CVE-2023-29360
Microsoft Streaming Service allows local privilege escalation to SYSTEM via untrusted pointer dereference.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Microsoft Streaming Service allows local privilege escalation to SYSTEM via untrusted pointer dereference.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server is actively exploited via CVE-2024-21410, enabling privilege escalation and ransomware entry.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows SmartScreen bypass allows code injection and potential execution, enabling attackers to circumvent a core security feature.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Type Confusion Vulnerability allows remote code execution via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server was exploited in the wild via CVE-2023-34048, enabling remote code execution through an out-of-bounds write in the DCERPC protocol.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC/Gateway buffer overflow vulnerability (CVE-2023-6549) allows denial-of-service in VPN/AAA configurations and is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC/Gateway allows authenticated remote code execution on management interfaces via CVE-2023-6548, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 engine contains an out-of-bounds memory access vulnerability that allows remote attackers to exploit heap corruption via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium WebRTC suffered a heap buffer overflow vulnerability (CVE-2023-7024) actively exploited in the wild via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Google Skia integer overflow vulnerability allowed sandbox escape via a malicious file, actively exploited in the wild and impacting Chrome, ChromeOS, Android, and Flutter products.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows MOTW security feature bypass vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Fusion Middleware WLS Core Components RCE vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows DWM Core Library privilege escalation vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Cloud Files Mini Filter Driver privilege escalation vulnerability allows SYSTEM privilege gain.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Juniper Junos OS SRX Series missing authentication for critical function allows file upload via J-Web.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Juniper Junos OS SRX Series missing authentication for critical function allows file upload via J-Web.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Juniper Junos OS PHP External Variable Modification Vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Juniper Junos OS EX Series PHP External Variable Modification Vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Juniper Junos OS EX Series missing authentication for critical function allows arbitrary file upload.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XE Web UI Command Injection Vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XE Web UI privilege escalation vulnerability allows remote, unauthenticated attackers to gain control of devices.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader Use-After-Free Vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS and IOS XE Group Encrypted Transport VPN out-of-bounds write vulnerability allows remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft WordPad info disclosure vulnerability exploited in the wild
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Skype for Business privilege escalation vulnerability allows for remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows CNG Key Isolation Service privilege escalation vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium libvpx heap buffer overflow allows remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Red Hat JBoss RichFaces Framework Expression Language Injection Vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and Worry-Free Business Security remote code execution vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader out-of-bounds write vulnerability allows code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap-based buffer overflow in Google Chromium's WebP codec is actively being exploited in the wild, potentially allowing attackers to write out-of-bounds memory and compromise systems using the codec.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Streaming Service Proxy vulnerability allows privilege escalation, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Word's information disclosure vulnerability (CVE-2023-36761) is actively exploited, potentially exposing sensitive data to attackers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's deserialization vulnerability (CVE-2023-26359) allows for code execution, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix ShareFile allowed unauthenticated attackers to remotely compromise customer storage zones due to improper access controls, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft .NET Core and Visual Studio have a denial-of-service vulnerability actively exploited in the wild, impacting DIB organizations using these tools for development and deployment.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authenticated administrator of Ivanti Endpoint Manager Mobile (EPMM) can write malicious files to the server via a path traversal vulnerability, potentially bypassing access controls and enabling further compromise.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's improper access control vulnerability allows security feature bypass, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's improper access control vulnerability allows security feature bypass, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.