4% probability of exploitation within 30 days. Do: Immediately update to Safari 18.1.1, iOS/iPadOS 17.7.2 or 18.1.1, macOS Sequoia 15.1.1 and visionOS 2.1.1, prioritizing Intel-based Macs since confirmed exploitation was reported on those systems. Federal agencies must patch per CISA's KEV requirement (added 2024-11-21), and defenders should review unpatched Macs for signs of browser-based compromise. Debian users should monitor their vendor's advisory for a WebKit-related backport, as no fixed Debian version was specified in the source data. | 8.8 group max | 10% | KEV |
| masshundreds of millions to 1 billion+ users (Apple's global active device base across iPhone, iPad, Mac, Vision Pro and Safari) | |
| CVE-2024-49039 | Windows Task Scheduler Elevation-of-Privilege Flaw Actively Exploited in the Wild CVE-2024-49039 is an elevation-of-privilege vulnerability (CWE-287, improper authentication) in the Microsoft Windows Task Scheduler, scored 8.8 (High) with a local attack vector, low required privileges, and a changed scope indicating the exploit crosses a security boundary. A local attacker with limited user privileges can trigger the flaw through Task Scheduler to gain elevated rights on the affected system, typically SYSTEM- or administrator-level control, with no user interaction required. Every supported Windows desktop and server release in the vendor's affected list is impacted, since Task Scheduler is a core component of the operating system. The flaw was patched as an actively exploited zero-day in the November 2024 Patch Tuesday release, was added to CISA's Known Exploited Vulnerabilities catalog on 2024-11-12, and ransomware operators are known to use it. With an EPSS of 14.2% (96th percentile), defenders should treat this as a high-priority local privilege escalation for privilege-chaining and ransomware campaigns. Do: Apply the November 2024 Windows security updates across all affected Windows 10, Windows 11, and Windows Server branches, prioritizing servers, jump hosts, and machines used by privileged users given confirmed ransomware use. Confirm no supported Windows host is left unpatched, review local task creation and authentication logs for signs of privilege escalation, and follow CISA's required action to apply vendor mitigations or discontinue use if patches are unavailable. | 8.8 | 14% | KEV ransomware |
| masshundreds of millions of Windows systems (Task Scheduler ships with every Windows 10, Windows 11, and Windows Server installation) | |
| CVE-2024-53104 | Out-of-Bounds Write in Linux Kernel UVC Video Driver (CVE-2024-53104) CVE-2024-53104 is an out-of-bounds write (CWE-787) in the Linux kernel's uvcvideo (USB Video Class) driver: uvc_parse_format does not skip frames of type UVC_VS_UNDEFINED, but those frame types were not accounted for when sizing the frames buffer in uvc_parse_streaming. The flaw is triggered when the kernel parses format/frame descriptors from a USB camera device, so a crafted or nonconforming USB video descriptor can corrupt adjacent kernel memory. An attacker with local, low-privileged access (CVSS 3.1: AV:L/AC:L/PR:L, 7.8 High) can gain kernel memory corruption with high impact to confidentiality, integrity and availability, typically yielding local privilege escalation. Any Linux system or Android device running a kernel that ships the UVC driver is in scope, including Debian and other distributions built from affected kernel sources. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV on 2025-02-05, Google fixed it as an actively exploited flaw in the March 2025 Android Security Update, and EPSS currently estimates a 3.4% (88th percentile) probability of exploitation over the next 30 days. Do: Upgrade to a Linux kernel version that contains the uvcvideo fix (apply updated kernel packages from your distribution, e.g. Debian), and for Android devices install the March 2025 Android Security Bulletin patches or later. Follow the CISA KEV required action by applying vendor mitigations or discontinuing use if patches are unavailable. To gauge exposure on unpatched hosts, check whether the UVC driver is loaded (e.g. 'lsmod | grep uvcvideo') and restrict untrusted USB video devices until patched. | 7.8 | 3% | KEV |
| masshundreds of millions of Linux/Android installations potentially carrying the vulnerable driver (Linux kernel runs on billions of devices and the UVC driver… | |
