June 6, 2023

The U.S. CISA has added the following five new issues to its Known Exploited Vulnerabilities Catalog:

  • CVE-2021-27876 – Veritas Backup Exec Agent File Access Vulnerability
  • CVE-2021-27877 – Veritas Backup Exec Agent Improper Authentication Vulnerability
  • CVE-2021-27878 – Veritas Backup Exec Agent Command Execution Vulnerability
  • CVE-2019-1388 – Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
  • CVE-2023-26083 – Arm Mali GPU Kernel Driver Information Disclosure Vulnerability

Researchers reported that an affiliate of the Blackcat Ransomware gang, tracked as UNC4466, was exploiting the three above vulnerabilities in the Veritas Backup solution to gain initial access to the target network.

Advertisements

The CVE-2023-26083 flaw in the Arm Mali GPU driver is chained with other issues to install commercial spyware, as reported by Google’s TAG recently.

CISA orders federal agencies to fix this flaw by April 28, 2023.

Leave a Reply

%d bloggers like this: