CISA Flags Microsoft Office and HPE OneView Bugs as Actively Exploited
好的,我现在需要帮用户总结这篇文章的内容,控制在100个字以内。首先,我得仔细阅读文章,理解主要信息。 文章讲的是美国网络安全和基础设施安全局(CISA)将两个安全漏洞加入到了已知被利用的漏洞目录中。这两个漏洞分别影响了微软的Office和HPE的OneView。具体来说,CVE-2009-0556是一个代码注入漏洞,CVSS评分8.8;CVE-2025-37164评分10.0,影响所有旧版本的OneView,并且已经发布了PoC。HPE提供了热修复补丁,但攻击范围尚不清楚。CISA要求联邦机构在2026年1月28日前修复。 接下来,我需要提取关键点:CISA新增两个漏洞到KEV目录,分别影响微软Office和HPE OneView,评分高,存在PoC,HPE提供补丁,攻击来源不明,要求修复时间。 然后把这些信息浓缩到100字以内。注意不要用“文章内容总结”这样的开头,直接描述内容。 可能的结构是:CISA新增两个漏洞到目录中,分别影响微软Office和HPE OneView,评分高且有PoC存在。HPE提供补丁但攻击来源不明。要求机构在特定日期前修复。 最后检查字数是否符合要求,并确保信息准确无误。 </think> 美国网络安全机构CISA将两个高危漏洞加入已知被利用列表中,涉及微软Office和HPE OneView,均存在远程代码执行风险,其中HPE漏洞已发布概念验证代码,建议用户尽快更新补丁以应对潜在威胁。 2026-1-8 04:52:0 Author: thehackernews.com(查看原文) 阅读量:2 收藏

Vulnerability / KEV Catalog

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added two security flaws impacting Microsoft Office and Hewlett Packard Enterprise (HPE) OneView to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerabilities are listed below -

  • CVE-2009-0556 (CVSS score: 8.8) - A code injection vulnerability in Microsoft Office PowerPoint that allows remote attackers to execute arbitrary code by means of memory corruption
  • CVE-2025-37164 (CVSS score: 10.0) - A code injection vulnerability in HPW OneView that allows a remote unauthenticated user to perform remote code execution

Details of CVE-2025-37164 emerged last month when HPE said the vulnerability impacts all versions of the software prior to version 11.00. The company also made available hotfixes for OneView versions 5.20 through 10.

Cybersecurity

The scope and source of the attacks targeting the two flaws is presently unclear, and there appear to be no public reports referencing their exploitation in the wild. However, a report from eSentire on December 23, 2025, revealed the release of a detailed proof-of-concept (PoC) exploit for CVE-2025-37164.

"Public availability of PoC exploit code significantly increases the risk to organizations running affected versions of the application," eSentire said. "As the vulnerability impacts all versions prior to 11.0, organizations are strongly advised to apply the required updates to mitigate the potential risk of exploitation."

Pursuant to Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies are recommended to apply the necessary fixes by January 28, 2026, to secure their networks against active threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/01/cisa-flags-microsoft-office-and-hpe.html
如有侵权请联系:admin#unsafe.sh