ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA urges to fix actively exploited Firefox zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2009-3960
Information Disclosure in Adobe BlazeDS (Used by LiveCycle and ColdFusion)

CVE-2009-3960 is an information disclosure vulnerability in Adobe BlazeDS, the Java-based remoting and messaging layer that ships with Adobe LiveCycle and is available with Adobe ColdFusion. An attacker can trigger the flaw by sending crafted requests to an application running an affected BlazeDS deployment, gaining access to information that should not be exposed. Successful exploitation can leak sensitive data and, as observed in the Cring ransomware campaign against unpatched ColdFusion servers, can serve as an initial foothold that leads to further compromise and ransomware deployment. Organizations running BlazeDS as part of LiveCycle or ColdFusion deployments are affected. The flaw has been exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, with ransomware use explicitly confirmed and a very high EPSS of 90%.

Do: Apply updates per vendor instructions as required by CISA, upgrading BlazeDS, LiveCycle, and ColdFusion to the patched releases specified in Adobe's advisory. Prioritize internet-facing ColdFusion and LiveCycle servers, verify BlazeDS-related endpoints are patched, and check for signs of compromise given known ransomware use. Until patched, restrict external access to BlazeDS/ColdFusion endpoints where feasible.

90% KEV ransomware
  • Adobe BlazeDS (as used in LiveCycle and ColdFusion)
largeon the order of tens of thousands of internet-exposed ColdFusion/LiveCycle servers plausibly affected
CVE-2013-0625
Authentication Bypass in Adobe ColdFusion Grants Admin Access

CVE-2013-0625 is an authentication bypass (CWE-255) in Adobe ColdFusion that lets an unauthorized, unauthenticated user gain administrative access to the ColdFusion Administrator. It is triggered by remote requests against vulnerable ColdFusion installations' administrative interfaces (the source data specifies no technical details beyond the bypass itself), and an attacker who succeeds can take administrative control of the ColdFusion server, which in practice can be leveraged to run arbitrary commands on the host. Organizations running legacy ColdFusion are affected, with CISA's 2022 alert citing versions 9.0, 9.0.1, 9.0.2, and 10, and internet-exposed admin endpoints being the highest-risk targets. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07 after observed threat-actor use, and EPSS assigns it a 93.8% probability of exploitation in the next 30 days.

Do: Apply updates per vendor instructions — the applicable Adobe ColdFusion security hotfixes (APSB13-03 era) for 9.x/10, and ideally upgrade to a currently supported ColdFusion release since those versions are end-of-life. Until patched, restrict /CFIDE/administrator and related admin API paths to trusted networks and confirm authentication is enforced. Review web logs for unauthenticated access to admin endpoints and check for unexpected administrative changes or command execution on the host.

94% KEV
  • Adobe ColdFusion
large≈10,000–50,000 internet-exposed ColdFusion servers, a meaningful share still on legacy 9.x/10 releases (order-of-magnitude estimate)
CVE-2013-0629
Actively Exploited Directory Traversal in Adobe ColdFusion

Adobe ColdFusion contains a directory traversal vulnerability (CWE-264) that permits an unauthorized user to access restricted directories outside the paths the application is meant to expose. It is triggered when an attacker submits crafted input containing directory traversal sequences to a ColdFusion server, bypassing the access controls that normally confine requests to allowed directories. Successful exploitation can allow an attacker to read files in restricted directories, potentially including configuration files containing credentials, enabling further compromise of the host. Any organization running Adobe ColdFusion servers is affected, with the highest risk on servers exposed to the internet. The flaw is confirmed exploited in the wild: it was added to CISA's KEV catalog on 2022-03-07 (federal agencies are required to patch per vendor instructions), EPSS assigns a 65.9% probability of exploitation within 30 days (99th percentile), ransomware association is unknown, and no public PoC is known.

Do: Inventory all Adobe ColdFusion installations — prioritizing internet-facing servers — and apply the applicable Adobe update per vendor instructions, which is a mandatory federal remediation under the KEV listing. Until patched, restrict network access to ColdFusion servers and monitor access logs for directory-traversal patterns. Because in-the-wild exploitation is confirmed, review affected servers for unauthorized directory/file access and exposed credentials.

66% KEV
  • Adobe ColdFusion
largetens of thousands of ColdFusion server deployments worldwide, with roughly 10,000–20,000 internet-exposed per public scans
CVE-2013-0631
Information Disclosure Flaw in Adobe ColdFusion Listed as Actively Exploited

Adobe ColdFusion contains an information disclosure vulnerability (CWE-200) that can result in sensitive information being exposed from a compromised server. The available data does not detail the exact trigger or access vector, but the flaw affects ColdFusion server deployments and leads to disclosure of information once a server is compromised. An attacker who successfully exploits it gains access to potentially sensitive data residing on the affected ColdFusion server. Any organization running Adobe ColdFusion may be affected; the data does not specify affected version ranges. The vulnerability is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, carries a 65.9% EPSS probability of exploitation within 30 days (99th percentile), and no public proof-of-concept is known.