| CVE-2024-55956 | Unauthenticated File Upload RCE in Cleo Harmony, VLTrader, and LexiCom CVE-2024-55956 is an unauthenticated command-execution flaw (CWE-77) in Cleo's managed file transfer products: by default the Autorun directory automatically imports and runs files, so an unauthenticated attacker can import Bash or PowerShell commands that execute on the host. It is triggered over the network with no authentication and no user interaction (CVSS 3.1 score 9.8), by sending crafted import requests to a vulnerable Cleo server. Successful exploitation yields arbitrary command execution on the server, enabling data theft, lateral movement, and ransomware deployment. Any organization running Cleo Harmony, VLTrader, or LexiCom before 5.8.0.24 is affected — typically enterprises using these servers for EDI and partner file exchange. The flaw is actively exploited in the wild: it was added to CISA KEV on 2024-12-17 with known ransomware use (widely attributed to Cl0p), EPSS is 94% (top percentile), and confirmed downstream breaches such as WK Kellogg's have been tied to it. Do: Upgrade all Cleo Harmony, VLTrader, and LexiCom instances to 5.8.0.24 or later immediately, per the CISA KEV required action to apply vendor mitigations or discontinue use. If patching is delayed, restrict or remove internet exposure of the server. Because exploitation is confirmed and ransomware-linked, inspect the Autorun directory for unexpected imported files, review application logs for executed commands, and hunt for signs of data exfiltration or staging. | 9.8 | 94% | KEV ransomware PoC |
| largetens of thousands of installations (Cleo cites 100,000+ business customers; public internet scans showed roughly 1,000–2,000 exposed instances) | |
| CVE-2024-9680 | Use-After-Free in Mozilla Firefox Animation Timelines Allows Code Execution Mozilla Firefox and Firefox ESR contain a use-after-free (CWE-416) in the browser's animation timelines component, which CISA describes as allowing code execution in the content process. The flaw is reachable through malicious web content: a crafted page can manipulate animation timelines so that an in-use object is freed, producing exploitable memory corruption. A successful attacker gains code execution in the content process, the sandboxed process that renders web pages, on the machine of the user who loaded the content. All users of Firefox and Firefox ESR are affected by the flaw itself. It is being actively exploited: the vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2024-10-15 with known ransomware use, and EPSS assigns it a 23.2% probability of exploitation in the next 30 days (98th percentile). Do: Apply Mozilla's patched Firefox/Firefox ESR release immediately and verify the running version via the browser's About Firefox dialog, since many installs only pick up auto-updates after a restart (per CISA's required action: apply mitigations per vendor instructions or discontinue use). Given the known ransomware use, prioritize enterprise ESR rollout and check for managed-update failures, auto-update-disabled installs, or unmanaged Firefox copies on user machines. Note that no public proof-of-concept is known, but KEV listing confirms exploitation, so patching should not wait for PoC availability. | 9.8 | 23% | KEV ransomware |
| masshundreds of millions of users (Firefox's global desktop user base of roughly 150-200M active users, plus enterprise Firefox ESR deployments) |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | gov.ua | website of the Diplomatic Academy of Ukraine (online.da.mfa.gov[.]ua), which triggered an exploit for CVE-2024-44308 , resulti |
| domain | microsoftonline.com | ect users' cookies in order to unauthorized access to login.microsoftonline[.]com. The tech giant further noted that it independently disco |
Full article754 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 29, 2025Enterprise Security / Vulnerability
Google has revealed that it observed 75 zero-day vulnerabilities exploited in the wild in 2024, down from 98 in 2023 but an increase from 63 the year before.
Of the 75 zero-days, 44% of them targeted enterprise products. As many as 20 flaws were identified in security software and appliances.
"Zero-day exploitation of browsers and mobile devices fell drastically, decreasing by about a third for browsers and by about half for mobile devices compared to what we observed last year," the Google Threat Intelligence Group (GTIG) said in a report shared with The Hacker news.
"Exploit chains made up of multiple zero-day vulnerabilities continue to be almost exclusively (~90%) used to target mobile devices."
While Microsoft Windows accounted for 22 of the zero-day flaws exploited in 2024, Apple's Safari had three, iOS had two, Android had seven, Chrome had seven, and Mozilla Firefox had one flaw that were abused during the same period. Three of the seven zero-days exploited in Android were found in third-party components.
Among the exploited 33 zero-days in enterprise software and appliances, 20 of them targeted security and network products, such as those from Ivanti, Palo Alto Networks, and Cisco.
"Security and network tools and devices are designed to connect widespread systems and devices with high permissions required to manage the products and their services, making them highly valuable targets for threat actors seeking efficient access into enterprise networks," GTIG researchers noted.
In all, a total of 18 unique enterprise vendors were targeted in 2024, in comparison to 12 in 2021, 17 in 2022, and 22 in 2023. The companies with the most targeted zero-days were Microsoft (26), Google (11), Ivanti (7), and Apple (5).
Google, which defines zero-days as vulnerabilities exploited in the wild before a patch is made publicly available, said state-backed cyber espionage was still the leading motivation behind the exploitation of a significant chunk of the bugs. The zero-day exploitation of 34 of the 75 flaws have been attributed to six broad threat activity clusters -
- State-sponsored espionage (10), led by China (5), Russia (1), and South Korea (1) (e.g., CVE-2023-46805, CVE-2024-21887)
- Commercial surveillance vendors (8) (e.g., CVE-2024-53104, CVE-2024-32896, CVE-2024-29745, CVE-2024-29748)
- Non-state financially motivated groups (5) (e.g., CVE-2024-55956)
- State-sponsored espionage and financially motivated groups (5), all from North Korea (e.g., CVE-2024-21338, CVE-2024-38178)
- Non-state financially motivated groups also conducting espionage (2), all from Russia (e.g. CVE-2024-9680, CVE-2024-49039)
Google said it discovered in November 2024 a malicious JavaScript inject on the website of the Diplomatic Academy of Ukraine (online.da.mfa.gov[.]ua), which triggered an exploit for CVE-2024-44308, resulting in arbitrary code execution.
This was then chained with CVE-2024-44309, a cookie management vulnerability in WebKit, to launch a cross-site scripting (XSS) attack and ultimately collect users' cookies in order to unauthorized access to login.microsoftonline[.]com.
The tech giant further noted that it independently discovered an exploit chain for Firefox and Tor browsers that leveraged a combination of CVE-2024-9680 and CVE-2024-49039 to break out of the Firefox sandbox and execute malicious code with elevated privileges, thereby paving the way for the deployment of RomCom RAT.
The activity, previously flagged by ESET, has been attributed to a threat actor called RomCom (aka Storm-0978, Tropical Scorpius, UAC-0180, UNC2596, and Void Rabisu). Google is tracking the dual financial- and espionage-motivated threat group under the name CIGAR.
Both the flaws are said to have been abused as a zero-day by another likely financially motivated hacking crew that used a legitimate, compromised cryptocurrency news website as a watering hole to redirect visitors to an attacker-controlled domain hosting the exploit chain.
"Zero-day exploitation continues to grow at a slow but steady pace. However, we've also started seeing vendors' work to mitigate zero-day exploitation start to pay off," Casey Charrier, Senior Analyst at GTIG, said in a statement shared with The Hacker News.
"For instance, we have observed fewer instances of zero-day exploitation targeting products that have been historically popular, likely due to efforts and resources many large vendors have invested in order to prevent exploitation."
"At the same time, we're seeing zero-day exploitation shift towards the increased targeting of enterprise-focused products, which requires a wider and more diverse set of vendors to increase proactive security measures. The future of zero-day exploitation will ultimately be dictated by vendors' decisions and ability to counter threat actors' objectives and pursuits."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/04/google-reports-75-zero-days-exploited.html