ZeroHour
Security Affairspublished ()ingested @securityaffairs

U.S. CISA adds Microsoft Windows Kernel-Mode Driver and Adobe ColdFusion flaws to its Known Exploited Vulnerabilities catalog

highExploit / PoC exploited in the wildimportance 60CVE-2024-35250CVE-2024-20767CVE-2024-49138

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20767
Improper Access Control in Adobe ColdFusion Enables Arbitrary File Read

Adobe ColdFusion contains an improper access control flaw (CWE-284) that allows an unauthenticated attacker to read arbitrary files on the server's file system; per Adobe's advisory, an attacker could also access or modify restricted files. Exploitation occurs over the network with no authentication and no user interaction, but it requires the ColdFusion Administrator panel to be exposed to the internet. A successful attacker can retrieve restricted files, potentially exposing sensitive configuration and credential material stored on the server. Organizations running ColdFusion 2023.6 or earlier on the 2023 release, or 2021.12 or earlier on the 2021 release, with the admin panel reachable from the internet are affected. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-16, thousands of exploit attempts were observed during the Christmas holiday, and EPSS assigns a 98.5% probability of exploitation within 30 days.

Do: Upgrade ColdFusion 2023 to a version later than 2023.6 and ColdFusion 2021 to a version later than 2021.12 per Adobe's advisory and CISA's required action. If patching must be deferred, keep the ColdFusion Administrator panel off the public internet by restricting it via firewall, VPN, or IP allowlisting, since internet exposure of the admin panel is required for exploitation. Given the KEV listing (2024-12-16) and thousands of observed exploit attempts over the Christmas holiday, organizations with internet-exposed ColdFusion servers should review logs for exploitation activity and treat prior exposure as a potential compromise.

7.499% KEV
  • Adobe ColdFusion 2023 2023.6 and earlier
  • Adobe ColdFusion 2021 2021.12 and earlier
largeon the order of 10,000-100,000 potentially exposed systems (tens of thousands of internet-reachable ColdFusion servers, of which only those with the…
CVE-2024-35250
Local Privilege Escalation in Microsoft Windows Kernel-Mode Driver

CVE-2024-35250 is an untrusted pointer dereference flaw (CWE-822) in a Microsoft Windows kernel-mode driver, where a pointer supplied by untrusted code is mishandled. A local attacker who can already execute code on a vulnerable Windows system can trigger the flaw to run code in kernel context. Successful exploitation yields elevation of privilege, typically to SYSTEM-level rights, which can be chained with other weaknesses for fuller system compromise. Practically all Windows installations are potentially affected, though the bug is not remotely exploitable and requires an attacker to first gain local access. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-16, EPSS assigns a 25% probability of exploitation within 30 days (98th percentile), and no public PoC is known.

Do: Apply Microsoft's security updates immediately — the flaw was fixed in Microsoft's June 2024 Patch Tuesday release, so confirm affected hosts are at or beyond that patch level using Microsoft's advisory and your patch telemetry. Because exploitation requires a local foothold, prioritize multi-user servers, shared workstations, and RDS/VDI hosts, and treat this bug as an escalation vector when hunting post-compromise activity. CISA KEV requires applying vendor mitigations (or discontinuing use) by the stated deadline; ransomware use is currently unknown.

7.825% KEV
  • Microsoft Windows
mass≈1 billion+ Windows devices (Windows exceeds one billion active devices worldwide)
CVE-2024-49138
Local Privilege Escalation via Heap Overflow in Microsoft Windows CLFS Driver

Microsoft's Windows Common Log File System (CLFS) driver contains a heap-based buffer overflow (CWE-122) that a local attacker can trigger by submitting crafted input to the CLFS component after gaining the ability to run code on the target machine. Successful exploitation overwrites heap memory in the kernel driver and allows the attacker to escalate privileges, typically from an ordinary user account to SYSTEM-level execution. Any Microsoft Windows system is potentially affected; the CISA listing identifies only "Microsoft Windows" and does not enumerate specific versions or builds, and no CVSS score has been published yet. The flaw was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on 2024-12-10, confirming it is being exploited in the wild (ransomware use is unknown), and EPSS assigns a 25.4% probability of exploitation activity within 30 days (98th percentile). No public proof-of-concept is known, but the in-the-wild exploitation means defenders should treat this as an actively used privilege-escalation primitive, often chained after initial access by malware or another exploit.

Do: Apply Microsoft's security update for Windows per vendor instructions, as required by the CISA KEV listing (added 2024-12-10), and verify patch compliance across Windows endpoints. Because this is a local privilege escalation, prioritize hosts where untrusted users or malware execute code, and review telemetry for local code execution followed by unexpected escalation to SYSTEM. No public PoC exists, so detection should rely on vendor advisory guidance and EDR telemetry rather than public exploit signatures.

7.825% KEV PoC ×2
  • Microsoft Windows
masshundreds of millions to 1 billion+ Windows installations (Windows runs on 1B+ active devices)
Full article280 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 17, 2024

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows Kernel-Mode Driver and Adobe ColdFusion flaws to its Known Exploited Vulnerabilities catalog.

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference (CVE-2024-35250) and Adobe ColdFusion Improper Access Control (CVE-2024-20767) vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability CVE-2024-35250 (CVSS score 7.8) is a Windows Kernel-Mode Driver Elevation of Privilege issue

A local attacker could exploit this vulnerability to gain SYSTEM privileges. The attack complexity is labeled as low.

The vulnerability CVE-2024-20767 (CVSS score 7.4) is an Improper Access Control issue in ColdFusion versions 2023.6, 2021.12, and earlier. An attacker can exploit the flaw to gain arbitrary file reads. Exploitation requires an exposed admin panel.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts also recommend private organizations review the Catalog and address the vulnerabilities in their infrastructure.

CISA orders federal agencies to fix this vulnerability by January 6, 2025.

The US agency is unaware of ransomware attacks exploiting the above vulnerabilities in the wild.

Last week, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another Microsoft flaw to its Known Exploited Vulnerabilities (KEV) catalog, the Windows Common Log File System (CLFS) driver vulnerability CVE-2024-49138  (CVSS score: 7.8).

CISA ordered federal agencies to fix this vulnerability by December 31, 2024.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, CISA)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172059/security/u-s-cisa-adds-microsoft-windows-kernel-mode-driver-and-adobe-coldfusion-flaws-to-its-known-exploited-vulnerabilities-catalog.html