For those involved in SOC/security operations, we have provided explanations + countermeasures based on the "Known Exploited Vulnerbilities Catalog", which publishes public information by the Cybersecurity and Infrastructure Security Agency (CISA) about the most recent vulnerabilities of interest. Please take advantage of this to reduce the operational burden while visualizing and prioritizing risks.
What is Known Exploited Vulnerabilities Catalog?
The Known Exploited Vulnerabilities (KEV) Catalog is a list of "Vulnerabilities Confirmed to Have Actually Exploited" published by CISA. Therefore, it can be used as a criterion for quickly responding to vulnerabilities that are actually used in cyberattacks.
Overview of each vulnerability and how to address it
CVE-2025-54253
Product/Scope of Influence Adobe Experience Manager (AEM) Forms
Target version: 6.5.23 and earlier
Overview/Key Points
This is a serious vulnerability due to "Invalid Authorization (CWE-863)" in Adobe Experience Manager.
Incorrect access control settings can bypass authentication and allow arbitrary code execution. An attacker can take over the system and execute arbitrary code without user interaction.
The CVSS 3.1 score is the highest at 10.0 (Critical), indicating a broad range of impact.
Points to Deal with
Apply the update to the latest patch published by Adobe (6.5.0-0108 or later) as soon as possible. For details on what to do before the update and how to update, please refer to this official documentation.
CVE-2025-59230
Product/Scope of Influence for Microsoft Windows
All Windows servers/clients, including the Remote Access Connection Manager (RasMan) service, may be affected.
Overview/Key Points
This vulnerability allows an attacker to escalate privileges in a local environment due to "improper access control (CWE-284)".
Authenticated users can take over system privileges, which can be exploited to spread internal compromises.
The CVSS 3.1 score is 7.8 (High).
Points to Deal with
Use this official guidance to apply the latest security patches as soon as possible.
CVE-2025-24990
Product/Scope of Influence Agere Modem
Driver (ltmdm64.sys) that comes standard with Windows OS
Affects both Windows Server and client.
Overview/Key Points
An "untrusted pointer reference (CWE-822)" vulnerability that allows privilege escalation.
Microsoft has identified issues caused by third-party Agere Modem drivers and removed them in the October 2025 cumulative update. As a result, the fax modem hardware will no longer be available, so you need to be careful about the operating effects on the dependent system.
The CVSS 3.1 score is 7.8 (High).
Points to Deal with
Use this official guidance to apply the latest security patches as soon as possible.
CVE-2025-61884
Product/Scope of Influence Oracle E-Business Suite
Target Component: Oracle Configurator (Runtime UI)
Target versions: 12.2.3 to 12.2.14
Overview/Key Points
Oracle Configurator の Runtime UI
An information disclosure vulnerability in a component due to an authentication-free access control failure.
An attacker could gain unauthenticated access to the system via HTTP and obtain sensitive data (configuration and configuration information) within the Configurator. The CVSS 3.1 score is 7.5 (High).
Points to Deal with
Apply the October 2025 Critical Patch Update (CPU) patch provided by Oracle.
What Colorkrew can help Colorkrew can help ColorkrewSecurity provides SOC services that support attack detection and CSIRT response to vulnerabilities such as the above.
If you have any requests such as "I want to reduce the operational burden" or "I want to quickly detect cyber attacks", please feel free to contact us. Let's strengthen your company's security operations together.