Intel Addresses 80 Firmware, Software Vulnerabilities

Intel on Tuesday released a total of 46 new security advisories to inform customers about 80 vulnerabilities affecting the company’s firmware and software.

The most serious of the flaws, based on their CVSS score, are 18 high-severity issues allowing privilege escalation or, in a few cases, denial-of-service (DoS) attacks. 

The vulnerabilities impact processor BIOS, chipset firmware, NUC BIOS, Unison, Manageability Commander, NUC Kit and Mini PC BIOS, Driver and Support Assistant (DSA), AI Hackathon, PROSet/Wireless Wi-Fi and Killer WiFi, NUC Pro Software Suite, Easy Streaming Wizard, Virtual RAID on CPU (VROC), SGX and TDX for some Xeon Processors, and Unite products.

Medium-severity vulnerabilities have been addressed in processors, RealSense SDKs and ID software, ITS, Unite Android app, NUC BIOS firmware, PSR SDK, SDP tool, Server Board BMC video drivers, Unison, oneAPI, Hyperscan Library, DTT, Support Android app, Agilex (Quartus Prime Pro Edition for Linux), ISPC, and Advanced Link Analyzer Standard Edition.

Bugs with a ‘medium severity’ rating have also been resolved in VCUST Tool, Distribution of OpenVINO Toolkit, Optimization for TensorFlow, Ethernet controllers and adapters, System Firmware Update Utility for Server Boards and Server System, NUC ITE Tech, Arc graphics cards, SSD Tools, PCSD, Ethernet Controller RDMA driver for Linux, and RST products. 

These mostly allow a local attacker to escalate privileges, and some can lead to information disclosure or DoS attacks. 

A vast majority of the flaws disclosed on Tuesday have received patches, but some of the impacted products have been discontinued. 

Advertisement. Scroll to continue reading.

Intel has also published an advisory for the Downfall vulnerability disclosed on Tuesday by Google researchers. 

Related: Intel, AMD Address Many Vulnerabilities With Patch Tuesday Advisories

Related: Intel Paid Out Over $4.1 Million via Bug Bounty Program Since 2017

Related: Chipmaker Patch Tuesday: Intel, AMD Address Over 100 Vulnerabilities

https://www.securityweek.com/intel-addresses-80-firmware-software-vulnerabilities/




SAP Patches Critical Vulnerability in PowerDesigner Product

German software giant SAP has fixed more than a dozen new vulnerabilities with its August 2023 Patch Tuesday updates, including a critical flaw affecting the company’s PowerDesigner data modeling and enterprise architecture product.

SAP released 16 new patches and updated several previously released fixes.

The critical (HotNews) PowerDesigner flaw, tracked as CVE-2023-37483, is an improper access control issue that can be exploited by an unauthenticated attacker to run arbitrary queries against the backend database, according to business application security firm Onapsis

Onapsis noted that the same update also fixes a medium-severity password disclosure issue in SAP PowerDesigner. 

SAP has also informed customers about a patch for CVE-2023-36923, a high-severity code injection vulnerability in PowerDesigner. 

“The patched Code Injection vulnerability is tagged with a CVSS score of 7.8 and allows an attacker with local access to the system to place a malicious library that can be executed by the application,” Onapsis explained. “After a successful exploit, attackers can control the behavior of the application. This only affects customers who are using a bundle of SAP SQL Analyzer for PowerDesigner 17 and SAP PowerDesigner 16.7 SP06 PL03.”

SAP has also highlighted CVE-2023-37490, a binary hijack flaw in the BusinessObjects Business Intelligence Suite that “allows attackers to compromise system integrity and confidentiality”, as well as CVE-2023-39437, an XSS vulnerability in SAP Business One.

Advertisement. Scroll to continue reading.

Security holes have also been addressed in S/4HANA, NetWeaver AS ABAP, Message Server, Host Agent, Netweaver Process Integration, Commerce and Commerce Cloud, SAP Supplier Relationship Management, and ECC.

SAP product vulnerabilities have been known to be exploited by threat actors, which is why it’s important that organizations review the latest patches and take action as necessary. 

CISA’s Known Exploited Vulnerabilities Catalog currently includes four SAP flaws that have been exploited in the wild. 

