【Security】Vulnerability warning: Major security vulnerabilities in VMware, Microsoft Exchange Server, WinRAR, Cisco firewall systems, and WordPress
Hello everyone:
Forward the National Institute of Cyber Security and TWCERT/CC vulnerability warning announcement. Please confirm and update or patch as soon as possible to reduce related information security risks.
1. VMware ESXi, Workstation, Fusion, and Tools updates address multiple vulnerabilities
■ VMware ESXi, Workstation, and Fusion
▲ The VMXNET3 virtual network interface card has an integer overflow vulnerability.
▲ VMCI has an integer underflow vulnerability that could result in an out-of-bounds write.
▲ The PVSCSI controller has a stack overflow vulnerability that could result in an out-of-bounds write.
■ Suggestions: Apply the patch according to the workaround released on the official website.
2. Microsoft Exchange Server has a major security vulnerability (CVE-2025-53786)
■ Microsoft has issued a critical security vulnerability advisory for its Exchange Server product (CVE-2025-53786, CVSS: 8.0). This vulnerability allows an attacker with administrator privileges to escalate privileges in a hybrid cloud-on-premises deployment. Currently, log monitoring tools in cloud environments are unable to record malicious activity related to this vulnerability.
■ A proof-of-concept (PoC) for this vulnerability was recently publicly demonstrated at the Black Hat conference in the United States, potentially accelerating subsequent exploitation by attackers. Microsoft has released security updates and temporary mitigations. It is recommended to implement these mitigations as soon as possible to prevent potential attacks targeting this vulnerability.
■ Suggestions: Patch according to the workaround provided on the official website.
3. WinRAR has a high-risk security vulnerability (CVE-2025-8088)
■ Researchers have discovered a path traversal vulnerability (CVE-2025-8088) in the Windows version of WinRAR. Unauthenticated remote attackers can exploit this vulnerability to create a malicious compressed file and send it via phishing emails. When the victim opens the compressed file, the malicious program is written to the startup folder and automatically executed at each boot. This vulnerability has been exploited by hackers. Please confirm and patch it as soon as possible.
■ Suggestions: Please update the Windows version of WinRAR to version 7.13 or later.
4. Cisco's firewall system has a critical security vulnerability (CVE-2025-20265)
■ Cisco Secure Firewall Management Center (FMC) is a centralized management platform for unified management and monitoring of Cisco firewall products, providing a complete threat defense perspective and supporting policy development, event analysis, traffic monitoring, and device configuration. Cisco has issued a critical security vulnerability advisory (CVE-2025-20265, CVSS: 10.0) and released an update. This vulnerability, when used for RADIUS authentication, allows an unauthenticated remote attacker to inject arbitrary shell commands and cause the device to execute.
■ Suggestions: Apply the patch according to the solution released on the official website.
5. WordPress recently announced 10 extension-related security vulnerabilities.
■ Most of these WordPress extension-related vulnerabilities could allow unauthenticated remote attackers to execute or delete files on the server. Please identify and patch them as soon as possible.
■ Detailed vulnerability information:
https://www.twcert.org.tw/tw/cp-169-10275-dd7a8-1.html
■ Suggestions: All of the above vulnerabilities pose a risk of remote code execution. Please identify and patch them as soon as possible.
6. Related Articles:
▲ https://www.twcert.org.tw/tw/cp-169-10250-08712-1.html
▲ https://www.twcert.org.tw/tw/cp-169-10316-60f9c-1.html
▲ https://www.nics.nat.gov.tw/core_business/information_security_information_sharing/Vulnerability_Alert_Announcements/48e8a6cd-3391-4465-8bce-cd0807fbfc8e/
▲ https://www.twcert.org.tw/tw/cp-169-10251-d9034-1.html
▲ https://www.twcert.org.tw/tw/cp-169-10275-dd7a8-1.html
For more question about information security, please directly consult with Computer Center, at rogeryu@mail.ntust.edu.tw or applechang@mail.ntust.edu.tw
