The U.S. CISA has added the following five new issues to its Known Exploited Vulnerabilities Catalog:
- CVE-2021-27876 – Veritas Backup Exec Agent File Access Vulnerability
- CVE-2021-27877 – Veritas Backup Exec Agent Improper Authentication Vulnerability
- CVE-2021-27878 – Veritas Backup Exec Agent Command Execution Vulnerability
- CVE-2019-1388 – Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
- CVE-2023-26083 – Arm Mali GPU Kernel Driver Information Disclosure Vulnerability
Researchers reported that an affiliate of the Blackcat Ransomware gang, tracked as UNC4466, was exploiting the three above vulnerabilities in the Veritas Backup solution to gain initial access to the target network.
The CVE-2023-26083 flaw in the Arm Mali GPU driver is chained with other issues to install commercial spyware, as reported by Google’s TAG recently.
CISA orders federal agencies to fix this flaw by April 28, 2023.