ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

CISA Urges Government to Patch Exploited Cisco, Microsoft Flaws

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-8639
Kernel-mode privilege escalation in Microsoft Windows Win32k

CVE-2018-8639 is an improper resource shutdown or release flaw (CWE-404) in the Windows Win32k kernel component. A local, authenticated attacker can trigger the faulty resource handling and leverage it to execute arbitrary code in kernel mode, the highest privilege level on a Windows system. Successful exploitation effectively yields full system control (SYSTEM-equivalent), making it useful both for escalating from a low-privileged foothold and as a step in post-compromise activity, including ransomware operations. All Microsoft Windows versions covered by the vendor's advisory for this CVE are affected; the source data does not specify exact version ranges. The flaw is confirmed exploited in the wild: it was added to the CISA Known Exploited Vulnerabilities catalog on 2025-03-03 with known ransomware use, and EPSS estimates a 22.2% probability of exploitation within 30 days (98th percentile), though no public proof-of-concept is known.

Do: Apply Microsoft's security updates for all affected Windows releases immediately per vendor instructions, prioritizing servers, shared workstations, and systems where untrusted users can run code, since the flaw is in the CISA KEV catalog with known ransomware use. Follow applicable BOD 22-01 guidance for cloud services, or discontinue use where mitigations are unavailable. Until patched, restrict local code execution by untrusted accounts and monitor for unusual privilege-escalation activity.

7.822% KEV ransomware
  • Microsoft Windows
masswell over 1 billion Windows installations worldwide
CVE-2022-43939
+1 in the same advisory: …43769
Authorization Bypass in Hitachi Vantara Pentaho Business Analytics Server

Hitachi Vantara Pentaho Business Analytics (BA) Server versions before 9.4.0.1 and 9.3.0.2, including all 8.3.x releases, enforce security restrictions using non-canonical URL checks (CWE-647), so an attacker can circumvent authentication and authorization with crafted, non-canonical URL variants. The flaw is network-exploitable with no privileges or user interaction required (CVSS 3.1 score of 9.8), meaning a remote unauthenticated attacker can reach protected functionality simply by sending specially formed URLs to the server. A public proof-of-concept (published on Packet Storm) demonstrates the authentication bypass chained with server-side template injection (SSTI) to achieve code execution. Organizations running affected Pentaho BA Server versions — typically enterprises using the platform for BI reporting and analytics — are affected, particularly where the server is reachable from untrusted networks. The vulnerability was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, confirming exploitation in the wild, and EPSS assigns it a 92.3% probability of exploitation within 30 days (100th percentile).

Do: Upgrade Pentaho BA Server to 9.4.0.1 or 9.3.0.2 or later; 8.3.x deployments are also affected and must move to a fixed release per Hitachi Vantara's guidance. Federal agencies must apply the required BOD 22-01 mitigations per the KEV listing (or discontinue use if mitigations are unavailable). All defenders should identify internet-exposed Pentaho instances, restrict access to trusted networks where possible, and hunt for indicators of the authentication bypass/SSTI exploitation chain.

9.8
group max
92% KEV PoC
  • Hitachi Vantara Pentaho Business Analytics (BA) Server All versions before 9.4.0.1 and before 9.3.0.2, including all 8.3.x releases
moderate≈1,000–10,000 deployments (estimate; no authoritative install count available)
CVE-2023-20118
Authenticated Command Injection in Cisco Small Business RV Series Routers

CVE-2023-20118 is a command injection flaw (CWE-77) in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 routers, caused by improper validation of user input within incoming HTTP packets. An authenticated remote attacker who already holds valid administrative credentials sends a crafted HTTP request to the management interface and can execute arbitrary commands with root-level privileges, gaining full device control and access to unauthorized data. All organizations running these six small-business router models are affected, and Cisco has stated it will not release any software update, leaving only a workaround. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-03, carries a high EPSS score of 54.1%, and news reporting around that period describes campaigns (e.g., ViciousTrap, which built a global honeypot from roughly 5,300 compromised devices) abusing Cisco router flaws, with botnet operators such as PolarEdge also targeting Cisco small-business routers. These end-of-service devices are therefore under active, in-the-wild exploitation and should be treated as high-priority for mitigation.

Do: No firmware fix will ever be released, so apply Cisco's workaround by disabling the affected feature or restricting the web management interface to trusted management hosts only (disable remote/internet-facing management). Check device logs and configurations for signs of compromise, including unexpected configuration changes or outbound connections indicating botnet implants. Because these routers are end-of-service, plan migration to supported models and, for federal agencies, follow BOD 22-01 mitigation guidance or discontinue use.

7.254% KEV
  • Cisco RV016 Router (firmware) all firmware versions; no patched release available
  • Cisco RV042 Router (firmware) all firmware versions; no patched release available
  • Cisco RV042G Router (firmware) all firmware versions; no patched release available
  • +3 more
largetens of thousands of internet-exposed devices (order-of-magnitude estimate; at least ~5,300 already confirmed compromised in one reported campaign)
CVE-2024-4885
Unauthenticated Path Traversal RCE in Progress WhatsUp Gold

CVE-2024-4885 is an unauthenticated path traversal vulnerability (CWE-22) in the WhatsUp.ExportUtilities.Export.GetFileWithoutZip function of Progress WhatsUp Gold, a network monitoring platform. An attacker can send a crafted request to the affected export/file-retrieval functionality to traverse outside the intended directory, which leads to execution of commands on the server. Successful exploitation yields remote code execution running with the privileges of the iisapppool\mconsole application pool identity, giving control of the WhatsUp Gold monitoring server and, potentially, a foothold in the network. All WhatsUp Gold versions released before 2023.1.3 are affected, meaning any organization running an unpatched on-premises deployment is exposed, especially if the web interface is reachable from untrusted networks. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-03-03, and its 99.3% EPSS probability reflects very high expected exploitation; no public PoC is known, though headlines indicate exploitation followed shortly after a proof-of-concept for this WhatsUp Gold flaw.

Do: Upgrade WhatsUp Gold to version 2023.1.3 or later, per Progress's advisories (which shipped patches for this and several related WhatsUp Gold flaws). Until patched, restrict access to the WhatsUp Gold web interface to trusted networks and review logs for unexpected requests to the export utility; federal agencies must apply vendor mitigations or follow BOD 22-01 guidance by the KEV due date. Because the flaw is unauthenticated and exploited in the wild, treat any internet-facing, unpatched instance as compromised until verified.

9.899% KEV
  • progress whatsup gold all versions released before 2023.1.3
moderatelow thousands of internet-exposed WhatsUp Gold servers; total on-prem deployments plausibly in the tens of thousands
Full article258 words · extracted from infosecurity-magazine.com · click to collapse

A leading US security agency has ordered federal government bodies to patch five vulnerabilities it claims are being actively exploited by threat actors.

The latest additions to the CISA Known Exploited Vulnerabilities (KEV) catalog include CVE-2023-20118, a command injection vulnerability in the web-based management interface of multiple Cisco Small Business RV Series routers.

“Successful exploitation could allow an authenticated, remote attacker to gain root-level privileges and access unauthorized data,” said CISA yesterday.

CVE-2018-8639 is an improper resource shutdown or release vulnerability in Microsoft Windows Win32k which enables local, authenticated privilege escalation.

“An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode,” CISA warned.

Read more on KEV: UK Lags Europe on Exploited Vulnerability Remediation

The three remaining CVEs added to the KEV catalog are:

  • CVE-2022-43939: A server authorization bypass vulnerability in Hitachi Vantara Pentaho BA (business analytics) servers
  • CVE-2022-43769: A special element injection vulnerability in Hitachi Vantara Pentaho BA servers
  • CVE-2024-4885: A path traversal vulnerability in Progress WhatsUp Gold network monitoring software

There’s little additional information about how the above are being exploited in the wild, although it’s not unusual for threat actors to revisit legacy CVEs which may have been passed over by patch management programs, such as the Win32k bug from 2018.

In the case of all vulnerabilities, CISA recommends the following: “Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.”

Federal civilian agencies have until March 24 to patch the above CVEs.

Image credit: JHVEPhoto / Shutterstock.com

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/cisa-govt-patch-exploited-cisco/