Tech and AIFeds add Windows, router vulnerabilities to actively exploited list

Feds add Windows, router vulnerabilities to actively exploited list

-


The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has just added new exploits to its actively exploited list, as first noticed by BleepingComputer.

CISA’s actions basically serve as a warning to U.S. federal agencies about vulnerabilities currently being exploited in the wild. 

One exploit being tracked, CVE-2023-20118, allows hackers to remotely “execute arbitrary commands” on certain VPN routers. These routers include Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325.

“An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface,” CISA wrote. “A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data.”

Mashable Light Speed

In order to take advantage of this exploit, an attacker would need admin credentials. However, as BleepingComputer points out, hackers could take advantage of another vulnerability, CVE-2023-20025, in order to bypass authentication. 

Another vulnerability added by CISA is CVE-2018-8639. This bug affects a broad swath of Windows operating systems including Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, and Windows 10 Servers.

According to CISA, this vulnerability “exists in Windows when the Win32k component fails to properly handle objects in memory.” A bad actor with local access to the vulnerable system can utilize the exploit to run arbitrary code in kernel mode. BleepingComputer reports that a bad actor could use this vulnerability to “alter data or create rogue accounts with full user rights to take over vulnerable Windows devices.”

Microsoft and Cisco have not yet released their own security warning regarding these two exploits.





Source link

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest news

This Artificial Wetland Is Reusing Wastewater to Revive a Lost Ecosystem

In the arid region south of Mexicali, where the pale desert dominates the landscape, the Las Arenitas wetland...

Bitcoin Reclaims $94,000, Rising 6.2% in 24 Hours

Bitcoin ( BTC) has reclaimed the $94,000 price level, rising 6.2% in the last 24 hours and 12.9%...

SUI crypto surges over 30% as meme coins gain traction

SUI crypto has gone up by...

JAN3 CEO: You’d Need $5,800 in XRP to Equal 1 BTC—But It’s Still Not Worth It

In a recent analysis, Samson Mow, CEO of Bitcoin-centric firm JAN3, scrutinized XRP’s valuation by comparing it to...

Advertisement

StrictlyVC London agenda for May 13

StrictlyVC is heading to London on May 13, uniting top investors and entrepreneurs to spark meaningful connections and...

What is Decentralized Science (DeSci)? Blockchain’s Next Big Use Case Beyond Finance and NFTs

Since the emergence of blockchain technology, we have witnessed many use cases and adoption across different traditional industries,...

Must read

This Artificial Wetland Is Reusing Wastewater to Revive a Lost Ecosystem

In the arid region south of Mexicali, where...

Bitcoin Reclaims $94,000, Rising 6.2% in 24 Hours

Bitcoin ( BTC) has reclaimed the $94,000 price...

You might also likeRELATED
Recommended to you