Site icon TheCyberThrone

CISA KEV Catalog Update Part III- February 2025

Advertisements

The Cybersecurity and Infrastructure Security Agency (CISA) has recently updated its Known Exploited Vulnerabilities (KEV) Catalog, adding five new vulnerabilities that are actively being exploited in the wild. These vulnerabilities pose significant risks to federal systems, and their exploitation can lead to various security breaches.

1. CVE-2025-04117: 7-Zip Mark of the Web Bypass Vulnerability

2. CVE-2022-23748: Dante Discovery Process Control Vulnerability

3. CVE-2024-21413: Microsoft Outlook Improper Input Validation Vulnerability

4. CVE-2020-29574: CyberoamOS (CROS) SQL Injection Vulnerability

5. CVE-2020-15069: Sophos XG Firewall Buffer Overflow Vulnerability

Final Thoughts

The addition of these five vulnerabilities to CISA’s KEV Catalog underscores the critical nature of these security issues and the importance of timely remediation. By applying the recommended patches, implementing robust security measures, and maintaining a proactive security posture, organizations can mitigate the risks associated with these vulnerabilities and protect their systems from potential exploitation.

Exit mobile version