HomeSecurityCISA to organizations: Fix 95 actively exploited vulnerabilities

CISA to organizations: Fix 95 actively exploited vulnerabilities

The US Cybersecurity and Infrastructure Security Agency (CISA) has added 95 vulnerabilities to its list of actively exploited security issues – a truly large number.

CISA 95 vulnerabilities

See also: CISA: List of free cybersecurity tools and services released

Despite the fact that some of them have been known for almost two decades, the agency notes that the bugs "pose significant risk to organizations.".

Critical bugs recently added to the list

Under BOD 22-01 on mitigating the risk of known exploitable vulnerabilities, federal agencies are given just over three weeks to patch the 95 vulnerabilities recently added to the CISA list, with the deadline for most of them being March 24th.

See also: CISA: Federal agencies must fix Chrome and Magento bugs

For 27 of the vulnerabilities, there is a shorter deadline for patching, March 17, largely because they are more recent and affect systems that provide access to sensitive information or allow movement to devices on the network. Eight of these bugs have a high critical severity rating (at least 9.8).

CISA 95 vulnerabilities

The most recent entries in CISA's list of known exploitable vulnerabilities affect products primarily from Microsoft (Windows, Office) and Cisco.

However, there are products from other vendors or projects – Oracle, Adobe, Mozilla, Siemens, Apache, Exim, Linux, Treck TCP/IP stack and ChakraCore.

Ancient flaws still exist

Surprisingly, it appears that federal agencies are still running systems with Adobe Flash Player, even though support for the product ended on the last day of 2020.

Adobe in early 2021 also blocked Flash content from running in Flash Player, and the company “recommends all users to uninstall it immediately” due to inherent security risks.

Some of the Flash Player bugs identified by CISA have a critical severity rating of 9.8 out of 10 and are over five years old (e.g. CVE-2016-4117 and CVE-2016-1019).

The oldest vulnerability on the list is from 2002, however, a privilege escalation vulnerability tracked as CVE-2002-0367 that affects the smss.exe debugging subsystem in Windows NT and Windows 2000.

See also: CISA and FBI: Data wiping attacks will also appear outside Ukraine

The following list lists the oldest 10 vulnerabilities that CISA added to the List of Known Exploitable Vulnerabilities:

Applying security updates when they become available should be a priority for both public and private sector organizations.

The US cybersecurity agency encourages all entities to fix all security issues added to its list to reduce their exposure to cyberattacks.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS