Feds add Windows, router vulnerabilities to actively exploited list

Bad actors are weaponizing these flaws.
By  on 
Hands typing on a keyboard
New vulnerabilities are actively being weaponized in the wild, affecting Cisco routers and Windows computers. Credit: Jorge Elizaquibel via Getty Images

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has just added new exploits to its actively exploited list, as first noticed by BleepingComputer.

CISA's actions basically serve as a warning to U.S. federal agencies about vulnerabilities currently being exploited in the wild. 

One exploit being tracked, CVE-2023-20118, allows hackers to remotely "execute arbitrary commands" on certain VPN routers. These routers include Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325.

"An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface," CISA wrote. "A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data."

Mashable Light Speed
Want more out-of-this world tech, space and science stories?
Sign up for Mashable's weekly Light Speed newsletter.
By clicking Sign Me Up, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up!

In order to take advantage of this exploit, an attacker would need admin credentials. However, as BleepingComputer points out, hackers could take advantage of another vulnerability, CVE-2023-20025, in order to bypass authentication. 

Another vulnerability added by CISA is CVE-2018-8639. This bug affects a broad swath of Windows operating systems including Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, and Windows 10 Servers.

According to CISA, this vulnerability "exists in Windows when the Win32k component fails to properly handle objects in memory." A bad actor with local access to the vulnerable system can utilize the exploit to run arbitrary code in kernel mode. BleepingComputer reports that a bad actor could use this vulnerability to "alter data or create rogue accounts with full user rights to take over vulnerable Windows devices."

Microsoft and Cisco have not yet released their own security warning regarding these two exploits.

Topics Cybersecurity


Recommended For You
This NETGEAR Nighthawk 6E router is over $300 off and solid for multiplayer supremacy
NETGEAR Nighthawk AXE11000 WiFi 6E Router on a white textured background


Get a portable VPN router for just $150
Deeper Connect

You should update your iPhone to iOS 18.3.1 right now
iPhone USB

Microsoft to kill Office support for Windows 10 this year
Windows 10 operating system logo is displayed on a laptop screen

Trending on Mashable
NYT Connections hints today: Clues, answers for March 7, 2025
A close-up of an NYT Connections game on a smartphone.

NYT Strands hints, answers for March 7
A game being played on a smartphone.

Wordle today: Answer, hints for March 7, 2025
A close-up of a Wordle game open on a smartphone.

Tesla sales are reportedly falling globally. How bad it is and where.
Tesla logo

NYT Connections hints today: Clues, answers for March 6, 2025
A close-up of an NYT Connections game on a smartphone.
The biggest stories of the day delivered to your inbox.
These newsletters may contain advertising, deals, or affiliate links. By clicking Subscribe, you confirm you are 16+ and agree to our Terms of Use and Privacy Policy.
Thanks for signing up. See you at your inbox!