Do: Apply Adobe's security updates for your installed ColdFusion version per vendor instructions, which is CISA's required action; given the 99th-percentile EPSS score and KEV listing, prioritize patching immediately. Inventory all ColdFusion servers (version is visible in the ColdFusion Administrator), reduce their network exposure, and review server logs for indicators of information disclosure or compromise. Ransomware use is reported as unknown, so treat any signs of exploitation as a possible precursor to broader compromise.

66% KEV
  • Adobe ColdFusion
moderateon the order of 10,000-50,000 internet-exposed ColdFusion servers (total deployments, including internal ones, likely higher)
CVE-2016-6277
Unauthenticated RCE via Command Injection in NETGEAR Multiple Routers

Multiple NETGEAR router models allow unauthenticated web pages to pass form input directly to the device's command-line interface, which permits remote code execution (CVE-2016-6277). An attacker triggers the flaw by sending a crafted HTTP request to the router's web interface without logging in, causing attacker-supplied input to be interpreted as commands on the router. Successful exploitation grants the ability to run arbitrary commands on the device, typically with root privileges, enabling full takeover of the router and use as a pivot point into the network behind it. Any NETGEAR router among the affected models running firmware without the vendor patch is vulnerable, with internet-facing management interfaces at greatest risk. The flaw was added to CISA's Known Exploited Vulnerability catalog on 2022-03-07, indicating exploitation in the wild, and it carries a very high 99.8% EPSS probability of exploitation within 30 days.

Do: Update affected NETGEAR routers to the latest available firmware for the specific model, per the vendor's upgrade instructions, as required by CISA's KEV listing. As interim mitigation, disable WAN-side/remote management and restrict the router's admin interface to the local network, then review devices for signs of compromise such as unexpected configuration changes or added accounts.

8.8100% KEV PoC ×3
  • NETGEAR
masslikely 100,000+ internet-exposed NETGEAR routers (exact count unknown)
CVE-2017-6077
Command Injection RCE in NETGEAR DGN2200 Router ping.cgi

ping.cgi on NETGEAR DGN2200 routers running firmware through version 10.0.0.50 fails to sanitize the ping_IPAddr field of HTTP POST requests, allowing shell metacharacters to inject arbitrary operating-system commands (CWE-78, OS command injection). Per the vulnerability description, an attacker needs authenticated access to the router's web interface to send the crafted POST request, although the CVSS vector treats the flaw as exploitable over the network without privileges — significant because many deployed routers use default or weak admin credentials. Successful exploitation yields arbitrary command execution on the device, enabling full router compromise, manipulation of DNS or routing, interception of traffic, and pivoting into the local network. All NETGEAR DGN2200 (Wireless Router) units on affected firmware are exposed, particularly those with the management interface reachable from the WAN. The flaw is actively exploited: it was added to the CISA Known Exploited Vulnerabilities catalog on 2022-03-07, carries a high exploitation probability (EPSS 68.2%, 99th percentile), and a public proof-of-concept is available (Exploit-DB 41394).

Do: Upgrade DGN2200 firmware to a version later than 10.0.0.50 per NETGEAR's guidance, as required by the CISA KEV listing; if the device is end-of-life and no fixed firmware is available, plan replacement. As interim mitigations, disable WAN-side remote management, restrict the admin interface to trusted hosts, and replace default credentials, since authenticated access is the trigger. Check web server logs for HTTP POST requests to ping.cgi containing shell metacharacters in the ping_IPAddr parameter.

9.868% KEV PoC
  • NETGEAR DGN2200 Wireless Router (ping.cgi web interface) firmware through 10.0.0.50 (inclusive)
largeon the order of tens of thousands of internet-exposed DGN2200 routers (legacy ISP-bundled ADSL units); total deployed base likely higher
CVE-2019-11581
Unauthenticated SSTI RCE in Atlassian Jira Server and Data Center

Atlassian Jira Server and Data Center contain a server-side template injection (CWE-74) in the ContactAdministrators and SendBulkMail actions, rated critical at CVSS 9.8. The flaw is triggered by sending crafted, template-syntax input to these mail-related actions over the network; because the vulnerability requires no authentication or user interaction per the CVSS vector, any attacker who can reach the Jira web interface can trigger it. Successful exploitation yields unauthenticated remote code execution on the server hosting Jira, with high impact on confidentiality, integrity, and availability. Organizations running any Jira Server or Data Center release in the 4.4–7.6, 7.7–7.13, 8.0, 8.1, or 8.2 lines prior to the listed fixed versions are affected, and the exposure is concentrated among instances reachable from the internet. The flaw is actively exploited: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07 with a required action to apply vendor updates, and EPSS places it in the 100th percentile (~84.6% probability of exploitation within 30 days).

Do: Apply the vendor updates per Atlassian/CISA instructions — upgrade to Jira 7.6.14, 7.13.5, 8.0.3, 8.1.2, or 8.2.3 (or later) as applicable, since this is a KEV item with a required patching action. As an interim mitigation, disable the 'Allow users to contact administrators' option in Jira's General Configuration to close the ContactAdministrators path and restrict SendBulkMail access, and limit exposure of the Jira web interface to the internet. Review access logs for requests hitting ContactAdministrators/SendBulkMail endpoints containing template injection payloads and hunt for signs of post-exploitation code execution on affected servers.

9.885% KEV
  • Atlassian Jira Server All versions from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3
  • Atlassian Jira Data Center All versions from 4.4.0 before 7.6.14, from 7.7.0 before 7.13.5, from 8.0.0 before 8.0.3, from 8.1.0 before 8.1.2, and from 8.2.0 before 8.2.3
largetens of thousands of internet-exposed Jira Server/Data Center instances
CVE-2020-8218
Code Injection RCE in Pulse Connect Secure Admin Web Interface

CVE-2020-8218 is a code injection vulnerability (CWE-94) in the admin web interface of Pulse Secure's Pulse Connect Secure SSL VPN appliance. An attacker triggers it by sending a specially crafted URI to the admin web interface, resulting in arbitrary code execution on the appliance. Successful exploitation gives the attacker code execution on the VPN gateway and a foothold from which internal networks behind the appliance could be reached. All organizations running Pulse Connect Secure are affected, particularly those whose admin web interface is reachable by untrusted users. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-07), confirming in-the-wild exploitation, and its 98th-percentile EPSS score (32.7% probability of exploitation within 30 days) indicates elevated risk; no public proof-of-concept is known.

Do: Apply the latest Pulse Connect Secure maintenance update per the vendor's instructions, as required by the CISA KEV listing. Until patched, restrict the admin web interface to trusted management networks or jump hosts and review admin interface logs for unusual crafted-URI requests or signs of post-exploitation. Because ransomware use is listed as unknown, treat any unpatched, internet-reachable appliance as high priority for patching and compromise assessment.

7.233% KEV PoC
  • Pulse Secure Pulse Connect Secure
largetens of thousands of internet-exposed Pulse Connect Secure appliances (public internet scans showed roughly 20,000-30,000+)
CVE-2021-21973
SSRF in VMware vCenter Server and Cloud Foundation (vSphere Client HTML5)

CVE-2021-21973 is a server-side request forgery (SSRF, CWE-918) in the vSphere Client (HTML5), caused by improper validation of URLs in a vCenter Server plugin. An unauthenticated attacker with network access to TCP port 443 can trigger it by sending a crafted POST request to the affected vCenter Server plugin, causing vCenter to make attacker-influenced internal requests. The direct impact is information disclosure (confidentiality only, CVSS 3.1 base 5.3), but SSRF in vCenter is frequently chained with other vCenter flaws to reach remote code execution, as reflected in the related advisories. Everyone running VMware vCenter Server 7.x/6.7/6.5 or VMware Cloud Foundation 4.x/3.x before the fixed releases is affected. The flaw is actively exploited: it is listed in CISA KEV (added 2022-03-07) and carries a very high EPSS (87.6%), with reporting of coordinated SSRF exploitation campaigns involving hundreds of source IPs.

Do: Upgrade vCenter Server to 7.0 U1c, 6.7 U3l, or 6.5 U3n, and Cloud Foundation to 4.2 or 3.10.1.2, per VMware's instructions. Until patched, restrict access to vCenter's port 443 from untrusted networks and review access logs for suspicious unauthenticated POST requests to the vSphere Client plugin endpoints. Given the KEV listing and reports of coordinated SSRF exploitation, treat patching as urgent even though this flaw alone yields information disclosure.

