Alerts: CISA Adds Two Known Exploited Vulnerabilities to Catalog

Source URL: https://www.cisa.gov/news-events/alerts/2024/12/16/cisa-adds-two-known-exploited-vulnerabilities-catalog
Source: Alerts
Title: CISA Adds Two Known Exploited Vulnerabilities to Catalog

Feedly Summary: CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities Catalog, based on evidence of active exploitation.

CVE-2024-20767 Adobe ColdFusion Improper Access Control Vulnerability
CVE-2024-35250 Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability

These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.
Binding Operational Directive (BOD) 22-01: Reducing the Significant Risk of Known Exploited Vulnerabilities established the Known Exploited Vulnerabilities Catalog as a living list of known Common Vulnerabilities and Exposures (CVEs) that carry significant risk to the federal enterprise. BOD 22-01 requires Federal Civilian Executive Branch (FCEB) agencies to remediate identified vulnerabilities by the due date to protect FCEB networks against active threats. See the BOD 22-01 Fact Sheet for more information.
Although BOD 22-01 only applies to FCEB agencies, CISA strongly urges all organizations to reduce their exposure to cyberattacks by prioritizing timely remediation of Catalog vulnerabilities as part of their vulnerability management practice. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria.

AI Summary and Description: Yes

Summary: The text discusses the recent addition of two vulnerabilities to CISA’s Known Exploited Vulnerabilities Catalog, emphasizing the threats posed by malicious cyber actors to federal enterprises. The update ties into Binding Operational Directive 22-01, which mandates remediation of these vulnerabilities by federal agencies and encourages all organizations to prioritize vulnerability management.

Detailed Description:
The text outlines the critical role of CISA in identifying and cataloging known vulnerabilities that have been actively exploited in cyberattacks. By recognizing and addressing such vulnerabilities, organizations can better safeguard their networks against potential threats. Here are the key points discussed:

– **New Vulnerabilities Added**:
– **CVE-2024-20767**: Adobe ColdFusion Improper Access Control Vulnerability
– **CVE-2024-35250**: Microsoft Windows Kernel-Mode Driver Untrusted Pointer Dereference Vulnerability

– **Implications of Vulnerabilities**:
– These vulnerabilities are notable entry points frequently exploited by malicious actors, posing substantial risks, particularly to federal enterprises.

– **Binding Operational Directive (BOD) 22-01**:
– Establishes the Known Exploited Vulnerabilities Catalog.
– Directs Federal Civilian Executive Branch (FCEB) agencies to ensure timely remediation of identified vulnerabilities to enhance network security.
– Describes the catalog as a dynamic resource that will be updated as new vulnerabilities are identified.

– **Recommendations for Organizations**:
– While BOD 22-01 specifically targets FCEB, CISA advises all organizations to adopt a proactive stance in addressing vulnerabilities.
– Timely remediation is positioned as a crucial element of effective vulnerability management practices.

– **Continued Vigilance**:
– CISA’s commitment to ongoing updates ensures that organizations are alerted to emerging threats and can respond appropriately.

This information is particularly relevant for professionals in the fields of cybersecurity, infrastructure security, and compliance, underscoring the importance of maintaining up-to-date security practices to mitigate risks posed by known vulnerabilities.