Related: Details Disclosed for Critical SAP Vulnerabilities, Including Wormable Exploit Chain

Related: SAP Patches Critical Vulnerability in ECC and S/4HANA Products

Related: Threat Actors Quick to Target (Patched) SAP Vulnerabilities

https://www.securityweek.com/sap-patches-critical-vulnerability-in-powerdesigner-product/




New ‘Inception’ Side-Channel Attack Targets AMD Processors

Researchers on Tuesday disclosed the details of a new CPU side-channel attack named Inception that impacts AMD processors.

The Inception attack method was discovered by a team of researchers from the ETH Zurich university in Switzerland. It allows a local attacker to leak potentially sensitive data, such as passwords or encryption keys, from anywhere in the memory of a computer powered by an AMD Zen processor.

Inception is a transient execution attack that leverages a method named Training in Transient Execution (TTE) and an attack dubbed Phantom Speculation (CVE-2022-23825).

“As in the movie of the same name, Inception plants an ‘idea’ in the CPU while it is in a sense ‘dreaming’, to make it take wrong actions based on supposedly self conceived experiences. Using this approach, Inception hijacks the transient control-flow of return instructions on all AMD Zen CPUs,” the researchers explained.

They have published separate papers detailing the Inception and Phantom attacks. For Inception, they have also made available proof-of-concept (PoC) source code and a video showing the exploit in action.

[embedded content]

AMD has published an advisory confirming that an Inception attack can lead to information disclosure. 

Advertisement. Scroll to continue reading.

The chipmaker provides microcode patches and other mitigations. It has also advised customers to employ security best practices. 

“This attack is similar to previous branch prediction-based attacks like Spectrev2 and Branch Type Confusion (BTC)/RetBleed,” AMD explained. “As with similar attacks, speculation is constrained within the current address space and to exploit, an attacker must have knowledge of the address space and control of sufficient registers at the time of RET (return from procedure) speculation.” 

The company believes the vulnerability could only be exploited locally — by a piece of malware, for example — and noted that it’s not aware of any malicious exploitation. 

Inception is not the only AMD Zen vulnerability disclosed in recent weeks. Google researchers have found Zenbleed, an AMD Zen 2 processor vulnerability that can allow an attacker to access sensitive information. 

Google’s researchers have also discovered an Intel processor attack method Downfall, whose details they disclosed on Tuesday, when Intel also published an advisory. 

Related: Wiz Says 62% of AWS Environments Exposed to Zenbleed Exploitation

Related: AMD Processors Expose Sensitive Data to New ‘SQUIP’ Attack

https://www.securityweek.com/new-inception-side-channel-attack-targets-amd-processors/




Patch Tuesday: Microsoft (Finally) Patches Exploited Office Zero-Days

A month after confirming active exploitation of “a series of remote code execution vulnerabilities” impacting Windows and Office users, Microsoft on Tuesday shipped patches for 33 affected products and a “defense in depth update” to block the attack chain.

Redmond’s beleaguered security response team said the pre-patch mitigation stops the attack chain leading to the Windows Search security feature bypass vulnerability (CVE-2023-36884) being abused by Russian spies and cybercriminals.

“This defense in depth update is not a vulnerability, but installing this update stops the attack chain,” Microsoft said, urging Windows users to install the newly available Office updates as well as installing the Windows updates from August 2023.

The company also updated the CVE-2023-36884 bulletin with additional documentation on the security bug and provided security fixes for affected Office installations. 

In an unusual move last month, Microsoft warned that skilled attackers are using specially crafted Office documents to launch targeted code execution attacks. “An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim.”

Those attacks included a phishing campaign with Office zero-day exploits targeting defense and government entities in Europe and North America 

The Office patches and mitigations headline a busy Patch Tuesday that provides fixes for approximately 75 security defects in the Microsoft Windows ecosystem. 

Advertisement. Scroll to continue reading.

According to Zero Day Initiative, a company that tracks security updates, this month’s patches cover vulnerabilities in Edge (Chromium-Based); Exchange Server; Office and Office Components; .NET and Visual Studio; ASP.NET; Azure DevOps and HDInsights; Teams; and Windows Defender. 

Microsoft rates the bulk of the issues as critical-severity, meaning that exploitation could lead to arbitrary code execution. 

Software maker Adobe also joined the Patch Tuesday train with a big batch of security updates for its flagship Acrobat and Reader software, patching at least 30 vulnerabilities affecting Windows and macOS installations.

The software maker documented the 30 security defects in a critical-level advisory and warned that successful exploitation could lead to arbitrary code execution, memory leaks, security feature bypass and application denial-of-service attacks.

