• News/
  • https://www.bleepingcomputer.com/news/security/cisa-tags-microsoft-net-and-apache-ofbiz-bugs-as-exploited-in-attacks/

CISA tags Microsoft .NET and Apache OFBiz bugs as exploited in attacks

BleepingComputer
·
Bill Toulas
·
Published Feb 5, 2025
·
Updated

The US Cybersecurity & Infrastructure Security Agency (CISA) has added four vulnerabilities to its Known Exploited Vulnerabilities catalog, urging federal agencies and large organizations to apply the available security updates as soon as possible. Among them are flaws impacting Microsoft .NET Framework and Apache OFBiz (Open For Business), two widely used software applications. Though the agency has marked those flaws as actively exploited in attacks, it has not provided specific details about the malicious activity, who is conducting it, and against whom. The first flaw, tracked under CVE-2024-29059, is a high severity (CVSS v3 score: 7.5) information disclosure bug in the .NET Framework discovered by CODE WHITE and disclosed to Microsoft in November 2023. Microsoft closed the disclosure report in December 2023, stating, "after careful investigation, we determined this case does not meet our bar for immediate servicing." However, Microsoft ultimately fixed the flaw in the January 2024 security updates but mistakenly did not issue a CVE or acknowledge the researchers. In February, CODE WHITE released technical details and a proof of concept exploit for leaking internal object URIs, which can be used to perform .NET Remoting attacks, Microsoft finally released an advisory for this flaw under CVE-2024-29059 in March 2024 and attributed the discovery to the researchers. The Apache OFBiz flaw is CVE-2024-45195, a critical severity (CVSS v3 score: 9.8) remote code execution vuln...

Read full article

Affected Software

5 affected components
Microsoft .NET Framework
Apache OFBiz=18.12.16
Paessler PRTG=18.2.41.1652
Microsoft .NET Framework
Apache OFBiz
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities have CISA identified as being actively exploited?

CISA has tagged vulnerabilities in Microsoft .NET Framework and Apache OFBiz as being exploited in attacks.

2

What is the significance of CISA's alert regarding these vulnerabilities?

The alert signifies that federal agencies and large organizations must prioritize applying security updates to these affected software to mitigate risks.

3

Which versions of Apache OFBiz are impacted by the identified vulnerabilities?

The vulnerabilities specifically affect Apache OFBiz version 18.12.16.

4

What should organizations do in response to CISA's warning about these vulnerabilities?

Organizations should immediately apply the available security patches to the affected software as recommended by CISA.

5

Is there any mention of other affected software besides Microsoft .NET and Apache OFBiz?

Yes, Paessler PRTG version 18.2.41.1652 is also mentioned as affected by the vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203