A leading US security agency has issued an emergency directive requiring all of the government's civilian federal agencies to mitigate two zero-days under active exploitation.
Ivanti first disclosed the vulnerabilities on January 10, although it's believed they had been under active exploitation by a Chinese state actor since December 3.
When chained, CVE-2023-46805 and CVE-2024-21887 enable threat actors to craft malicious requests and execute arbitrary commands on the system, without needing to authenticate first.
Last week, researchers at Volexity revealed that the bugs were under active exploitation by a number of threat groups, with over 1700 devices already compromised.
This Cyber News was published on www.infosecurity-magazine.com. Publication date: Mon, 22 Jan 2024 10:20:05 +0000