CVE-2022-26923
Authenticated users could exploit a Microsoft Active Directory Domain Services (AD DS) vulnerability for privilege escalation to SYSTEM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Authenticated users could exploit a Microsoft Active Directory Domain Services (AD DS) vulnerability for privilege escalation to SYSTEM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Palo Alto Networks PAN-OS vulnerability allowed for chained remote code execution, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium Intents CVE-2022-2856 allows remote code execution via malicious HTML pages
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP's NetWeaver products exploited for HTTP request smuggling
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CVE-2022-21971: Microsoft Windows Runtime RCE actively exploited
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allows remote code execution via specially crafted URLs, actively exploited in the wild and impacting CMMC compliance efforts.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to escalate privileges to SYSTEM, actively exploited in the wild and impacting DIB organizations using Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to spoof authentication, potentially granting them unauthorized access to domain resources using NTLM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Red Hat Polkit vulnerability allowed privilege escalation, actively exploited in the wild, impacting systems relying on it for authorization.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Chromium PopupBlocker vulnerability allowed attackers to bypass navigation restrictions via crafted iframes, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A SQL injection vulnerability in SAP NetWeaver allowed attackers to execute arbitrary SQL commands remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver's unrestricted file upload vulnerability allows attackers to upload arbitrary files, potentially leading to system compromise and data exfiltration.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver allowed attackers to steal user information via HTTP requests, and remains actively exploited despite being years old.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption vulnerability in Adobe Reader and Acrobat allowed for potential remote code execution and denial-of-service attacks, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A flaw in Windows' signature verification allowed attackers to execute code via a user-assisted exploit, and it's currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A crafted PDF file can trigger remote code execution in Adobe Acrobat and Reader due to a use-after-free vulnerability, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's memory corruption vulnerability (CVE-2012-0754) allows for remote code execution and remains unpatched due to the product's end-of-life status.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A design flaw in Adobe Acrobat and Reader allowed silent, arbitrary printing of specially crafted files, marking it as an actively exploited vulnerability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player, now end-of-life, contained an unspecified vulnerability allowing remote code execution and denial-of-service attacks, and is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player, now end-of-life, contains a cross-site scripting vulnerability actively exploited in the wild, posing a significant risk to systems still running it despite its discontinuation and lack of updates.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A decade-old Microsoft XML Core Services vulnerability is actively exploited, enabling remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A buffer overflow in Adobe Acrobat and Reader allowed attackers to execute code remotely, actively exploited in the wild and impacting DIB organizations using these products.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft PowerPoint buffer overflow vulnerability allows for remote code execution and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in Adobe Acrobat and Reader allowed attackers to execute code remotely via malicious 3D files, actively exploited in the wild and impacting DIB organizations reliant on these tools for document handling.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Internet Explorer use-after-free vulnerability allows remote code execution via a crafted website, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An integer overflow in Adobe Flash Player allowed remote code execution, and its end-of-life status means no patches exist for this vulnerability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Chromium V8 out-of-bounds memory vulnerability enabled remote code execution in multiple browsers, including those used within the DIB, and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Chromium V8 vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers and potentially DIB organizations using them for web access or internal tools.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Chromium V8 out-of-bounds write vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers including Chrome and Edge, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via a crafted HTML page.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A 2009 Microsoft Office buffer overflow flaw allowed remote attackers to execute code via crafted Word documents.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A buffer overflow in Adobe Acrobat and Reader allowed remote attackers to execute code via malicious PDF files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched memory corruption vulnerability allowed remote attackers to execute code, a critical flaw in an end-of-life product that remains a perpetual security liability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A malformed object pointer vulnerability in Microsoft Word allowed remote code execution and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Office buffer overflow vulnerability allows remote code execution via crafted PNG files, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A malformed Excel file could trigger remote code execution in Microsoft Office via an object record corruption flaw.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco RV Series routers had a remotely exploitable deserialization vulnerability allowing code execution with root privileges, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unpatched Adobe Acrobat/Reader and Flash Player RCE vulnerabilities were actively exploited in the wild, enabling remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.