CVE-2021-31955
A Windows kernel vulnerability allowed attackers to read kernel memory from user mode, exposing sensitive data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
A Windows kernel vulnerability allowed attackers to read kernel memory from user mode, exposing sensitive data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Enhanced Cryptographic Provider privilege escalation vulnerability (CVE-2021-31201) was actively exploited in the wild, allowing attackers to escalate privileges on affected systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Enhanced Cryptographic Provider privilege escalation vulnerability (CVE-2021-31199) was actively exploited in the wild, allowing attackers to escalate privileges on affected systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free flaw in Chromium's Indexed DB API allowed sandbox escapes after a renderer compromise, but required prior compromise and was not a zero-day.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An out-of-bounds write vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution flaw in Windows Media Center allowed attackers to execute arbitrary code via malicious .mcl files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Google Chromium WebGL allowed remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader suffered a use-after-free vulnerability allowing unauthenticated remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Microsoft Win32k was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer had a remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A buffer overflow in Microsoft IIS 6.0 on Windows Server 2003 R2 allowed remote attackers to execute code via a malformed PROPFIND request.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Hyper-V RemoteFX vGPU suffered an improper input validation flaw allowing authenticated guest users to execute remote code on the host.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server suffered a remote code execution vulnerability via deserialization of untrusted data that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution flaw in Windows' Adobe Font Manager Library allowed attackers to execute arbitrary code on systems running Windows 10 and earlier.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unspecified vulnerability in Oracle Solaris and ZFS was actively exploited in the wild, causing high impacts to confidentiality, integrity, and availability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authenticated admin on Ivanti Pulse Connect Secure could upload malicious archives to write arbitrary files via an unrestricted file upload flaw.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Pulse Connect Secure suffered a command injection vulnerability allowing remote authenticated users to execute arbitrary code via Windows File Resource Profiles.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Pulse Connect Secure suffered a buffer overflow allowing remote authenticated users to execute root code via malicious meeting rooms.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows kernel privilege escalation flaw allowed attackers to execute arbitrary code in kernel mode.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Small Business RV320 and RV325 routers suffered an information disclosure flaw allowing attackers to download router configurations and diagnostic data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google Chromium V8 allowed remote code execution inside a browser sandbox via a crafted HTML page.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote attacker could exploit heap corruption via a crafted HTML page in Google Chromium V8 to execute arbitrary code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Microsoft Office allowed remote code execution when processing rich text format files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A race condition in Google Chromium allows remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap buffer overflow in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader suffered a heap-based buffer overflow allowing unauthenticated remote code execution, a known critical flaw repeatedly exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Defender contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco HyperFlex HX installer VM had insufficient input validation allowing command execution as tomcat8 user.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco HyperFlex HX installer VM suffered a command injection flaw allowing root-level code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and OfficeScan servers suffered an authentication bypass allowing remote attackers to write data and bypass root login.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents had a content validation escape vulnerability allowing attackers to manipulate agent client components.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and OfficeScan suffered a remote code execution vulnerability in a migration tool component that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authenticated attacker could execute arbitrary code via uncontrolled gzip extraction in Ivanti Pulse Connect Secure.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authenticated attacker could upload a custom template to Pulse Connect Secure to perform code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix ADC/Gateway/SD-WAN appliances suffer an information disclosure flaw actively exploited in the wild, exposing sensitive data and undermining trust in a vendor with a recent history of critical RCE 0-days.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.