CISA Warns of Exploited HPE OneView and Microsoft Office Vulnerabilities
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
CISA has recently flagged two significant vulnerabilities in its Known Exploited Vulnerabilities catalog. The first, CVE-2025-37164, is a code injection vulnerability in HPE’s OneView management software, which is used for managing servers, storage, and networking equipment. This vulnerability has a perfect CVSS score of 10.0 and can allow attackers to inject and execute code, potentially granting them full control over affected environments.
HPE disclosed this flaw in a December 18 advisory, but did not confirm whether attacks were already occurring. However, CISA’s inclusion of this vulnerability in its exploited-in-the-wild catalog suggests that active exploitation is now happening. Security firms had previously warned that the availability of a proof-of-concept exploit would likely lead to real-world attacks.
The second vulnerability, CVE-2009-0556, is a PowerPoint code injection flaw that has been known since 2009 and carries a CVSS score of 8.8. This vulnerability allows remote attackers to execute arbitrary code via memory corruption when a user opens a specially crafted PowerPoint file. Although Microsoft patched this issue as part of MS09-017, its presence in the KEV catalog indicates that unpatched or unsupported systems are still being targeted.
These vulnerabilities highlight the ongoing risks associated with both new and old software flaws. While CVE-2025-37164 is a recent critical vulnerability, CVE-2009-0556 serves as a reminder that outdated vulnerabilities can still pose significant threats if systems are not properly updated.
Implications for Users and Organizations
Organizations using HPE OneView should prioritize patching this critical vulnerability to prevent potential exploitation. The risk of full control over server environments is significant, especially in enterprise settings where sensitive data may be managed.
For users of Microsoft Office, it is crucial to ensure that all software is updated to the latest versions to mitigate risks associated with older vulnerabilities like CVE-2009-0556. Unpatched systems can be easily targeted by attackers using known exploits.
Both vulnerabilities underscore the importance of maintaining a proactive security posture. Regularly updating software and monitoring for vulnerabilities can help organizations defend against potential breaches.
Key Takeaways
- Update HPE OneView software immediately to address CVE-2025-37164 and prevent exploitation.
- Ensure Microsoft Office is updated to the latest version to mitigate risks from CVE-2009-0556.
- Regularly review and patch all software to protect against known vulnerabilities.
- Monitor systems for unusual activity that may indicate exploitation attempts.
- Educate employees about the risks of opening untrusted files, especially in PowerPoint format.
Key Terms & Concepts
- CVE-2025-37164: In this article, CVE-2025-37164 refers to a critical code injection vulnerability in HPE OneView that allows attackers to execute code.
- CVE-2009-0556: CVE-2009-0556 is a PowerPoint code injection vulnerability that enables remote code execution when a malicious PowerPoint file is opened.
- CVSS: CVSS stands for Common Vulnerability Scoring System, which rates the severity of vulnerabilities on a scale from 0 to 10.
- HPE OneView: HPE OneView is management software used for controlling servers, storage, and networking equipment from a central console.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.