ZeroHour
Security Affairspublished ()ingested @securityaffairs

CISA adds 41 flaws to its Known Exploited Vulnerabilities Catalog

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2016-0162
Information Disclosure via JavaScript File Detection in Microsoft Internet Explorer

CVE-2016-0162 is an information disclosure flaw (CWE-200) in Microsoft Internet Explorer caused by improper handling of JavaScript, which can allow an attacker to detect the presence of specific files on a user's computer. It is triggered when Internet Explorer processes attacker-controlled JavaScript, typically when a user views a crafted webpage or embedded web content. What the attacker gains is reconnaissance value rather than code execution: confirmation that named files exist on the victim's machine, which can be used to tailor more targeted follow-on attacks. Any user running the affected Internet Explorer versions is potentially exposed, although the source data does not enumerate specific version ranges beyond 'Microsoft Internet Explorer.' The flaw was added to CISA's Known Exploited Vulnerability (KEV) catalog on 2022-05-24, confirming exploitation in the wild; EPSS estimates a 22.1% probability of exploitation within 30 days (98th percentile), and no public proof-of-concept is known.

Do: Apply Microsoft security updates for Internet Explorer per vendor instructions, prioritizing user workstations and any internet-facing systems where IE is in use, and treat this as a patch-now item given the KEV listing. Verify that IE builds are current against Microsoft's cumulative IE security updates, since the source data does not list specific fixed versions. Where feasible, reduce attack surface by steering users to supported modern browsers or restricting legacy IE to trusted sites; CISA lists ransomware association as unknown, so confirm whether your threat intel ties this CVE to known campaigns.

4.322% KEV
  • Microsoft Internet Explorer
masshundreds of millions of users (IE historically shipped by default on Windows; exact counts of unpatched installs unknown)
CVE-2016-3298
Information Disclosure in Microsoft Internet Explorer Messaging API

CVE-2016-3298 is an information disclosure flaw (CWE-200) in the Microsoft Internet Messaging API used by Internet Explorer, in which the API improperly handles objects in memory. Exploitation requires driving Internet Explorer to process attacker-influenced content so the Messaging API mishandles memory, after which the attacker can probe whether specific files exist on the victim's disk. An attacker gains only limited reconnaissance value — confirming file presence for fingerprinting — rather than code execution or direct data theft. Only systems running Microsoft Internet Explorer, as cataloged by CISA, are affected; CISA added the bug to the Known Exploited Vulnerabilities catalog on 2022-05-24, confirming exploitation in the wild, though any ransomware association is unknown. EPSS estimates a 32.8% probability of exploitation within 30 days (98th percentile), no public proof-of-concept is known, and a CVSS score has not yet been published in this dataset.

Do: Apply Microsoft's security update for CVE-2016-3298 per vendor instructions, as mandated by the CISA KEV catalog (added 2022-05-24, so remediation deadlines apply to federal agencies and many regulated environments). Audit any Windows hosts where Internet Explorer is still used for interactive browsing and confirm the patch is installed; because the flaw only permits probing for file existence, residual risk after patching is low.

6.533% KEV
  • Microsoft Internet Explorer
masshundreds of millions of Windows devices (Internet Explorer shipped as a built-in Windows component for decades)
CVE-2016-3351
Information Disclosure in Microsoft Internet Explorer and Edge

CVE-2016-3351 is an information disclosure flaw in the way Internet Explorer and Microsoft Edge handle objects in memory. An attacker can trigger it by getting the browser to process attacker-controlled content, such as a malicious or compromised web page, and thereby determine the presence of specific files on the user's computer. This file-detection capability is useful for profiling a victim machine and is commonly used as a reconnaissance step in broader attack chains. All users of Internet Explorer and Microsoft Edge on affected Microsoft products are impacted; the flaw carries CWE-200 (information exposure) and no CVSS score is available. It was added to the CISA Known Exploited Vulnerabilities catalog on 2022-05-24 with known ransomware use, and EPSS assigns it a 26.3% probability of exploitation within 30 days (98th percentile).

Do: Apply Microsoft security updates per vendor instructions, as required by the CISA KEV catalog entry, prioritizing internet-facing and user workstations given known ransomware use. Because legacy Internet Explorer is end-of-life, retire or restrict IE usage where possible and confirm that both IE and Edge builds on Windows hosts are fully patched. Hunt for exploitation activity involving browser-based file-detection probes on endpoints in your environment.

6.526% KEV ransomware PoC
  • Microsoft Internet Explorer
  • Microsoft Edge
masshundreds of millions of Windows devices (both browsers shipped with Windows)
CVE-2016-4657
+2 in the same advisory: …4656 …4655
Memory Corruption RCE in Apple iOS WebKit (CVE-2016-4657)

WebKit, the browser engine used by Safari and other apps on Apple iOS, contains a memory corruption flaw (CWE-787, out-of-bounds write) affecting all iOS versions before 9.3.5. The flaw is triggered when a user visits a crafted website, causing corruption within the WebKit process. A successful attacker can execute arbitrary code in the context of the browser or cause a denial of service, a typical first stage in a full device compromise. All iPhone, iPad, and iPod touch users running iOS earlier than 9.3.5 are affected. The vulnerability has been exploited in the wild (CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-05-24, with public PoC/exploit references available) and EPSS estimates a 66.8% probability of exploitation within 30 days.

Do: Update all iPhones, iPads, and iPod touches to iOS 9.3.5 or later, and verify fleet versions via Settings > General > About. Devices with hardware that cannot run iOS 9.3.5+ remain permanently exposed, so consider isolating or retiring them. Until patched, reduce risk by avoiding untrusted websites in Safari and other WebKit-based apps.

8.8
group max
67% KEV PoC ×2
  • Apple iPhone OS (iOS) - WebKit component, used by Safari and WebKit-based apps All iOS versions before 9.3.5
masshundreds of millions of iOS devices were on affected builds at disclosure; the number still running iOS < 9.3.5 today is unknown but plausibly in the hundreds…
CVE-2016-6366
+1 in the same advisory: …6367
SNMP Buffer Overflow RCE (EXTRABACON) in Cisco ASA, PIX, and FWSM Firewalls

CVE-2016-6366, known as EXTRABACON (Cisco Bug ID CSCva92151), is a classic buffer overflow (CWE-120) in the SNMP processing of Cisco Adaptive Security Appliance (ASA) Software through 9.4.2.3, which runs on ASA 5500, ASA 5500-X, ASA Services Module, ASA 1000V, ASAv, Firepower 9300 ASA Security Module, PIX, and FWSM devices. A remote, authenticated attacker who knows the device's SNMP credentials (community string or SNMP user) can send crafted IPv4 SNMP packets that trigger the overflow and execute arbitrary code on the firewall, yielding full device control (CVSS 3.1: 8.8, high impact to confidentiality, integrity, and availability). Because these firewalls typically sit at the network perimeter, compromise gives attackers a chokepoint for traffic interception and further lateral movement, so any organization running affected ASA/PIX/FWSM software with SNMP enabled and reachable is at risk. A public exploit was released in 2016 in connection with the Shadow Brokers disclosures of Equation Group tooling, and CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-05-24, confirming exploitation in the wild. The high EPSS score of 87.6% (100th percentile) combined with the KEV listing indicates elevated near-term exploitation risk, making patching urgent.

Do: Upgrade Cisco ASA Software to a fixed release for Bug ID CSCva92151 per Cisco's security advisory (all versions through 9.4.2.3 are affected), and apply the corresponding vendor fixes for ASA 1000V, PIX, and FWSM as required by the CISA KEV listing. As interim mitigation, restrict SNMP access to trusted management hosts via ACLs, disable SNMP where unused, prefer SNMPv3 with strong credentials over v1/v2c community strings, and review devices for indicators of compromise such as unexplained configuration changes or added user accounts.

8.8
group max
88% KEV PoC ×3
  • Cisco Adaptive Security Appliance (ASA) Software all versions through 9.4.2.3 (at time of disclosure; runs on ASA 5500, ASA 5500-X, ASA Services Module, ASAv, and Firepower 9300 ASA Security Module)
  • Cisco ASA 1000V Cloud Firewall Software affected per Cisco/CISA; no specific version range provided in source data
  • Cisco PIX Firewall Software affected per Cisco/CISA; no specific version range provided in source data
  • +1 more
mass≈1M+ deployed ASA/PIX/FWSM devices (multi-million-unit ASA installed base; historically tens of thousands of ASA management interfaces exposed on the public…
CVE-2021-1048
+1 in the same advisory: …0920
Use-After-Free Privilege Escalation in Android Kernel (CVE-2021-1048)

CVE-2021-1048 is a use-after-free (CWE-416) in ep_loop_check_proc of eventpoll.c — the Android kernel's epoll event-notification code — that can corrupt kernel memory. A local attacker (e.g., a malicious app with no special permissions) can trigger the flaw, and no user interaction is required, yielding local escalation of privilege to kernel level. Any Android device running an unpatched Android kernel is affected. The flaw is being actively exploited: it is in CISA's Known Exploited Vulnerabilities Catalog (added 2022-05-23) and reporting indicates Google fixed it as a zero-day used in targeted attacks, with coverage tying Android kernel zero-days to Cytrox/Intellexa Predator spyware campaigns. EPSS currently puts the 30-day exploitation probability at ~1.0%, but the KEV listing and in-the-wild targeting make patching urgent.

