Target Industry

Indiscriminate, opportunistic targeting.

Overview

The Cybersecurity and Infrastructure Security Agency (CISA) has added five new vulnerabilities to its Known Exploited Vulnerabilities Catalog (KEV). These vulnerabilities are actively being exploited, with one rated at a critical risk level of 9.8. Federal agencies are required to implement mitigations by 24th March 2025.

Impact

The five critical security vulnerabilities in software from Cisco, Hitachi Vantara, Microsoft, and Progress. The vulnerabilities are tracked as CVE-2018-8639 (CVSS score: 7.8), CVE-2022-43769 (CVSS score: 8.8), CVE-2022-43939 (CVSS score: 8.6), CVE-2023-20118 (CVSS score: 6.5), and CVE-2024-4885 (CVSS score: 9.8) 

CVE-2018-8639 is an elevation of privilege affecting the Microsoft Windows Win32k component in Microsoft Windows 7 to Microsoft Windows 10.  

CVE-2022-43769 allows authenticated threat actors to execute arbitrary code in Hitachi Vantara Pentaho BA Server (versions prior to 9.4.0.1 and 9.3.0.2, including all 8.3.x releases).  

CVE-2022-43939 bypasses authentication in Hitachi Vantara Pentaho BA Server (affecting the same versions as before).  

CVE-2023-20118 allows authenticated remote threat actors to execute arbitrary code in the web-based management interface of Cisco Small Business Routers. It affects these routers: RV016, RV042, RV042G, RV082, RV320, and RV325. 

CVE-2024-4885 allows unauthenticated remote code execution in Progress WhatsUp Gold versions released before 2023.1.3. 

Exploitation

CVE-2018-8639 is exploited by authenticated local threat actors executing arbitrary code in kernel mode, allowing them to gain elevated privileges and bypass security protocols. CVE-2022-43769 is exploited by injecting a special element into Hitachi Vantara Pentaho BA Server, allowing an authenticated threat actor to execute arbitrary code. 

CVE-2022-43939 is exploited by manipulating non-canonical URLs in Hitachi Vantara Pentaho BA Server, allowing threat actors to bypass authentication. CVE-2024-4885 is a path traversal vulnerability that allows unauthenticated threat actors to execute remote code. 

Containment, Mitigations & Remediations

To safeguard against potential attacks, organisations using the affected software are strongly encouraged to apply the latest patches to protect against potential threats.  

Threat Landscape

This emphasises the importance of applying the recommended patches and mitigation measures to protect systems. These critical vulnerabilities highlight the challenges which users in both personal and business environments face.  

Threat Groups

The specific threat group behind this has not been publicly identified at the time of writing. 

Further Information

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content