CVE-2012-2539
A remote code execution flaw in Microsoft Word allowed attackers to execute arbitrary code via crafted RTF data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
A remote code execution flaw in Microsoft Word allowed attackers to execute arbitrary code via crafted RTF data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Java SE shipped with default configurations allowing sandbox bypass via untrusted applets, enabling arbitrary code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Juniper Junos OS path traversal flaw in J-Web and related services allows unauthenticated remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle BI Publisher had an authentication bypass vulnerability that allowed unauthorized access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware SD-WAN Edge suffered a command injection flaw in its local web UI allowing remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Elasticsearch's dynamic scripting feature allowed remote attackers to execute arbitrary MVEL and Java code, a flaw listed in CISA's KEV catalog.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched use-after-free vulnerability in Adobe Flash Player allowed remote code execution, exploited in the wild after Flash reached end-of-life in 2020.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution vulnerability in the Microsoft Scripting Engine of Internet Explorer allowed attackers to execute arbitrary code on affected systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Shell remote code execution vulnerability allows attackers to execute arbitrary code via improper file path validation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XR BGP allows remote attackers to cause a denial-of-service attack.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A path traversal flaw in VMware Tanzu Spring Cloud Config allowed attackers to serve arbitrary files, leading to potential data exposure and compliance violations.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS and IOS XE suffered a remote code execution vulnerability in the Cluster Management Protocol allowing unauthenticated attackers to execute elevated code or reload devices.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler and XenMobile Server management interfaces allowed unauthenticated remote attackers to execute arbitrary code as root.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft GDI remote code execution vulnerability allowed attackers to take control of affected systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS XR BGP allows remote attackers to cause a denial-of-service attack.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ACS suffered an unpatched Java deserialization vulnerability allowing remote command execution, now on CISA's KEV list.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix SD-WAN and NetScaler suffered a SQL injection vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix SD-WAN and NetScaler suffered an authenticated command injection flaw that allowed attackers to execute arbitrary commands on the devices.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's end-of-life status left unpatched RCE vulnerabilities perpetually exploitable, exemplifying the catastrophic risk of shipping and maintaining obsolete software.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A 2014 OLE automation array RCE in Windows was actively exploited in the wild and remains in CISA's KEV catalog.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Prime DCNM allowed remote attackers to read arbitrary files via a directory traversal flaw in its fmserver servlet.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Elasticsearch's Groovy scripting engine allowed remote attackers to bypass sandbox protections and execute arbitrary shell commands.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft KDC allows remote authenticated users to escalate to domain admin via privilege escalation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Reader and Acrobat contained a stack-based buffer overflow allowing remote attackers to execute arbitrary code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco VPN routers had an unauthenticated remote code execution flaw in their web interface allowing attackers full system control.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Windows Win32k was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Attackers exploited an unpatched SSRF vulnerability in VMware vCenter Server to gain persistent remote access and deploy backdoors.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authentication bypass in Adobe ColdFusion allowed unauthorized administrative access, later linked to CVSS 10.0 command and eval injection flaws.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion suffered a directory traversal vulnerability allowing unauthorized access to restricted directories.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion suffered from critical unpatched command injection and eval injection flaws enabling remote code execution and privilege escalation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A 2002 Windows privilege escalation flaw in smss.exe allowed local users to gain SYSTEM privileges without proper authentication.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A 20-year-old Windows privilege escalation flaw in the POSIX subsystem allows local users to gain full system control.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle VirtualBox's VBoxDrv.sys driver had an input validation flaw allowing local arbitrary code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A 2009 Windows kernel privilege escalation flaw was actively exploited in the wild for years before patching.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution vulnerability in Microsoft Excel allows attackers to execute arbitrary code via a malicious spreadsheet file.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A 2010 Windows kernel flaw allowed local privilege escalation via unvalidated BIOS calls when 16-bit app support was enabled.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A stack-based buffer overflow in Microsoft Office's RTF parser allowed remote code execution, and it was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched remote code execution vulnerability (CVE-2011-0611) remains actively exploited in the wild despite the product's end-of-life in 2020.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution flaw in Microsoft Forefront TMG's Winsock provider allowed attackers to execute code in the client application's security context.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Java SE JRE had an access control flaw in the Rhino Script Engine allowing remote arbitrary code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.