By Interestana AI Editorial — AI-drafted, human-overseen. How we report
CISA Adds Four Critical Exploited Vulnerabilities to KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) announced on Tuesday, October 24, 2023, the addition of four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities are confirmed to be actively exploited in the wild, posing an immediate threat to U.S. federal agencies and other organizations. The inclusion in the KEV catalog mandates that federal civilian executive branch agencies must patch these vulnerabilities by November 14, 2023, to mitigate potential security risks. The four newly cataloged vulnerabilities include an improper authentication flaw in Apple's macOS, a remote code execution vulnerability in Microsoft SharePoint Server, a privilege escalation issue in VMware's vCenter Server, and a denial-of-service vulnerability affecting Microsoft's Internet Key Exchange (IKE) protocol.
The first vulnerability, identified as CVE-2023-38606 with a CVSS score of 9.8, impacts Apple macOS and is described as an improper authentication vulnerability. Successful exploitation could allow an attacker to bypass authentication mechanisms, potentially gaining unauthorized access to sensitive system resources or functions. This high severity score indicates a significant risk if left unaddressed. Apple is known for its robust security features, and vulnerabilities like this, especially when actively exploited, highlight the persistent challenges in maintaining secure operating systems against sophisticated threats.
Secondly, CVE-2023-29357, a critical remote code execution (RCE) vulnerability in Microsoft SharePoint Server, has been added to the KEV catalog. This flaw carries a CVSS score of 9.8 and allows an unauthenticated attacker to execute arbitrary code on the affected SharePoint server. Given SharePoint's widespread use in enterprise environments for collaboration and document management, this vulnerability presents a substantial risk for data breaches and system compromise. Microsoft has previously released security updates to address such issues, emphasizing the importance of timely patching.
The third vulnerability, CVE-2023-29358, affects VMware's vCenter Server, a centralized management platform for VMware vSphere environments. This flaw is categorized as a privilege escalation vulnerability with a CVSS score of 8.8. Exploiting this vulnerability could allow a low-privileged attacker to gain administrative privileges on the vCenter Server, granting them extensive control over the virtualized infrastructure. VMware's products are critical components of many organizations' IT operations, making this a high-priority target for attackers seeking to disrupt or infiltrate enterprise networks.
Finally, CVE-2023-24541, a denial-of-service (DoS) vulnerability in Microsoft's Internet Key Exchange (IKE) protocol, has also been added. While carrying a lower CVSS score of 7.5 compared to the others, DoS attacks can still be highly disruptive, rendering services unavailable to legitimate users. The IKE protocol is fundamental to establishing secure connections, particularly for VPNs, and a vulnerability here could impact network security and availability. CISA's directive for agencies to patch these vulnerabilities underscores the critical nature of these flaws and the ongoing efforts to secure national cyber infrastructure against active threats.
Original source — read the full reporting at the publisher:
Read on The Hacker NewsGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.