Site navigation

Top Most Exploited Vulnerabilities of 2022

Elizabeth Greenberg

,

vulnerabilities
National cybersecurity agencies have revealed the most exploited vulnerabilities of 2022. 

Malicious actors in 2022 tended to target older vulnerabilities more frequently than recently disclosed ones, and had a penchant for targeting unpatched, internet-facing systems, according to a new release.

Members of the Five Eyes Alliance, including the National Cyber Security Centres (NCSC) in the UK, as well as the American, New Zealand, Australian, and Canadian equivalents, released the top 12 most routinely exploited cybersecurity vulnerabilities of 2022.

The report explores the Common Vulnerabilities and Exposures (CVEs) of 2022, along with their associated Common Weakness Enumerations (CWE).

According to the report, malicious actors tend to have more success exploiting known vulnerabilities in the first two years of public-disclosure, as the value of such weaknesses decreases as software is patched or upgraded.

Threat actors are likely to prioritise exploiting severe and globally prevalent CVEs, the report said, because developing tools to exploit these critical, wide-spread, and known vulnerabilities gives them a low-cost, high-impact tools they can use continually for years to come.

Top 12 Exploited Vulnerabilities of 2022

  • CVE-2018013379. This vulnerability, affecting Fortinet SSL VPNs, was also exploited in 2020 and 2021. The continued exploitation indiciates that many organisations failed to patch software in a timely manner and remain vulnerable to malicious cyber actors.
  • CVE-2021-34473, CVE-2021-31207, CVE-2021-34523. These vulnerabilities, known as ProxyShell, affect Microsoft Exchange email servers, and typically reside within the Microsoft Client Access Service (CAS). CAS is commonly exposed to the internet to enable users to access their email via mobile devices and web browsers.
  • CVE-2021-40539. This vulnerability enabled unauthenticated remote code execution (RCE) in Zoho ManageEngine ADSelfService Plus and was linked to the usage of outdated third-party dependency. Initially this was exploited in 2021, and continued throughout 2022.
  • CVE-2021-26084. Atlassian Confluence Server and Data Centre, a web-based collaboration tool used by governments and private companies, was exploited by this vulnerability which could enable an unauthenticated cyber actor to execute arbitrary code on vulnerable systems. This vulnerability quickly became one of the most routinely exploited vulnerabilities after a Proof of Concept (PoC) code was released within a week of its disclosure.
  • CVE-2021-44228. Known as Log4Shell, this vulnerability affects Apache’s Log4j library, an open-source logging framework incorporated into thousands of products worldwide. An actor can exploit this vulnerability by submitting a specially crafted request to a vulnerable system, causing the execution of arbitrary code. The request allows a cyber actor to take full control of a system. The actor can then steal information, launch ransomware, or conduct other malicious activity. Threat actors continues exploiting the vulnerability throughout the first half of 2022 after it was disclosed in December 2021.
  • CVE-2022-22954, CVE-2022-22960. These vulnerabilities allow RCE, privilege escalation, and authentication bypass in VMware Workspace ONE Access, Identity Manager, and other VMware products. A malicious cyber actor with network access could trigger a server-side template injection that may result in remote code execution.
  • CVE-2022-1388. This vulnerability allows unauthenticated malicious cyber actors to bypass iControl REST authentication on F5 BIG-IP application delivery and security software. It allows threat actors to create and execute arbitrary system commands.
  • CVE-2022-30190. This vulnerability impacts the Microsoft Support Diagnostic Tool (MSDT) in Windows. A remote, unauthenticated cyber actor could exploit this vulnerability to take control of an affected system.
  • CVE-2022-26134. This critical RCE vulnerability affects Atlassian Confluence and Data Centre. It was likely exploited as a zero-day before public disclosure in June 2022, and is related to an older Confluence vulnerability which was also exploited in 2022.

The report also included 30 more routinely exploited vulnerabilities, alongside mitigation advice to help organisations and software developers reduce the risk of compromise.


Recommended


Mitigations

The authoring agencies of the report recommended several mitigation efforts for vendors and developers to ensure their products are secure by design.

Identifying repeatedly exploited classes of vulnerability can be key in understanding what products and software needs to be most protected.

Further, the agencies say that business leaders should ensure that proactive steps to eliminate entire classes of security vulnerabilities, rather than only making one-off patches when new vulnerabilities are discovered.

Besides following security-by-design protocols, companies should also prioritise secure-by-default configurations, such as eliminating default passwords, implementing single sign on (SSO) technology via modern open standards, and providing high-quality audit logs to customers with no additional configuration and at no extra charge.

End-User Organisations

The report also provided guidance for end-user companies to keep more secure against threat actors, including some baseline advice like updating software, routinely preforming automated asset discovery, implementing a robust patch management process, regularly and securely backing up the system, and maintaining an updated cybersecurity incident response plan.

Other mitigation efforts include enforcing multifactor authentication, reviewing privileged accounts, and implementing zero trust network architecture.

UK organisations are also encouraged to sign up for the NCSC’s Early Warning service to receive alerts about potential issues, including vulnerabilities, affecting their networks.

Jonathon Ellison, NCSC director of resilience and future technology, said: “Vulnerabilities are sadly part and parcel of our online world and we see threat actors continue to take advantage of these weaknesses to compromise systems.

“This joint advisory with our allies raises awareness of the most routinely exploited vulnerabilities in 2022 to help organisations identify where they might be at risk and take action.

“To bolster resilience, we encourage organisations to apply all security updates promptly and call on software vendors to ensure security is at the core of their product design to help shift the burden of responsibility away from consumers.”

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data