The Cybersecurity and Infrastructure Security Agency (CISA) has added three new vulnerabilities to its Known Exploited Vulnerabilities Catalog, warning that threat actors are actively exploiting them in the wild.
The vulnerabilities affect various products and could lead to serious consequences such as remote code execution and privilege escalation.
ImageMagick, a popular open-source image processing library, contains an improper input validation vulnerability that affects multiple coders, including EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT. This flaw allows a remote attacker to execute arbitrary code by crafting an image with malicious shell metacharacters.
CISA advises organizations to apply mitigations according to the vendor’s instructions or discontinue the use of the affected product if mitigations are unavailable. The vulnerability has been added to the catalog with a due date of September 30, 2024.
Decoding Compliance: What CISOs Need to Know – Join Free Webinar
The Linux kernel is affected by a position-independent executable (PIE) stack buffer corruption vulnerability in the load_elf_binary() function. This vulnerability allows a local attacker to escalate privileges and has been known to be used in ransomware campaigns.
To mitigate the risk, CISA recommends applying vendor-provided mitigations or discontinuing the use of the affected product if mitigations are not available. The vulnerability has been added to the catalog with a due date of September 30, 2024.
SonicWall SonicOS, a popular firewall solution, contains an improper access control vulnerability that could lead to unauthorized resource access. In certain conditions, this vulnerability may also cause the firewall to crash, disrupting network security.
This issue affects SonicWall Firewall Gen 5 and Gen 6 devices, as well as Gen 7 devices running SonicOS 7.0.1-5035 and older versions. SonicWall recommends updating to the latest version.
CISA urges organizations to follow the vendor’s instructions to apply mitigations or discontinue the use of the affected product if mitigations are not available. The vulnerability has been added to the catalog, but it is unknown if it has been used in ransomware campaigns[3].
To protect against these actively exploited vulnerabilities, organizations should:
As these vulnerabilities affect common open-source components, third-party libraries, and protocols used by various products, organizations should remain vigilant and stay informed about any updates or advisories from the respective vendors.
By promptly addressing these actively exploited vulnerabilities and implementing strong security practices, organizations can reduce their risk of falling victim to cyber attacks and minimize the potential impact of a breach.
Download Free Incident Response Plan Template for Your Security Team – Free Download
Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…
Hackers are making some phishing pages harder to track by changing the code delivered to…
A cyber incident reportedly forced a British power plant to halt operations for about four…
Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…
TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…
A fake student resume is being used to place a remote-access tool on researchers’ Windows…