5.388% KEV
  • vmware vCenter Server 7.x before 7.0 U1c
  • vmware vCenter Server 6.7 before 6.7 U3l
  • vmware vCenter Server 6.5 before 6.5 U3n
  • +2 more
largetens of thousands of internet-exposed vCenter instances (likely 50,000+ on public port 443), with far more deployed internally in enterprise data centers
CVE-2022-26486
+1 in the same advisory: …26485
Use-After-Free Sandbox Escape in Mozilla Firefox and Thunderbird

CVE-2022-26486 is a use-after-free (CWE-416) in the WebGPU inter-process communication (IPC) framework of Mozilla Firefox, triggered when the IPC framework receives an unexpected message. An attacker who can get the browser to process malicious content gains a sandbox escape from the compromised content process, and the flaw was chained with the sibling zero-day CVE-2022-26485 in attacks observed in the wild. Users of Firefox, Firefox ESR, Firefox for Android, Firefox Focus, and Thunderbird running builds prior to the patched releases are affected. Exploitation is confirmed in the wild: the issue was disclosed as a zero-day, added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, and CISA urged defenders to patch promptly. Mozilla rated the fix urgent, and the flaw carries a critical CVSS 3.1 score of 9.6 with an EPSS 30-day exploitation probability of about 2.3%.

Do: Upgrade immediately: Firefox to 97.0.2 or later, Firefox ESR to 91.6.1 or later, Firefox for Android and Firefox Focus to 97.3.0 or later, and Thunderbird to 91.6.2 or later. Prioritize this patch because the flaw is a confirmed zero-day in CISA KEV; inventory managed endpoints for outdated Firefox/Thunderbird builds and, as an interim mitigation, consider disabling or restricting WebGPU where feasible until updates are applied.

9.6
group max
2% KEV PoC ×2
  • Mozilla Firefox < 97.0.2
  • Mozilla Firefox ESR < 91.6.1
  • Mozilla Firefox for Android < 97.3.0
  • +2 more
massplausibly hundreds of millions of users (Firefox alone has roughly 200M+ active users worldwide, plus Firefox for Android and Thunderbird installs)
Full article384 words · extracted from securityaffairs.com · click to collapse

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added recently disclosed Firefox zero-days to its Known Exploited Vulnerabilities Catalog.

The Cybersecurity and Infrastructure Security Agency (CISA) added two critical security vulnerabilities in Mozilla firefox, tracked as CVE-2022-26485 and CVE-2022-26486, to its Known Exploited Vulnerabilities Catalog. The US agency has ordered federal civilian agencies to address both issues by March 21, 2022.

Yesterday Mozilla has released Firefox 97.0.2, Firefox ESR 91.6.1, Firefox for Android 97.3.0, and Focus 97.3.0 to address the two zero-day vulnerabilities that are actively exploited in attacks.

The two vulnerabilities are “Use-after-free” issues in XSLT parameter processing and in the WebGPU IPC Framework respectively.

Successful exploitation of the flaws can cause a program crash or execute arbitrary commands on the machine.

Below is the description of both flaws included in the advisory published by Mozilla:

  • CVE-2022-26485: Removing an XSLT parameter during processing could have lead to an exploitable use-after-free. We have had reports of attacks in the wild abusing this flaw.
  • CVE-2022-26486: An unexpected message in the WebGPU IPC framework could lead to a use-after-free and exploitable sandbox escape. 

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Known Exploited Vulnerabilities Catalog and address the vulnerabilities in their infrastructure.

CISA added nine other vulnerabilities to its Known Exploited Vulnerabilities Catalog that are reported in the following table along with the associated due date.

CVE ID Vulnerability Name Due Date 
CVE-2022-26486Mozilla Firefox Use-After-Free Vulnerability03/21/22
CVE-2022-26485Mozilla Firefox Use-After-Free Vulnerability03/21/22
CVE-2021-21973VMware vCenter Server, Cloud Foundation Server Side Request Forgery (SSRF)03/21/22
CVE-2020-8218Pulse Connect Secure Code Injection Vulnerability09/07/22
CVE-2019-11581Atlassian Jira Server and Data Center Server-Side Template Injection Vulnerability09/07/22
CVE-2017-6077NETGEAR DGN2200 Remote Code Execution Vulnerability09/07/22
CVE-2016-6277NETGEAR Multiple Routers Remote Code Execution Vulnerability09/07/22
CVE-2013-0631Adobe ColdFusion Information Disclosure Vulnerability09/07/22
CVE-2013-0629Adobe ColdFusion Directory Traversal Vulnerability09/07/22
CVE-2013-0625Adobe ColdFusion Authentication Bypass Vulnerability09/07/22
CVE-2009-3960Adobe BlazeDS Information Disclosure Vulnerability09/07/22

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, SIM swapping)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/128803/security/cisa-firefox-zerodays-known-exploited-vulnerabilities-catalog.html