CyberzSOC

Publication detail
← Back to advisories & guidance

#StopRansomware: Ghost (Cring) Ransomware ↗ source

February 19, 2025 CISA Advisory
Co-sealed by: CISA, FBI, MS-ISAC

Summary

Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Ghost

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2010-2861 9.8 Critical Adobe ColdFusion A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
CVE-2019-0604 9.8 Critical Microsoft SharePoint Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run re…
CVE-2018-13379 9.1 Critical Fortinet FortiOS Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system fil…
CVE-2021-34473 9.1 Critical Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
CVE-2021-34523 9.0 Critical Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
CVE-2014-1812 8.8 High Microsoft Windows Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Gr…
CVE-2017-0143 8.8 High Microsoft Windows Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
CVE-2017-0144 8.8 High Microsoft SMBv1 The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
CVE-2021-31207 6.6 Medium Microsoft Exchange Server Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
CVE-2009-3960 6.5 Medium Adobe BlazeDS Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
CVE-2020-1472 5.5 Medium Microsoft Netlogon Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secur…

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.