Skip to content

Commit

Permalink
CISA Updates Known Exploited Catalog - 20240724001 (#895)
Browse files Browse the repository at this point in the history
* CISA Updates Known Exploited Catalog - 20240724001

* Format markdown docs

* Update 20240724001

Added Microsoft Advisory URL

---------

Co-authored-by: carel-v98 <carel-v98@users.noreply.github.com>
Co-authored-by: JadonWill <117053393+JadonWill@users.noreply.github.com>
  • Loading branch information
3 people committed Jul 24, 2024
1 parent 1e376c2 commit 456399b
Showing 1 changed file with 23 additions and 0 deletions.
Original file line number Diff line number Diff line change
@@ -0,0 +1,23 @@
# CISA Updates Known Exploited Catalog - 20240724001

## Overview

CISA has added two new vulnerabilities to its [Known Exploited Vulnerabilities Catalog](https://www.cisa.gov/known-exploited-vulnerabilities-catalog), based on evidence of active exploitation. These types of vulnerabilities are frequent attack vectors for malicious cyber actors and pose significant risks to the federal enterprise.

## What is vulnerable?

| Product(s) Affected | Version(s) | CVE # | CVSS v4/v3 | Severity |
| --------------------------- | --------------------------- | ------------------------------------------------- | ---------- | -------- |
| Microsoft Internet Explorer | versions IE6 through to IE8 | <https://nvd.nist.gov/vuln/detail/CVE-2012-4792> | 9.3 | High |
| Twilio products | all versions before 25.1.0 | <https://nvd.nist.gov/vuln/detail/CVE-2024-39891> | 5.3 | Medium |

## What has been observed?

There is no evidence of exploitation affecting Western Australian Government networks at the time of publishing.

## Recommendation

The WA SOC recommends administrators apply the solutions as per vendor instructions to all affected devices within expected timeframe of *48 hrs...* (refer [Patch Management](../guidelines/patch-management.md)):

- Microsoft Advisory: <http://technet.microsoft.com/security/advisory/2794220>
- Twilio Advisory: <https://www.twilio.com/en-us/changelog/Security_Alert_Authy_App_Android_iOS>

0 comments on commit 456399b

Please sign in to comment.