Target Industry
Indiscriminate, opportunistic targeting.
Overview
The Cybersecurity and Infrastructure Security Agency (CISA) has added five new vulnerabilities to its Known Exploited Vulnerabilities Catalog (KEV). These vulnerabilities are actively being exploited, with one rated at a critical risk level of 9.8. Federal agencies are required to implement mitigations by 24th March 2025.
Impact
The five critical security vulnerabilities in software from Cisco, Hitachi Vantara, Microsoft, and Progress. The vulnerabilities are tracked as CVE-2018-8639 (CVSS score: 7.8), CVE-2022-43769 (CVSS score: 8.8), CVE-2022-43939 (CVSS score: 8.6), CVE-2023-20118 (CVSS score: 6.5), and CVE-2024-4885 (CVSS score: 9.8)
CVE-2018-8639 is an elevation of privilege affecting the Microsoft Windows Win32k component in Microsoft Windows 7 to Microsoft Windows 10.
CVE-2022-43769 allows authenticated threat actors to execute arbitrary code in Hitachi Vantara Pentaho BA Server (versions prior to 9.4.0.1 and 9.3.0.2, including all 8.3.x releases).
CVE-2022-43939 bypasses authentication in Hitachi Vantara Pentaho BA Server (affecting the same versions as before).
CVE-2023-20118 allows authenticated remote threat actors to execute arbitrary code in the web-based management interface of Cisco Small Business Routers. It affects these routers: RV016, RV042, RV042G, RV082, RV320, and RV325.
CVE-2024-4885 allows unauthenticated remote code execution in Progress WhatsUp Gold versions released before 2023.1.3.
Exploitation
CVE-2018-8639 is exploited by authenticated local threat actors executing arbitrary code in kernel mode, allowing them to gain elevated privileges and bypass security protocols. CVE-2022-43769 is exploited by injecting a special element into Hitachi Vantara Pentaho BA Server, allowing an authenticated threat actor to execute arbitrary code.
CVE-2022-43939 is exploited by manipulating non-canonical URLs in Hitachi Vantara Pentaho BA Server, allowing threat actors to bypass authentication. CVE-2024-4885 is a path traversal vulnerability that allows unauthenticated threat actors to execute remote code.
Containment, Mitigations & Remediations
To safeguard against potential attacks, organisations using the affected software are strongly encouraged to apply the latest patches to protect against potential threats.
Threat Landscape
This emphasises the importance of applying the recommended patches and mitigation measures to protect systems. These critical vulnerabilities highlight the challenges which users in both personal and business environments face.
Threat Groups
The specific threat group behind this has not been publicly identified at the time of writing.
Further Information













