Site icon TheCyberThrone

CISA Adds Microsoft and Zyxel Vulnerabilities to KEV Catalog

Advertisements

On February 11, 2025, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added four vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog. These vulnerabilities, associated with Microsoft and Zyxel products, have been actively exploited, prompting CISA to prioritize their remediation. Federal agencies and organizations are advised to apply the necessary fixes by March 02, 2025, to safeguard against potential threats.

Microsoft Vulnerabilities

CVE-2025-21391: Windows Storage Link Following Vulnerability

CVE-2025-21418: Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

Zyxel Vulnerabilities

CVE-2024-40891: Zyxel DSL CPE OS Command Injection Vulnerability

CVE-2024-40890: Zyxel DSL CPE OS Command Injection Vulnerability

Mitigation Measures

To protect against the exploitation of these vulnerabilities, organizations should implement the following mitigation measures:

For Microsoft Vulnerabilities

For Zyxel Vulnerabilities

Final Thoughts

The addition of these vulnerabilities to CISA’s KEV catalog underscores the critical importance of timely remediation to protect against cyber threats. By applying the recommended updates, implementing strong security measures, and maintaining regular monitoring, organizations can mitigate the risks associated with these vulnerabilities and safeguard their systems and data.

Exit mobile version