ZeroHour
Security Affairspublished ()ingested @securityaffairs

Security Affairs newsletter Round 538 by Pierluigi Paganini

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-29824
Use-After-Free Privilege Escalation in Microsoft Windows CLFS Driver (Actively Exploited)

CVE-2025-29824 is a use-after-free flaw (CWE-416) in the Windows Common Log File System (CLFS) kernel driver, scored 7.8 (High) with a local attack vector, low privileges required, and no user interaction. An authorized local attacker can trigger it by interacting with CLFS-managed log files in a way that references freed kernel memory. Successful exploitation elevates the attacker's local privileges, typically to SYSTEM, providing full control of the host that can be chained into ransomware deployment or lateral movement. Any unpatched system running the listed Windows 10, Windows 11, or Windows Server versions is affected. The flaw was exploited as a zero-day — reportedly by Play ransomware — before Microsoft shipped fixes in the April 2025 Patch Tuesday release; it was added to CISA's KEV catalog on 2025-04-08 with known ransomware use, and EPSS estimates a 13.9% probability of continued exploitation over 30 days (96th percentile).

Do: Apply Microsoft's April 2025 Patch Tuesday security updates for your Windows version immediately — the vendor update is the only complete fix, and the flaw is on the KEV list with known ransomware use, so prioritize servers and endpoints used by privileged users. Until patched, limit untrusted local code execution and review hosts for post-exploitation privilege escalation; public detection and mitigation scripts (e.g., Vicarius) are available to help hunt for exploitation. Federal agencies must apply the vendor mitigations per BOD 22-01 deadlines or discontinue use of affected versions.

7.814% KEV ransomware PoC ×2
  • microsoft Windows 10 1507 1507
  • microsoft Windows 10 1607 1607
  • microsoft Windows 10 1809 1809
  • +9 more
massHundreds of millions of Windows devices worldwide
CVE-2025-31324
Unauthenticated File Upload RCE in SAP NetWeaver Visual Composer

CVE-2025-31324 is a critical (CVSS 9.8) unrestricted file upload flaw (CWE-434) in the Visual Composer Metadata Uploader component of SAP NetWeaver, which lacks proper authorization. An unauthenticated attacker can send crafted upload requests over the network to the Metadata Uploader endpoint and plant malicious executable binaries, such as webshells, on the host. Executing the uploaded files yields remote code execution with full impact on confidentiality, integrity, and availability, enabling system compromise, lateral movement, and ransomware deployment. Any organization running the affected SAP NetWeaver component is at risk, with the greatest exposure for instances reachable from the internet. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2025-04-29, a public PoC exists, and researchers and media report active attacks, including by Chinese-linked actors deploying Golang-based implants on Linux systems and known ransomware use, often chained with CVE-2025-42999.

Do: Apply SAP's patch for CVE-2025-31324 (released in the April 2025 security updates) and follow the vendor mitigation instructions per CISA KEV/BOD 22-01 requirements. As interim mitigation, restrict or disable the Visual Composer Metadata Uploader endpoint and ensure it is not reachable from the internet; also patch the related CVE-2025-42999 since the flaws are being chained. Check affected hosts for uploaded webshells, Golang-based implants, and signs of ransomware activity.

9.8100% KEV ransomware PoC
  • sap netweaver
largetens of thousands of enterprise deployments worldwide, with several thousand instances directly internet-exposed
CVE-2025-43300
Actively Exploited Out-of-Bounds Write in Apple iOS/iPadOS/macOS Image I/O

CVE-2025-43300 is an out-of-bounds write (CWE-787) in the Image I/O (ImageIO) framework used by Apple iOS, iPadOS, and macOS. It can be triggered when a device processes a specially crafted image file, corrupting memory in the image-parsing process. Successful exploitation may cause application crashes or allow arbitrary code execution with the privileges of the application handling the image. Because ImageIO is a core system component on essentially every Apple device, virtually all users of iPhones, iPads, and Macs are exposed. The flaw is being exploited in the wild — CISA added it to the KEV catalog on 2025-08-21, mandating patching per BOD 22-01 for federal agencies — and EPSS estimates a 22% probability of exploitation in the next 30 days (98th percentile); no public PoC is known and ransomware use is unconfirmed.

Do: Apply Apple's security updates for iOS, iPadOS, and macOS issued in August 2025 (e.g., iOS 18.6.1 / iPadOS 18.6.1 and macOS Sequoia 15.6.1) on all devices, prioritizing user-facing fleets and agencies bound by BOD 22-01 deadlines. Until devices are patched, exercise caution with images from untrusted sources (email, messaging, web content), since no compensating mitigations are specified. Note that the source data does not enumerate exact affected builds, so verify coverage against Apple's advisory and CISA KEV required actions.

10.022% KEV PoC
  • Apple iOS
  • Apple iPadOS
  • Apple macOS
mass>1 billion active Apple devices (ImageIO is a core framework on all iOS/iPadOS/macOS devices; Apple's active device base exceeds 2 billion)
Full article431 words · extracted from securityaffairs.com · click to collapse

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs newsletter, including the international press.

International Press – Newsletter

Cybercrime

Justice Department Announces Seizure of Over $2.8 Million in Cryptocurrency, Cash, and other Assets     

Colt Telecom attack claimed by WarLock ransomware, data up for sale  

Serial hacker who defaced official websites is sentenced

Oregon man charged with administering “Rapper Bot” DDoS-for-hire Botnet  

Fraud-as-a-Service: The Rising Threat to Africa’s Digital Future 

SIM-Swapper, Scattered Spider Hacker Gets 10 Years 

Colt confirms customer data stolen as Warlock ransomware auctions files

Chinese National Who Deployed “Kill Switch” Code on Employer’s Network Sentenced to Four Years in Prison  

African authorities dismantle massive cybercrime and fraud networks, recover millions

Europol confirms $50,000 Qilin ransomware reward is fake

Malware

Hunt.io Exposes and Analyzes ERMAC V3.0 Banking Trojan Full Source Code Leak  

Evolution of the PipeMagic backdoor: from the RansomExx incident to CVE-2025-29824

Noodlophile Stealer Evolves: Targeted Copyright Phishing Hits Enterprises with Social Media Footprints  

GodRAT – New RAT targeting financial institutions 

Preventing Domain Resurrection Attacks  

Hacking

From Support Ticket to Zero Day  

New Exploit for Critical SAP Vulnerability CVE-2025-31324 Released in the Wild  

Hijacked Satellites and Orbiting Space Weapons: In the 21st Century, Space Is the New Battlefield

Google says its AI-based bug hunter found 20 security vulnerabilities      

“Scamlexity” We Put Agentic AI Browsers to the Test – They Clicked, They Paid, They Failed 

Brazil: 121,981 files were exposed without security on a server containing health documents  

DOM-based Extension Clickjacking: Your Password Manager Data at Risk  

Scattered Spider: A Threat Profile  

Apple Patches CVE-2025-43300 Zero-Day in iOS, iPadOS, and macOS Exploited in Targeted Attacks

Intelligence and Information Warfare

Russian state-sponsored espionage group Static Tundra compromises unpatched end-of-life network devices

Russian Government Cyber Actors Targeting Networking Devices, Critical Infrastructure     

Microsoft reportedly cuts China’s early access to bug disclosures, PoC exploit code  

MURKY PANDA: A Trusted-Relationship Threat in the Cloud  

APT36: Targets Indian BOSS Linux Systems with Weaponized AutoStart Files 

Cybersecurity

HR giant Workday discloses data breach amid Salesforce attacks 

Allianz Life data breach affects 1.1 million customers 

U.K. Government Drops Apple Encryption Backdoor Order After U.S. Civil Liberties Pushback

Flaws in Software Used by Hundreds of Cities and Towns Exposed Sensitive Data  

Orange Belgium informs its customers about a cyberattack 

Hackers who exposed North Korean government hacker explain why they did it 

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, newsletter)



you might also like

leave a comment

Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/181465/breaking-news/security-affairs-newsletter-round-538-by-pierluigi-paganini-international-edition.html