Daily Tech News, Interviews, Reviews and Updates

CISA adds two new bugs to their Known Exploited Vulnerabilities catalog

Yesterday, on August 9 2022, the U.S Cybersecurity and Infrastructure Security Agency (CISA) updated their catalog of Known Exploited Vulnerabilities with two more flaws. The CISA updated the catalog based on evidence of active exploitation. 

One of those two flaw has exploit code publicly available. That code has spent more than two years as a zero-day bug in the Windows Support Diagnostic Tool (MSDT). 

The flaws have received a high severity score and are recognized as directory traversal vulnerabilities, which could help the attackers plant malware on a targeted system. 

The first bug is officially tracked as CVE-2022-34713 and informally referred to as DogWalk. This flaw in MSDT facilitates the threat actor to deploy a malicious executable into the Windows Startup folder. 

Researcher Imre Rad first reported the issue to Microsoft in January 2022. However, his report was dismissed as it was found misclassified as not describing a security risk. Consequently, the bug made its comeback to public attention this year. 

On the other hand, the second bug added to CISA’s Known Exploited Vulnerabilities catalog is tracked as CVE-2022-30333. This bug is a path traversal bug in the UnRar utility for Linux and Unix systems. 

This bug facilitates an attacker to plant a malicious file on the target system by extracting it to an arbitrary location during the unpack operation. 

The federal agencies in the US will apply the updates from the vendors by August 30. 



Readers like you help support The Tech Outlook. When you make a purchase using links on our site, we may earn an affiliate commission. We cannot guarantee the Product information shown is 100% accurate and we advise you to check the product listing on the original manufacturer website. Thetechoutlook is not responsible for price changes carried out by retailers. The discounted price or deal mentioned in this item was available at the time of writing and may be subject to time restrictions and/or limited unit availability. Amazon and the Amazon logo are trademarks of Amazon.com, Inc. or its affiliates Read More
You might also like

This website uses cookies to improve your experience. We'll assume you're ok with this, but you can opt-out if you wish. Accept Read More