Site icon TheCyberThrone

CISA adds Zimbra and Microsoft vulnerabilities to its KEV Catalog

Advertisements

The Cybersecurity and Infrastructure Security Agency (CISA) has recently added two critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog. These vulnerabilities, affecting Microsoft Partner Center and Synacor Zimbra Collaboration Suite (ZCS), have been actively exploited, prompting CISA to urge immediate remediation. Here’s a detailed analysis of these vulnerabilities:

1. CVE-2024-49035: Microsoft Partner Center Improper Access Control Vulnerability

Nature of the Vulnerability

Exploitation Details

Mitigation Measures

2. CVE-2023-34192: Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting (XSS) Vulnerability

Nature of the Vulnerability

Exploitation Details

Mitigation Measures

Final Thoughts

CISA emphasizes the importance of timely remediation of these vulnerabilities to protect against active threats. Federal Civilian Executive Branch (FCEB) agencies are mandated to apply the necessary updates by March 18, 2025, to secure their networks. However, CISA strongly urges all organizations to prioritize the remediation of these vulnerabilities as part of their vulnerability management practices.

Exit mobile version