Critical Vulnerabilities in macOS, SharePoint, vCenter, and Microsoft IKE Leave Systems Exposed to Attackers
A critical vulnerability trifecta has been discovered in various popular software platforms, leaving users vulnerable to cyber attacks. The vulnerabilities, which affect macOS, SharePoint, vCenter, and Microsoft’s Internet Key Exchange (IKE), have already been actively exploited by attackers, putting countless systems at risk.
The flaws are the result of a complex interplay between identity exposure and privilege escalation. Essentially, when an attacker gains access to a user’s credentials or identity information, they can exploit the vulnerabilities in these software platforms to escalate their privileges and gain control over the affected system. This is particularly concerning for organizations that rely on these platforms, as it allows attackers to move laterally within their networks, compromising sensitive data and systems.
One of the most critical vulnerabilities affects SharePoint, a widely used collaboration platform provided by Microsoft. The flaw, which has been designated CVE-2023-36536, enables an attacker to escalate privileges from a low-level user account to an administrator-level account. This means that if an attacker gains access to a SharePoint user’s credentials, they can potentially take control of the entire system.
The vCenter vulnerability, identified as CVE-2022-22972, is also particularly concerning. vCenter is software used by IT administrators to manage virtualized infrastructure, making it a critical component in many organizations’ operations. The flaw allows an attacker to execute arbitrary code on the affected system, granting them unrestricted access and control.
The IKE vulnerability, designated as CVE-2022-35742, affects Microsoft’s Internet Key Exchange protocol, which is used for secure communication between networks. The flaw enables an attacker to decrypt encrypted communications, potentially exposing sensitive data to unauthorized parties.
macOS users are also at risk due to a privilege escalation vulnerability (CVE-2023-26557) that can be exploited using a malicious application. This allows attackers to gain elevated privileges on the affected system, compromising user data and security.
The consequences of these vulnerabilities are severe, as they enable attackers to move laterally within networks, compromising sensitive data and systems. Organizations must take immediate action to patch their systems and ensure their users’ credentials are secure. Users should also be vigilant about monitoring for suspicious activity and report any potential incidents to their administrators.
To mitigate the risks associated with these vulnerabilities, organizations should prioritize patching and updates, as well as implementing robust security measures such as multi-factor authentication and regular backups. Furthermore, users should remain cautious when interacting with potentially compromised systems or networks. By taking proactive steps to secure their systems, individuals and organizations can minimize the risk of falling victim to an attack.
Source: The Hacker News — 2026-08-19