Article Details

Scrape Timestamp (UTC): 2025-02-26 04:39:24.810

Source: https://thehackernews.com/2025/02/cisa-adds-microsoft-and-zimbra-flaws-to.html

Original Article Text

Click to Toggle View

CISA Adds Microsoft and Zimbra Flaws to KEV Catalog Amid Active Exploitation. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday placed two security flaws impacting Microsoft Partner Center and Synacor Zimbra Collaboration Suite (ZCS) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities in question are as follows - Last year, Microsoft acknowledged that CVE-2024-49035 had been exploited in the wild, but did not reveal any additional details on how it was weaponized in real-world attacks. There are currently no public reports about in-the-wild abuse of CVE-2023-34192. In light of the development, Federal Civilian Executive Branch (FCEB) agencies are mandated to apply the necessary updates by March 18, 2025, to secure their networks. The development comes a day after CISA added two security flaws impacting Adobe ColdFusion and Oracle Agile Product Lifecycle Management (PLM) to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

Daily Brief Summary

NATION STATE ACTIVITY // CISA Updates KEV Catalog with Microsoft and Zimbra Flaws

CISA included two new vulnerabilities in its Known Exploited Vulnerabilities (KEV) catalog, targeting Microsoft Partner Center and Synacor Zimbra Collaboration Suite.

The inclusion is based on confirmed instances of active exploitation of these security flaws.

Microsoft's vulnerability, identified as CVE-2024-49035, was acknowledged last year as being exploited, with no further details on its use in attacks provided.

No reports of in-the-wild abuse for the CVE-2023-34192 associated with Zimbra have surfaced to date.

Federal Civilian Executive Branch (FCEB) agencies are required to implement necessary security updates by March 18, 2025, to protect their networks.

This update to the KEV catalog follows closely after the addition of vulnerabilities in Adobe ColdFusion and Oracle Agile PLM due to similar exploitation threats.