CISA has warned US federal agencies to secure their systems against attacks exploiting vulnerabilities in Cisco and Windows systems. While the cybersecurity agency has tagged these flaws as actively exploited in the wild, it has yet to provide specific details regarding this malicious activity and who is behind it. The first flaw (tracked as CVE-2023-20118) enables attackers to execute arbitrary commands on RV016, RV042, RV042G, RV082, RV320, and RV325 VPN routers. While it requires valid administrative credentials, this can still be achieved by chaining the CVE-2023-20025 authentication bypass, which provides root privileges. Cisco says in an advisory published in January 2023 and updated one year later that its Product Security Incident Response Team (PSIRT) is aware of CVE-2023-20025 publicly available proof-of-concept exploit code. The second security bug (CVE-2018-8639) is a Win32k elevation of privilege flaw that local attackers logged into the target system can exploit to run arbitrary code in kernel mode. Successful exploitation also allows them to alter data or create rogue accounts with full user rights to take over vulnerable Windows devices. According to a security advisory issued by Microsoft in December 2018, this vulnerability impacts client (Windows 7 or later) and server (Windows Server 2008 and up) platforms. Today, CISA added the two vulnerabilities to its Known Exploited Vulnerabilities catalog, which lists security bugs the agency has tagged as exploited...
CISA tags Windows, Cisco vulnerabilities as actively exploited
BleepingComputer
·Sergiu Gatlan
·Published Mar 3, 2025
·Updated
Affected Software
15 affected components
Cisco RV016
Cisco RV042
Cisco RV042G
Cisco RV082
Cisco RV320
Cisco RV325
Microsoft Windows=7
Microsoft Windows Server=2008
Cisco RV016
Cisco RV042
Cisco RV042G
Cisco RV082
Cisco RV320
Cisco RV325
Microsoft Win32k
Frequently Asked Questions
1
What is the main focus of the article?
The article discusses CISA's warning about actively exploited vulnerabilities in Cisco and Microsoft Windows systems.
2
Which specific Cisco products are mentioned as vulnerable?
The vulnerabilities affect Cisco RV016, RV042, RV042G, RV082, RV320, and RV325 products.
3
What versions of Microsoft Windows are highlighted in the article?
The vulnerabilities specifically impact Microsoft Windows 7 and Windows Server 2008.
4
What actions does CISA recommend for federal agencies?
CISA recommends that federal agencies secure their systems against the identified vulnerabilities.
5
Are there any details about how these vulnerabilities are being exploited?
The article notes that the vulnerabilities are actively exploited in the wild, though it does not provide specific exploitation details.