• Menu
  • Skip to main content
  • Skip to primary sidebar

The Cyber Security News

Latest Cyber Security News

Header Right

  • Latest News
  • Vulnerabilities
  • Cloud Services
Cyber Security News

US Government IIS Server Breached via Telerik Software Flaw

You are here: Home / General Cyber Security News / US Government IIS Server Breached via Telerik Software Flaw
March 16, 2023

The US Cybersecurity and Infrastructure Security Agency (CISA) has disclosed info concerning a .NET deserialization vulnerability (CVE-2019-18935) in the Progress Telerik user interface (UI) for ASP.NET AJAX.

CISA described the conclusions in an advisory on Wednesday, indicating several cyber-danger actors have been equipped to exploit the flaw, which also affected the Microsoft Internet Facts Services (IIS) web server of a federal civilian executive department (FCEB) agency concerning November 2022 and January 2023.

If exploited efficiently, the vulnerability allows remote code execution (RCE). Simply because of this, the flaw has been rated as critical and assigned a CVSS v3.1 score of 9.8.

✔ Approved From Our Partners
AOMEI Backupper Lifetime

Protect and backup your data using AOMEI Backupper. AOMEI Backupper takes secure and encrypted backups from your Windows, hard drives or partitions. With AOMEI Backupper you will never be worried about loosing your data anymore.

Get AOMEI Backupper with 72% discount from an authorized distrinutor of AOMEI: SerialCart® (Limited Offer).

➤ Activate Your Coupon Code


Examine more on the CVSS procedure in this article: A Scenario Against CVSS

“Though the agency’s vulnerability scanner had the correct plugin for CVE-2019-18935, it failed to detect the vulnerability due to the Telerik UI software becoming mounted in a file path it does not usually scan,” reads the CISA advisory. “This may be the case for numerous program installations, as file paths extensively differ depending on the firm and set up approach.”

Commenting on the information, Dror Liwer, co-founder of cybersecurity corporation Coro, explained vulnerabilities like this are a “low-hanging fruit” for attackers.

“They signify an straightforward, effectively-documented entry issue that does not involve social engineering, robust complex skills or energetic checking,” Liwer spelled out.

According to the govt, maintaining up with regarded vulnerabilities throughout all assets can be overwhelming, but corporations must shell out extra interest to updates.

“There is no quick deal with. Vulnerability management have to be an integral portion of any cybersecurity system, as cumbersome and laborious as it might be,” Liwer extra.

As significantly as CVE-2019-18935 is concerned, CISA claimed entities working with Development Telerik application must put into action a patch management alternative to assure compliance with the most current security patches. 

They really should also validate the output from patch management and vulnerability scanning towards managing providers to check for any discrepancies, and restrict provider accounts to the minimum amount permissions required.

The CISA advisory comes weeks right after SentinelOne disclosed details linked to new malware loaders centered on the .NET progress platform.


Some elements of this posting are sourced from:
www.infosecurity-journal.com

Previous Post: «Cyber Security News ChipMixer Crypto Laundromat Shut Down By German, US Authorities
Next Post: Google Uncovers 18 Severe Security Vulnerabilities in Samsung Exynos Chips google uncovers 18 severe security vulnerabilities in samsung exynos chips»

Reader Interactions

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Primary Sidebar

Report This Article

Recent Posts

  • China-Linked Hackers Exploit Windows Shortcut Flaw to Target European Diplomats
  • China-Linked Tick Group Exploits Lanscope Zero-Day to Hijack Corporate Systems
  • The MSP Cybersecurity Readiness Guide: Turning Security into Growth
  • CISA and NSA Issue Urgent Guidance to Secure WSUS and Microsoft Exchange Servers
  • Eclipse Foundation Revokes Leaked Open VSX Tokens Following Wiz Discovery
  • CISA Flags VMware Zero-Day Exploited by China-Linked Hackers in Active Attacks
  • A New Security Layer for macOS Takes Aim at Admin Errors Before Hackers Do
  • Google’s Built-In AI Defenses on Android Now Block 10 Billion Scam Messages a Month
  • Russian Ransomware Gangs Weaponize Open-Source AdaptixC2 for Advanced Attacks
  • New “Brash” Exploit Crashes Chromium Browsers Instantly with a Single Malicious URL

Copyright © TheCyberSecurity.News, All Rights Reserved.