HomeSecurityCISA: 7 New Security Flaws Vulnerable to Attacks

CISA: 7 New Security Flaws That Are Vulnerable to Attacks

The US Cybersecurity and Infrastructure Security Agency (CISA) has added seven vulnerabilities (security flaws) to its list of actively exploited security issues, including those from Microsoft, Linux, and Jenkins.

The "List of Known Exploitable Vulnerabilities" is a list of vulnerabilities that are known to be actively used in cyberattacks and are required to be patched by the Federal Civilian Executive Branch (FCEB) agencies.

See also: CISA: Fix the Sophos firewall bug

“Binding Operational Directive (BOD) 22-01: Mitigating the Risk of Known Exploitable Vulnerabilities established the List of Known Exploitable Vulnerabilities as a list of known CVEs that pose a significant risk to federal business,” CISA explains.

“BOD 22-01 requires FCEB services to remediate identified vulnerabilities by the due date to protect FCEB networks from active threats. For more information, please refer to the BOD 22-01 fact sheet.”

CISA: 7 new additions to the list of vulnerabilities vulnerable to attacks
CISA: 7 new additions to the list of vulnerabilities vulnerable to attacks

CISA informs that the vulnerabilities listed in the list allow hackers to carry out a variety of attacks, such as stealing credentials, accessing networks, remotely executing commands, downloading and executing malware, or stealing information from devices.

See also: CISA in organizations: Fix the WatchGuard bug

With the addition of these seven vulnerabilities, the list now contains 654 vulnerabilities, including the date by which federal agencies must apply the relevant patches and security updates.

The seven new vulnerabilities added this week are listed below, with CISA requiring all of them to be patched by May 16, 2022.

CVE numberVulnerability titleCorrection deadline
CVE-2022-29464WSO2 Multi-Product Vulnerability Unlimited File Upload2022-05-16
CVE-2022-26904Microsoft Windows Profile Service Privilege Escalation Vulnerability2022-05-16
CVE-2022-21919Microsoft Windows Profile Service Privilege Escalation Vulnerability2022-05-16
CVE-2022-0847Linux kernel privilege escalation vulnerability2022-05-16
CVE-2021-41357Microsoft Win32k Elevation of Privilege Vulnerability2022-05-16
CVE-2021-40450Microsoft Win32k Elevation of Privilege Vulnerability2022-05-16
CVE-2019-1003029Jenkins Security Script Sandbox Addition Bypass Vulnerability2022-05-16

While it is useful to know that a bug is being exploited, it is even more useful to understand how they are actively used in attacks.

The WSO2 vulnerability tracked as CVE-2022-29464 by CISA was disclosed on April 18, 2022, and a few days later, a public exploit was released. Rapid7 researchers soon saw the PoC being used in attacks to deploy web shells and coinminers.

CISA: 7 new additions to the list of vulnerabilities vulnerable to attacks
CISA: 7 new additions to the list of vulnerabilities vulnerable to attacks

The Windows 'User Profile Service Privilege Escalation' security flaws tracked as CVE-2022-21919 and CVE-2022-26904 were both discovered by Abdelhamid Naceri and are follow-on exploits of an initial vulnerability CVE-2021-34484 that was patched in August. The vulnerabilities have been publicly disclosed and ransomware are using them to spread laterally through a Windows domain.

The Linux privilege escalation vulnerability known as “DirtyPipe” is tracked as CVE-2022-0847 by CISA and was disclosed in March 2022. Immediately after its disclosure, numerous proof-of-concept exploits were released, allowing users to quickly gain root privileges.

The vulnerabilities CVE-2021-40450 and CVE-2021-41357 named "Microsoft Win32k Privilege Escalation Vulnerability" were patched in October 2021 and are an interesting addition to the CISA list, as there is no public report of their exploitation on regular data.

Finally, the oldest vulnerability is the “Jenkins Security Script Sandbox Addition Bypass Vulnerability” bug tracked as CVE-2019-1003029, which has been previously used by the Capoae malware to deploy XMRig cryptominers.

It is highly recommended that all security professionals and administrators review the List of Known Exploitable Vulnerabilities and patch any security vulnerabilities in their environment.

Source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS