CVE-2014-4123
An unpatched privilege escalation flaw in Microsoft Internet Explorer allowed remote attackers to gain elevated privileges via a crafted website.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
An unpatched privilege escalation flaw in Microsoft Internet Explorer allowed remote attackers to gain elevated privileges via a crafted website.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution vulnerability in Windows kernel-mode drivers handling TrueType fonts was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unspecified vulnerability in Oracle's Java Runtime Environment (JRE) was actively exploited in the wild, affecting confidentiality, integrity, and availability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Internet Explorer allowed remote attackers to gain elevated privileges via a crafted website.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local privilege escalation flaw in Windows GDI allowed attackers to gain elevated access via a crafted application.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Windows kernel privilege escalation vulnerability (CVE-2018-8611) was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An information disclosure vulnerability in Internet Explorer allowed attackers to detect specific files on a user's computer.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An information disclosure vulnerability in Internet Explorer's Messaging API allowed attackers to test for file presence on disk.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA's SNMP code had a buffer overflow allowing remote code execution or system reloads.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA CLI parser flaw allowed authenticated local attackers to cause DoS or execute code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An information disclosure flaw in Microsoft XML Core Services allowed attackers to test for files on disk via a crafted website.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Internet Explorer allowed remote attackers to execute code or cause denial-of-service via a crafted website.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Internet Explorer's cross-domain policy enforcement flaw allowed attackers to escalate privileges and access sensitive data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows Search vulnerability allowed remote attackers to execute arbitrary code and take full control of affected systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer had an information disclosure vulnerability allowing attackers to test for file presence on disk.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Chrome Blink allowed out-of-bounds memory access via a crafted HTML page and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XR software health check opens TCP port 6379 by default, allowing attackers to access the Redis instance running within the NOSi container.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Google Chrome's WebAudio component allowed remote attackers to exploit heap corruption via a crafted HTML page.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Windows kernel privilege escalation flaw allowed attackers to gain elevated permissions and execute arbitrary code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local privilege escalation flaw in Windows splwow64.exe allowed attackers to elevate from low to medium integrity, enabling further system compromise.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation flaw allowed local system-level remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows SMB server leaked data via CVE-2019-0703, an unpatched flaw actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Spring Cloud Gateway allows code injection via its exposed and unsecured Actuator endpoint when enabled.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Microsoft Win32k was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Internet Explorer allowed remote attackers to execute code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in the Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges on unpatched systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability (CVE-2021-41357) allows attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability (CVE-2021-40450) was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows Print Spooler privilege escalation vulnerability (CVE-2022-22718) was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Workspace ONE Access, Identity Manager, and vRealize Automation suffered a privilege escalation vulnerability due to improper permissions in support scripts.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched RCE vulnerability remains a perpetual liability after its December 2020 end-of-life.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status meant it remained perpetually unpatched and exploitable.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, a flaw that persisted after the product's end-of-life in 2020.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched heap-based buffer overflow allowed remote attackers to execute code, proving that end-of-life software remains a perpetual security liability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Internet Explorer allowed remote code execution and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status left it perpetually unpatched.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.