Top Exploited Vulnerabilities of 2024

Get Started Quickly!

Cybercriminals took their best chance in 2024 by exploiting the vulnerabilities that are already known by everyone; frequently targeting certain systems before organisations can put in the necessary repairs. The top vulnerabilities list is compiled by the worldwide cyber security organisations such as the ACSC (Australian Cyber Security Centre) in Australia. It denotes the urgency that calls for preventative measures in protection. We explore these weaknesses in this blog with practical tips for Australian companies on how to improve their resilience against cyber attacks.

Top 15 Routinely Exploited Vulnerabilities in 2023

Cyber actors relied on these vulnerabilities most in the years 2023 and 2024. The vulnerabilities are some of the glaring illustrations to prove how unpatched systems could expose businesses to ransomware, data theft, and security breaches.

CVEProduct(s)Vulnerability TypeImpact
CVE-2023-3519– Citrix NetScaler ADC
– NetScaler Gateway
Code InjectionAllows unauthenticated attackers to exploit a stack buffer overflow.
CVE-2023-4966– Citrix NetScaler ADC
– NetScaler Gateway
Buffer OverflowAllows session token leakage (Citrix Bleed vulnerability).
CVE-2023-20198Cisco IOS XE Web UIPrivilege EscalationEnables unauthorised users to create accounts and gain access.
– CVE-2023-20273Cisco IOS XEOS Command InjectionAllows privilege escalation to root.
CVE-2023-27997– Fortinet FortiOS
– FortiProxy SSL-VPN
Heap-Based Buffer OverflowAllows remote code execution.
CVE-2023-34362Progress MOVEit TransferSQL InjectionEnables API access token abuse leading to remote code execution.
– CVE-2023-22515Atlassian Confluence Data Center and ServerBroken Access ControlAllows attackers to create administrator accounts and upload malicious plugins.
– CVE-2021-44228Apache Log4j2 (Log4Shell)Remote Code Execution (RCE)Allows attackers to take full control of a vulnerable system.
CVE-2023-2868Barracuda ESG ApplianceImproper Input ValidationAllows remote command execution.
CVE-2022-47966Zoho ManageEngine ProductsRemote Code ExecutionExploited via SAML endpoint to execute arbitrary code.
CVE-2023-27350PaperCut MF/NGImproper Access ControlAllows bypassing authentication and executing code.
CVE-2020-1472Microsoft NetlogonPrivilege EscalationAllows unauthorised users to establish vulnerable connections to domain controllers.
CVE-2023-42793JetBrains TeamCity ServersAuthentication BypassAllows remote code execution.
– CVE-2023-23397Microsoft Office OutlookPrivilege EscalationTriggered by specially crafted emails, even without user interaction.
CVE-2023-49103ownCloud graphapiInformation DisclosureAllows unauthenticated users to access sensitive data like admin passwords.

Additional Routinely Exploited Vulnerabilities

These additional vulnerabilities were also routinely targeted by malicious actors in 2023 and 2024:

CVEProductVulnerability Type
CVE-2023-22518Atlassian Confluence Data Center and ServerImproper Authorisation.
CVE-2023-29492Novi SurveyInsecure Deserialisation.
CVE-2021-27860FatPipe WARP, IPVPN, and MPVPNConfiguration Upload Exploit.
CVE-2021-40539Zoho ManageEngine ADSelfService PlusAuthentication Bypass.
CVE-2023-0669 Fortra GoAnywhere MFTRemote Code Execution.
CVE-2021-22986F5 BIG-IP and BIG-IQServer-Side Request Forgery (SSRF).
CVE-2019-0708Microsoft Remote Desktop ServicesRemote Code Execution.
CVE-2018-13379Fortinet FortiOS SSL-VPNPath Traversal.
CVE-2022-3236Sophos FirewallCode Injection.
CVE-2021-26084Atlassian ConfluenceOGNL Injection.
CVE-2022-26134Atlassian ConfluenceRemote Code Execution.
CVE-2023-38831WinRARCode Execution.
CVE-2021-33044Dahua ProductsAuthentication Bypass.
CVE-2019-11510Ivanti Pulse Connect SecureArbitrary File Read.

Key Takeaways: Cybercriminals targeted zero-day exploits incessantly. Pay attention to internet-reachable systems that are mission-critical in your organisation.

Why Business should Pay Attention?

Importance of Attention for Businesses According to the ACSC, malicious cyber actors exploit these vulnerabilities just as they become public. Hence, any organisation without patched systems on time has severe financial and reputational exposure.

  • Recent Attacks: Much of the assault against Australian businesses has taken place in sectors including government, healthcare, and finance.
  • Zero-Day Exploits: In 2023, the exploitation of zero-day vulnerabilities was greater than in years past, which shows the increasing proficiency of the cyber actors.

Mitigation Strategies for 2024

  • Centralised Patch Management: A centralised patch management system should be established to ensure that all systems receive up-to-date patches.
  • Endpoint Security: It should include endpoint detection and response (EDR) tools to enable early detection of suspicious activities.
  • Access Control: Multi-Factor Authentication must be enforced for all user accounts as part of access controls, especially on remote access systems and VPNs.
  • System Hardening: Hardening of systems refers to ensuring secure configurations, shutting down redundant ports, and eliminating default passwords.
  • Incident Response Plans: Systems should be tested regularly for incident response procedures to ensure prompt recovery in the event of an attack by cyber criminals.

Conclusion

In conclusion, the list of frequently exploited vulnerabilities in 2023 and 2024, monitoring, cyber hygiene, and timely patching are among the necessities for protecting companies. By taking action against these vulnerabilities and building resilience now, organisations can stand firm against hackers in 2024.

Connect now with ARANKISH for a specialised cyber security assessment or improve your patch management approaches.

Quick Links

Partner with the Expert Team Your Business Deserves.

Our dedicated professionals deliver tailored solutions to help your business thrive, ensuring you get the expertise and support you deserve every step of the way.

Talk To The ARANKISH Team

Feel free to reach out to us with your cyber security requirements or for a quotation. Our team will respond to you promptly.

What are you looking for?