Do: Apply updates per vendor instructions (CISA KEV required action): install the latest Android security/kernel updates from Google or your device OEM — Google's advisories indicate the complete fix shipped in the February 2022 Android security bulletin (2022-02-05 patch level), following the initial January 2022 fix. Fleet administrators should verify devices' security patch levels and prioritize high-value/targeted users, since observed exploitation has been targeted (spyware-linked) rather than mass-scale. No public PoC is known and ransomware use is unknown, but defenders should hunt for signs of local privilege escalation on unpatched fleets.

7.8
group max
1% KEV
  • Google Android (kernel)
mass≈3 billion Android devices worldwide (Android's global active-device installed base; unpatched share unknown)
CVE-2022-20821
Unauthenticated Redis Access via Open TCP 6379 in Cisco IOS XR Health Check RPM

A vulnerability in the health check RPM of Cisco IOS XR Software causes TCP port 6379 to be opened by default when the RPM is activated, exposing the Redis instance running inside the NOSi container to unauthenticated, remote access. An attacker who can reach the exposed port simply connects to the Redis service; no credentials, authentication, or user interaction are required. A successful exploit allows the attacker to write to the Redis in-memory database, write arbitrary files to the container's filesystem, and retrieve information about the Redis database; because the container is sandboxed, the flaw does not permit remote code execution or compromise of the host IOS XR system. Any organization running Cisco IOS XR with the health check RPM activated and TCP 6379 remotely reachable is affected, which in practice means service-provider and large-enterprise router deployments. The flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2022-05-23 and was reported as actively exploited in the wild, although no public proof-of-concept code is known.

Do: Apply updated IOS XR releases per Cisco's security advisory, prioritizing internet-facing routers since the flaw is listed as actively exploited in CISA's KEV. Until patching, restrict or ACL access to TCP port 6379 on IOS XR devices (including via control-plane filtering) and check whether the health check RPM is activated on each device. Monitor for unexpected connections to port 6379 and review the Redis database and container filesystem for signs of unauthorized writes.

6.512% KEV
  • Cisco IOS XR Software (devices with the health check RPM activated)
largeplausibly on the order of tens of thousands of IOS XR-based carrier routers, with the directly exposed subset (RPM active and TCP 6379 reachable) likely smaller
Full article350 words · extracted from securityaffairs.com · click to collapse

US Critical Infrastructure Security Agency (CISA) adds 41 new vulnerabilities to its Known Exploited Vulnerabilities Catalog.

The Cybersecurity & Infrastructure Security Agency (CISA) has added 41 flaws to its Known Exploited Vulnerabilities Catalog, including recently addressed issues in the Android kernel (CVE-2021-1048 and CVE-2021-0920) and Cisco IOS XR (CVE-2022-20821).

The Cisco IOS XR flaw (CVE-2022-20821, CVSS score: 6.5, is actively exploited in attacks in the wild, it resides in the health check RPM of Cisco IOS XR Software. An unauthenticated, remote attacker could trigger the issue to access the Redis instance that is running within the NOSi container.

According to Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities, FCEB agencies have to address the identified vulnerabilities by the due date to protect their networks against attacks exploiting the flaws in the catalog.

Experts recommend also private organizations review the Catalog and address the vulnerabilities in their infrastructure.

Some of the flaws added to the catalog in this turn are dated back to 2016, such as the issues affecting Apple (CVE-2016-4655, CVE-2016-4656, CVE-2016-4657), Microsoft (CVE-2016-0162, CVE-2016-3351, CVE-2016-3298) and Cisco Devices (CVE-2016-6366, CVE-2016-6367).

Other issues impact Google, Mozilla, Facebook, Adobe, and Webkit GTK software products, the vulnerabilities range from 2018 to 2021.

Some of the issues have to be addressed by federal agencies by June 13, 2022, while the others need to be fixed by June 14, 2022.

Security Affairs is one of the finalists for the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS. I ask you to vote for me again (even if you have already done it), because this vote is for the final.

Please vote for Security Affairs and Pierluigi Paganini in every category that includes them (e.g. sections “The Underdogs – Best Personal (non-commercial) Security Blog” and “The Tech Whizz – Best Technical Blog”)

To nominate, please visit: 

https://docs.google.com/forms/d/e/1FAIpQLSdNDzjvToMSq36YkIHQWwhma90SR0E9rLndflZ3Cu_gVI2Axw/viewform

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, Known Exploited Vulnerabilities Catalog)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/131646/security/known-exploited-vulnerabilities-catalog-flaws-2.html