Adobe said affected software includes Acrobat DC, Acrobat Reader DC, Acrobat 2020 and Acrobat Reader 2020.  The company described most of the bugs as memory safety issues and said it was not aware of any exploits in the wild.

Related: Microsoft Warns of Office Zero-Day Attacks, No Patch Yet

Related: Microsoft Pins Outlook Zero-Day Attacks on Russian Actor

Related: Microsoft Office Zero-Day Hit in Targeted Attacks

Related: Patch Tuesday: Adobe Patches 30 Acrobat, Reader Vulns

https://www.securityweek.com/patch-tuesday-microsoft-finally-patches-exploited-office-zero-days/




Patch Tuesday: Adobe Patches 30 Acrobat, Reader Vulns

Adobe on Tuesday rolled out a big batch of security updates for its flagship Acrobat and Reader software, patching at least 30 vulnerabilities affecting Windows and macOS installations.

The software maker documented the 30 security defects in a critical-level advisory and warned that successful exploitation could lead to arbitrary code execution, memory leaks, security feature bypass and application denial-of-service attacks.

Adobe said affected software include Acrobat DC, Acrobat Reader DC, Acrobat 2020 and Acrobat Reader 2020.  The company described most of the bugs as memory safety issues and said it was  not aware of any exploits in the wild.

The Acrobat and Reader fixes headline a busy Patch Tuesday at Adobe. The company separately shipped an urgent update covering a trio of security vulnerabilities  in the Adobe Commerce and Magento Open Source.

“Successful exploitation could lead to arbitrary code execution, privilege escalation and arbitrary file system read,” Adobe cautioned.

The Adobe PSIRT team also updated the Adobe Dimension software to cover three flaws that expose Windows and macOS users to  arbitrary code execution and memory leaks.

Related: Adobe Releases New Patches for Exploited ColdFusion Vulnerabilities

Advertisement. Scroll to continue reading.

Related: Two New Adobe ColdFusion Vulnerabilities Exploited in Attacks

Related: Adobe Patch Tuesday: Critical Flaws Haunt InDesign, ColdFusion

Related: Adobe Warns of ‘Very Limited Attacks’ Exploiting ColdFusion Zero-Day

https://www.securityweek.com/patch-tuesday-adobe-patches-30-acrobat-reader-vulns/




New PaperCut Vulnerability Allows Remote Code Execution

Organizations have been warned about a new potentially serious vulnerability affecting the PaperCut NG/MF print management software.

The flaw, tracked as CVE-2023-39143 and rated ‘high severity’, can be exploited by unauthenticated attackers to read or write arbitrary files, which could allow remote code execution in certain configurations of the product. 

“In particular, the vulnerability affects PaperCut servers running on Windows. File upload leading to remote code execution is possible when the external device integration setting is enabled. This setting is on by default with certain installations of PaperCut, such as the PaperCut NG Commercial version or PaperCut MF,” explained Horizon3, whose researchers discovered the issue.

The security firm’s analysis shows that a vast majority of PaperCut installations are impacted. 

Technical details have yet to be disclosed to prevent abuse. Horizon3 has provided a command that can be used to check if a PaperCut server is vulnerable. 

PaperCut has released a patch for this and other vulnerabilities with the release of version 22.1.3. Mitigations are also available. 

While there is no evidence that CVE-2023-39143 has been exploited in the wild, there is one recent PaperCut vulnerability, tracked as CVE-2023-27350, that has been widely used by both ransomware groups and state-sponsored threat actors.

Advertisement. Scroll to continue reading.

Horizon3 noted that both vulnerabilities can be exploited without authentication and user interaction, but the new security hole is more complex to exploit as it involves chaining multiple bugs. 

The vendor described CVE-2023-39143 as two path traversal bugs and noted that direct server IP access is required for exploitation.

Related: CISA, FBI: Ransomware Gang Exploited PaperCut Flaw Against Education Facilities

Related: Huntress: Most PaperCut Installations Not Patched Against Already-Exploited Security Flaw

https://www.securityweek.com/new-papercut-vulnerability-allows-remote-code-execution/




Unlimited miles and nights: Vulnerability found in rewards programs

Flight information display in an airport

Travel rewards programs like those offered by airlines and hotels tout the specific perks of joining their club over others. Under the hood, though, the digital infrastructure for many of these programs—including Delta SkyMiles, United MileagePlus, Hilton Honors, and Marriott Bonvoy—is built on the same platform. The backend comes from the loyalty commerce company Points and its suite of services, including an expansive application programming interface (API).

But new findings, published today by a group of security researchers, show that vulnerabilities in the Points.com API could have been exploited to expose customer data, steal customers’ “loyalty currency” (like miles), or even compromise Points global administration accounts to gain control of entire loyalty programs.

The researchers—Ian Carroll, Shubham Shah, and Sam Curry—reported a series of vulnerabilities to Points between March and May, and all the bugs have since been fixed.

“The surprise for me was related to the fact that there is a central entity for loyalty and points systems, which almost every big brand in the world uses,” Shah says. “From this point, it was clear to me that finding flaws in this system would have a cascading effect to every company utilizing their loyalty backend. I believe that once other hackers realized that targeting Points meant that they could potentially have unlimited points on loyalty systems, they would have also been successful in targeting Points.com eventually.”

One bug involved a manipulation that allowed the researchers to traverse from one part of the Points API infrastructure to another internal portion and then query it for reward program customer orders. The system included 22 million order records, which contain data like customer rewards account numbers, addresses, phone numbers, email addresses, and partial credit card numbers. Points.com had limits in place on how many responses the system could return at a time, meaning an attacker couldn’t simply dump the whole data trove at once. But the researchers note that it would have been possible to look up specific individuals of interest or slowly siphon data from the system over time.

Another bug the researchers found was an API configuration issue that could have allowed an attacker to generate an account authorization token for any user with just their last name and rewards number. These two pieces of data could potentially be found through past breaches or could be taken by exploiting the first vulnerability. With this token, attackers could take over customer accounts and transfer miles or other rewards points to themselves, draining the victim’s accounts.

The researchers found two vulnerabilities similar to the other pair of bugs, one of which only impacted Virgin Red while the other affected just United MileagePlus. Points.com fixed both of these vulnerabilities as well.

Most significantly, the researchers found a vulnerability in the Points.com global administration website in which an encrypted cookie assigned to each user had been encrypted with an easily guessable secret—the word “secret” itself. By guessing this, the researchers could decrypt their cookie, reassign themselves global administrator privileges for the site, reencrypt the cookie, and essentially assume god-mode-like capabilities to access any Points reward system and even grant accounts unlimited miles or other benefits.

“As part of our ongoing data security activities, Points recently worked with a group of skilled security researchers concerning a potential cybersecurity vulnerability in our system,” Points said in a statement shared by spokesperson Carrie Mumford. “There was no evidence of malice or misuse of this information, and all data accessed by the group has been destroyed. As with any responsible disclosure, upon learning of the vulnerability, Points acted immediately to address and remediate the reported issue. Our remediation efforts have been vetted and verified by third-party cybersecurity experts.”

The researchers confirm that the fixes work and say that Points was very responsive and collaborative in addressing the disclosures. The group started looking into the company’s systems partly because of a longtime interest in the inner workings of loyalty rewards programs. Carroll even runs a travel website related to optimizing plane tickets paid for with miles. But more broadly, the researchers focus their work on platforms that become critical because they are acting as shared infrastructure among a number of organizations or institutions.

Bad actors are increasingly homing in on this strategy as well, carrying out supply chain attacks for espionage or finding vulnerabilities in widely used software and equipment and exploiting them in cybercriminal attacks.

“We’re trying to find high-impact systems where if an attacker were able to compromise them there could be significant damage,” Curry says. “I think a lot of companies accidentally get to a point where they are ultimately in charge of a lot of data and systems, but they don’t necessarily stop and assess the position they’re in.”

This story originally appeared on wired.com.

https://arstechnica.com/?p=1959041




In Other News: Cybersecurity Funding Rebounds, Cloud Threats, BeyondTrust Vulnerability

SecurityWeek is publishing a weekly cybersecurity roundup that provides a concise compilation of noteworthy stories that might have slipped under the radar.

We provide a valuable summary of stories that may not warrant an entire article, but are nonetheless important for a comprehensive understanding of the cybersecurity landscape.

Each week, we will curate and present a collection of noteworthy developments, ranging from the latest vulnerability discoveries and emerging attack techniques to significant policy changes and industry reports.

Here are this week’s stories:   

Nozomi OT/IoT security report shows surge in malware and access control issues

Nozomi Networks’ OT & IoT Security Report for the first half of 2023 reveals that malware-related security threats have increased roughly ten times, and so have access control and authorization issues. Authentication and password issues, OT-specific threats, and suspicious network behavior have dropped in H1 2023. 

Schneider Electric launches Managed Security Services for OT

Advertisement. Scroll to continue reading.

Schneider Electric has launched a vendor-agnostic Managed Security Services (MSS) offering designed to help operational technology (OT) organizations address the risks associated with remote access and connectivity technologies. The offering is powered by Schneider’s Cybersecurity Connected Service Hub (CCSH) and provides monitoring and response capabilities. 

Early-stage cybersecurity funding rebounds

DataTribe’s latest cybersecurity funding report shows that deal volume for early-stage companies started to rebound in the second quarter of 2023. Seed, Series A and Series B deal volume increased by 47% compared to the first quarter.

Cybersecurity for large sporting events

The fifth installment of Microsoft’s Cyber Signals report provides an overview of the cyber risks associated with large sporting events, along with recommendations on how sports associations, teams, and venues can safeguard against cybersecurity threats, starting with the implementation of a multilayered security framework. Microsoft says it performed over 634 million authentications when providing cybersecurity defenses in Qatar during the FIFA World Cup in 2022.

Abusing the SSM agent as a remote access trojan 

Mitiga warns of a new post-exploitation technique in AWS, where the Systems Manager (SSM) agent can be used as a remote access trojan (RAT), to control Linux and Windows machines from another AWS account. A legitimate tool that admins can use to manage instances, the SSM agent may allow threat actors “to carry out malicious activities on an ongoing basis”.

Authorities on alert over extremists’ use of Flipper Zero hacking tool

Local authorities in major US cities have been put on alert over the potential use of the Flipper Zero hacking tool by racially and ethnically motivated violent extremists (REMVEs). The tool can be used to hack radio protocols and access control systems, to clone RFID cards, and to bypass the security of electronic safes.

New Azure Active Directory attack vector 

Vectra details a new attack vector against Azure Active Directory that could allow attackers to move laterally to other Microsoft tenants. The technique targets Cross-Tenant Synchronization, newly introduced functionality that exists in every Microsoft deployment, which allows organizations to synchronize users and groups between tenants. Vectra has published a proof-of-concept (PoC) exploit. 

Google Cloud Threat Horizons Report

Google has released the August 2023 Threat Horizons report (PDF) that provides intelligence about threats to cloud enterprise users and recommendations on how service providers and organizations can improve cloud security.

VMware patches two vulnerabilities in Horizon Server 

VMware announced patches for two medium-severity vulnerabilities in Horizon Server that could allow attackers to perform HTTP smuggle requests (CVE-2023-34037) and access information relating to the internal network configuration (CVE-2023-34038). Neither flaw appears to be exploited in attacks. 

BeyondTrust command injection vulnerability

BeyondTrust informed customers recently that it was working on patches for a command injection vulnerability in Privileged Remote Access (PRA) and Remote Support (RS) versions 23.2.1 and 23.2.2 that could allow a remote attacker to execute OS commands, without authentication. The issue reportedly has the maximum severity rating (CVSS score of 10).

Related: In Other News: Data Breach Cost Rises, Russia Targets Diplomats, Tracker Alerts in Android

https://www.securityweek.com/in-other-news-cybersecurity-funding-rebounds-cloud-threats-beyondtrust-vulnerability/




Points.com Vulnerabilities Allowed Customer Data Theft, Rewards Program Hacking

Multiple vulnerabilities in the popular airline and hotel rewards platform points.com could have allowed attackers to access users’ personal information, security researchers warn.

Acting as a backend for numerous airline and hotel rewards programs, points.com also operates as a market for exchanging and redeeming loyalty points.

Over the course of several months, security researchers Ian Carroll, Shubham Shah, and Sam Curry identified five security defects in the platform that could have provided attackers with unauthorized access to sensitive information such as names, addresses, emails, phone numbers, and transactions.

Furthermore, these issues could have allowed attackers to transfer points between accounts, and even access a global administrator website, gaining permissions to issue points, manage loyalty programs, and perform various administrative actions, Sam Curry explains.

In early March, the security researchers identified and reported to points.com an unauthenticated HTTP path traversal bug that could have been exploited to access an internal API exposing a database of 22 million order records.

“The data within the records included partial credit card numbers, home addresses, email addresses, phone numbers, reward points numbers, customer authorization tokens, and miscellaneous transaction details. This information could be queried through an API call that returned one-hundred results per HTTP request,” Curry notes.

The researchers also reported an authorization bypass in an improperly configured API, which could have been exploited to transfer airline rewards points from users. The issue could have allowed attackers to generate full account authorization tokens to manage customer accounts and view their information.

Advertisement. Scroll to continue reading.

In April, the researchers reported a bug impacting United Airlines, where an attacker could generate an authorization token for any user account, only by knowing their rewards number and surname.

“Through this issue, an attacker could both transfer miles to themselves and authenticate as the member on multiple apps related to MileagePlus, potentially including the MileagePlus administrator panel. This issue disclosed the member’s name, billing address, redacted credit card information, email, phone number, and past transactions on the account,” Curry explains.

In May, the researchers discovered a points.com-hosted Virgin rewards website leaking API authentication information, allowing an attacker to impersonate the airline and make API calls to modify accounts, add/remove points, and modify the Virgin rewards program’s settings.

Also in May, the researchers discovered the “Flask session secret for the points.com global administration website”, which provides management of all airline tenants and customer accounts, allowing them to create session cookies with super administrator permissions.

“We observed that we could access all core administration functionality on the website, including user lookup, manual bonuses, rewards points conversion modifications, and many more points.com administrative endpoints. An attacker could abuse this access to revoke existing reward program credentials and temporarily take down airline rewards functionality,” Curry notes.

The researchers note that the points.com security team was very responsive to their vulnerability reports, addressing each issue in roughly an hour after disclosure.

Related: American Airlines, Southwest Airlines Impacted by Data Breach at Third-Party Provider

Related: Information of European Hotel Chain’s Customers Found on Unprotected Server

Related: Breached American Airlines Email Accounts Abused for Phishing

https://www.securityweek.com/points-com-vulnerabilities-allowed-customer-data-theft-rewards-program-hacking/




Exploitation of Ivanti EPMM Flaw Picking Up as New Vulnerability Is Disclosed

Exploitation of the recently disclosed Ivanti Endpoint Manager Mobile (EPMM) vulnerability has started to pick up, just as the vendor announced the discovery of a new flaw.

The EPMM zero-day tracked as CVE-2023-35078, which allows an unauthenticated attacker to obtain sensitive information and make changes to the targeted system, was exploited in attacks aimed at the Norwegian government since at least April 2023

While initially the flaw was only exploited in targeted attacks, threat intelligence firm GreyNoise started seeing exploitation attempts from dozens of unique IP addresses on July 31. The company has seen attacks coming from a total of 75 IPs. 

The ShadowServer Foundation reports that there are still roughly 700 internet-exposed instances of the mobile management software that are vulnerable to attacks. 

In the attacks exploiting CVE-2023-35078, threat actors also leveraged a different EPMM security hole, CVE-2023-35081, to upload webshells on the device and run commands. 

This week, Ivanti informed customers about a third new vulnerability, CVE-2023-35082, which allows an unauthenticated, remote attacker to access users’ personally identifiable information and make limited changes to the server. 

Rapid7, whose researchers discovered this critical flaw, reported that CVE-2023-35082 is actually a bypass of the fix for CVE-2023-35078.

Advertisement. Scroll to continue reading.

“CVE-2023-35081 could be chained with CVE-2023-35082 to allow an attacker write malicious webshell files to the appliance, which may then be executed by the attacker,” the cybersecurity firm explained. 

One noteworthy aspect is that CVE-2023-35082 can only be exploited against unsupported versions of MobileIron Core, version 11.2 and below. MobileIron Core is the previous name of EPMM.

“The vulnerability was incidentally resolved in MobileIron Core 11.3 as part of work on a product bug. It had not previously been identified as a vulnerability,” Ivanti said in its advisory. 

The US Cybersecurity and Infrastructure Security Agency (CISA) and the Norwegian National Cyber Security Centre (NCSC-NO) said this week that they are concerned about the potential for widespread exploitation of the vulnerabilities against government and private sector organizations.

Related: Citrix Zero-Day Exploited Against Critical Infrastructure Organization

Related: Adobe Releases New Patches for Exploited ColdFusion Vulnerabilities

Related: Zero-Day Vulnerability Exploited to Hack Barracuda Email Security Gateway Appliances

https://www.securityweek.com/exploitation-of-ivanti-epmm-flaw-picking-up-as-new-vulnerability-is-disclosed/