HomeSecurityCISA adds Microsoft and Zimbra vulnerabilities to KEV list

CISA adds Microsoft and Zimbra vulnerabilities to KEV list

CISA has added two vulnerabilities affecting Microsoft Partner Center and Synacor Zimbra Collaboration Suite (ZCS) to its list of Known Exploitable Vulnerabilities (KEV). This means that both vulnerabilities have been used by cybercriminals in attacks .

CISA KEV Microsoft and Zimbra vulnerabilities

The first vulnerability , CVE-2024-49035 (CVSS score: 8.7/10), affects Microsoft Partner Center and allows an attacker to elevate privileges on a vulnerable system. The vulnerability was patched in November 2024.

See also: TSforge exploits vulnerabilities in every version of Windows

Microsoft had already warned last year that CVE-2024-49035 had been exploited, but had not disclosed additional details.

The second vulnerability , CVE-2023-34192 (CVSS Score: 9.0/10), added to the CISA KEV list, is a cross-site scripting (XSS) flaw in Synacor ZCS that allows a remote, authorized attacker to execute code via a specially crafted script in the /h/autoSaveDraft function. It was fixed in July 2023 with version 8.8.15 Patch 40.

Federal Civilian Executive Branch (FCEB) agencies are mandated to implement the necessary updates by March 18, 2025 , to secure their networks.

See also: Parallels Desktop: Vulnerability Exploits Allow Access to Macs

The day before yesterday, CISA added two more vulnerabilities to the KEV List. These are two security issues affecting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM).

While CISA's KEV list is primarily designed to alert federal agencies, all organizations should prioritize patching this vulnerability.

The list is very useful for organizations around the world who want to learn about new threats and are interested in better vulnerability management and prioritization.

CISA adds Microsoft and Zimbra vulnerabilities to KEV list
CISA adds Microsoft and Zimbra vulnerabilities to KEV list

Overall, CISA is a great help in protecting and addressing cybersecurity threats. This organization works with various sectors, such as private businesses, governments , and local authorities, to improve the security of digital systems.

See also: Confluence Server vulnerability allows LockBit Ransomware attacks

It provides information and tools to help organizations protect their networks from cyberattacks and respond to any attacks that may occur. It also informs the public about any vulnerabilities in widely used systems and applications.

Source: thehackernews.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS