ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

44% Of The Zero-Days Exploited In 2024 Were In Enterprise Solutions

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-29748
+1 in the same advisory: …29745
Local Privilege Escalation in Google Pixel (Android), Exploited in the Wild

Google Pixel devices running affected Android software contain a privilege escalation flaw (CVE-2024-29748) caused by a logic error that allows a security bypass. Exploitation is local to the device and requires user interaction, but the attacker needs no additional execution privileges to complete the escalation. A successful exploit grants the attacker elevated privileges on the device with high impact on confidentiality, integrity, and availability. All unpatched Google Android Pixel devices are affected; the source data does not specify exact affected version ranges. The flaw is being exploited in the wild: CISA added it to the KEV catalog on 2024-04-04, and press reporting describes Google patching actively exploited Pixel zero-day flaws, with reporting tying the exploitation to forensic/phone-cracking companies.

Do: Update Pixel devices with Google's latest Android security update and verify the Android security patch level is April 2024 or later in Settings > About phone; this is a CISA KEV entry, so apply vendor mitigations promptly or discontinue use per the KEV required action. Because exploitation requires local access and user interaction, restrict device access to untrusted parties and avoid side-loading untrusted apps on unpatched devices. No public proof-of-concept is known, but active exploitation means patching should not wait.

7.8
group max
<1% KEV
  • google Android Pixel (Pixel smartphones, Android OS/firmware)
mass≈tens of millions of Pixel smartphones (estimated active install base; only devices not yet on the vendor's security update are exploitable)
CVE-2024-32896
Local Privilege Escalation in Google Android Pixel Kernel

CVE-2024-32896 is a logic error (CWE-670/CWE-783) in Android code on Google Pixel devices that allows a bypass leading to local escalation of privilege. The flaw is triggered through local access with no additional execution privileges required, and user interaction is needed for exploitation to succeed. A successful attack yields high impact to confidentiality, integrity, and availability on the affected device (CVSS 3.1 base score 7.8), giving an attacker elevated control of the phone. Per CISA's advisory, only Google Pixel devices running Android are affected. The vulnerability is being exploited in the wild: it was added to CISA's KEV catalog on 2024-06-13, and news coverage describes limited, targeted exploitation of the Android kernel flaw as a zero-day, with users urged to install the latest security updates.

Do: Apply the latest Android security updates from Google (June 2024 security patch level or later) to all Pixel devices, per vendor instructions and CISA's required action. Users can verify their patch level under Settings > About phone > Android security update. Given reports of limited, targeted zero-day exploitation, prioritize patching high-risk users and treat the flaw as a post-compromise privilege-escalation risk.

7.83% KEV
  • google Android (Pixel)
masstens of millions of Pixel devices (estimated active Pixel install base; exact count unknown)
CVE-2024-53104
Out-of-Bounds Write in Linux Kernel UVC Video Driver (CVE-2024-53104)

CVE-2024-53104 is an out-of-bounds write (CWE-787) in the Linux kernel's uvcvideo (USB Video Class) driver: uvc_parse_format does not skip frames of type UVC_VS_UNDEFINED, but those frame types were not accounted for when sizing the frames buffer in uvc_parse_streaming. The flaw is triggered when the kernel parses format/frame descriptors from a USB camera device, so a crafted or nonconforming USB video descriptor can corrupt adjacent kernel memory. An attacker with local, low-privileged access (CVSS 3.1: AV:L/AC:L/PR:L, 7.8 High) can gain kernel memory corruption with high impact to confidentiality, integrity and availability, typically yielding local privilege escalation. Any Linux system or Android device running a kernel that ships the UVC driver is in scope, including Debian and other distributions built from affected kernel sources. Exploitation is confirmed in the wild: the vulnerability was added to CISA's KEV on 2025-02-05, Google fixed it as an actively exploited flaw in the March 2025 Android Security Update, and EPSS currently estimates a 3.4% (88th percentile) probability of exploitation over the next 30 days.

Do: Upgrade to a Linux kernel version that contains the uvcvideo fix (apply updated kernel packages from your distribution, e.g. Debian), and for Android devices install the March 2025 Android Security Bulletin patches or later. Follow the CISA KEV required action by applying vendor mitigations or discontinuing use if patches are unavailable. To gauge exposure on unpatched hosts, check whether the UVC driver is loaded (e.g. 'lsmod | grep uvcvideo') and restrict untrusted USB video devices until patched.

7.83% KEV
  • Linux kernel (uvcvideo / USB Video Class driver)
  • Debian Linux
masshundreds of millions of Linux/Android installations potentially carrying the vulnerable driver (Linux kernel runs on billions of devices and the UVC driver…
Full article674 words · extracted from helpnetsecurity.com · click to collapse

In 2024, threat actors exploited 75 zero-days – i.e., vulnerabilities previously unknown to vendors, thus without a readily available patch – in a wide variety of attacks.

Of these, 33 vulnerabilities (44%) affected enterprise solutions, which is up from 37% in 2023, according to Google Threat Intelligence Group researchers.

“Zero-day vulnerabilities in security software and appliances were a high-value target in 2024. We identified 20 security and networking vulnerabilities, which was over 60% of all zero-day exploitation of enterprise technologies,” they noted.

“Exploitation of these products, compared to end-user technologies, can more effectively and efficiently lead to extensive system and network compromises, and we anticipate adversaries will continue to increase their focus on these technologies.”

Interesting findings

Google Threat Intelligence Group has released its yearly analysis of the zero-day vulnerabilities exploited in the past year, and has pinpointed a number of interesting trends in the user-end technology side:

  • Zero-day exploitation of browsers and mobile devices fell drastically, when compared with 2023 numbers: 17 to 11 for browsers, and 17 to 9 for mobile.
  • Exploit chains consisting of multiple zero-days are almost exlusively aimed at targeting mobile users
  • There has been a marked decrease of exploitation of vulnerabilities in Apple’s Safari browser and iOS mobile OS

Source: GTIG

On the enterprise-focused technology side, it’s notable that attackers targeted vulnerabilities in solutions by 18 unique vendors (out of 20 in total).

“The vendors affected by multiple 2024 zero-day vulnerabilities generally fell into two categories: big tech (Microsoft, Google, and Apple) and vendors who supply security and network-focused products,” they determined.

“As expected, big tech took the top two spots, with Microsoft at 26 and Google at 11. Apple slid to the fourth most frequently exploited vendor this year, with detected exploitation of only five zero-days. Ivanti was third most frequently targeted with seven zero-days, reflecting increased threat actor focus on networking and security products.”

Ivanti’s rise on the list is partly due to an increase of exploitation of security and network technologies by threat actors backed by the People’s Republic of China.

“Security and network tools and devices are designed to connect widespread systems and devices with high permissions required to manage the products and their services, making them highly valuable targets for threat actors seeking efficient access into enterprise networks,” the researchers explained.

“Endpoint detection and response (EDR) tools are not usually equipped to work on these products, limiting available capabilities to monitor them. Additionally, exploit chains are not generally required to exploit these systems, giving extensive power to individual vulnerabilities that can single-handedly achieve remote code execution or privilege escalation.”

And while state-sponsored hackers concentrated on exploiting zero-days in firewalls, VPN and security appliances, financially motivated groups concentrated on hitting vulnerable managed file transfer products (e.g., by Cleo).

As expected, commercial spyware vendors continued leverage zero-days. “In 2024, we observed multiple exploitation chains using zero-days developed by forensic vendors that required physical access to a device (CVE-2024-53104, CVE-2024-32896, CVE-2024-29745, CVE-2024-29748). These bugs allow attackers to unlock the targeted mobile device with custom malicious USB devices,” the researchers noted.

Advice for vendors

The most frequent types of zero-day vulnerabilities exploited in 2024 were use-after-free, command/code injection, and cross-site scripting vulnerabilities, and these can be prevented by prioritizing higher coding standards and preventative practices such as regular code reviews, refactoring outdated codebases, and relying on up-to-date, trusted libraries, the researchers noted.

Newly targeted vendors and vendors of enterprise products that are being increasingly targeted should improve their security practices and procedures, shore up protection mechanisms, and consider addressing gaps in configurations and architectural decisions that could permit exploitation.

“We continue to see the same types of vulnerabilities exploited over time, indicating patterns in what weaknesses attackers seek out and find most beneficial to exploit. Continued existence and exploitation of similar issues makes zero-days easier; threat actors know what to look for and where exploitable weaknesses are most pervasive,” they added.

Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2025/04/29/44-of-the-zero-days-exploited-in-2024-were-in-enterprise-solutions/