CVE-2018-8589
Microsoft Win32k privilege escalation flaw allowed local system-level remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Microsoft Win32k privilege escalation flaw allowed local system-level remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Windows kernel privilege escalation flaw allowed attackers to gain elevated permissions and execute arbitrary code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local privilege escalation flaw in Windows splwow64.exe allowed attackers to elevate from low to medium integrity, enabling further system compromise.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Chrome Blink allowed out-of-bounds memory access via a crafted HTML page and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XR software health check opens TCP port 6379 by default, allowing attackers to access the Redis instance running within the NOSi container.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Spring Cloud Gateway allows code injection via its exposed and unsecured Actuator endpoint when enabled.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Internet Explorer allowed remote attackers to execute code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Microsoft Win32k was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in the Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges on unpatched systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability (CVE-2021-41357) allows attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability (CVE-2021-40450) was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows Print Spooler privilege escalation vulnerability (CVE-2022-22718) was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Workspace ONE Access, Identity Manager, and vRealize Automation suffered a privilege escalation vulnerability due to improper permissions in support scripts.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status left it perpetually unpatched.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched heap-based buffer overflow allowed remote attackers to execute code, proving that end-of-life software remains a perpetual security liability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, a flaw that persisted after the product's end-of-life in 2020.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched RCE vulnerability remains a perpetual liability after its December 2020 end-of-life.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's use-after-free vulnerability allowed remote attackers to execute arbitrary code, and the product's end-of-life status meant it remained perpetually unpatched and exploitable.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Internet Explorer allowed remote code execution and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched stack-based buffer overflow allowed remote code execution, proving that end-of-life software remains a perpetual liability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local privilege escalation vulnerability in Google Pixel devices was actively exploited in the wild, highlighting the risks of unpatched hardware in defense supply chains.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's http.sys HTTP protocol stack contained a remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Spring Framework apps on JDK 9+ suffered remote code execution via data binding.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in the Windows User Profile Service was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex Central allowed remote code execution via an arbitrary file upload flaw.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local privilege escalation vulnerability in the Windows kernel allowed attackers to gain elevated access without remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Internet Explorer's JScript engine allowed remote attackers to execute arbitrary code via a malicious website.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution vulnerability in Microsoft Office allowed attackers to execute arbitrary code via a crafted document.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local privilege escalation vulnerability in Windows allows attackers to bypass UAC and gain system access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution flaw in Microsoft Word allowed attackers to execute arbitrary code via crafted RTF data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local privilege escalation vulnerability in Microsoft's Win32k.sys allowed attackers to escalate privileges via a pointer initialization flaw.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Java SE shipped with default configurations allowing sandbox bypass via untrusted applets, enabling arbitrary code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution flaw in Windows' Adobe Type Manager Library allowed attackers to execute arbitrary code via specially crafted OpenType fonts.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Local privilege escalation via improper input validation in Microsoft's Ancillary Function Driver (afd.sys).
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched memory corruption flaw allowed remote code execution and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Windows Event Tracing was actively exploited in the wild, allowing attackers to escalate privileges without requiring remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.