CVE-2017-0262
Microsoft Office contained a remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Microsoft Office contained a remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability allows attackers to escalate privileges via kernel-mode driver memory handling failures.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft HTTP.sys contained a remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Windows SAM local privilege escalation vulnerability allowed any user to read the SAM file and escalate to SYSTEM level if a Volume Shadow Copy was available.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A crafted .LNK file triggered remote code execution in Windows Shell, a flaw actively exploited in the wild and now on CISA's KEV list.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability (CVE-2022-21882) was actively exploited in the wild before patching.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Internet Explorer allowed remote attackers to execute code as the current user.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unauthenticated attacker could steal email traffic from Microsoft Exchange Server via CVE-2021-33766, a vulnerability actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Business Intelligence Enterprise Edition suffered a path traversal vulnerability allowing attackers to read arbitrary system files via the getPreviewImage function.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Remote attackers could execute arbitrary commands via serialized-object interfaces in IBM WebSphere Application Server and Server Hypervisor Edition.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Google Chrome's media component allowed remote code execution via a crafted HTML page and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Elastic Kibana's Timelion visualizer contained an arbitrary code execution flaw that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Attackers exploited a directory-traversal flaw in VMware vCenter's Syslog server to gain persistent remote access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's WinVerifyTrust function allowed remote code execution via flawed Authenticode signature verification.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
MongoDB mongo-express versions before 0.54.0 suffered a remote code execution flaw via the toBSON method.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
JBoss Seam 2 in Red Hat Linux allows remote code execution when the Java Security Manager is misconfigured, and the flaw is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A local user can bypass Excel security features to execute arbitrary code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader suffered a use-after-free vulnerability allowing unauthenticated remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Microsoft Win32k was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer had a remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authenticated admin on Ivanti Pulse Connect Secure could upload malicious archives to write arbitrary files via an unrestricted file upload flaw.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Pulse Connect Secure suffered a command injection vulnerability allowing remote authenticated users to execute arbitrary code via Windows File Resource Profiles.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Pulse Connect Secure suffered a buffer overflow allowing remote authenticated users to execute root code via malicious meeting rooms.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google Chromium V8 allowed remote code execution inside a browser sandbox via a crafted HTML page.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote attacker could exploit heap corruption via a crafted HTML page in Google Chromium V8 to execute arbitrary code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in Google Chromium Blink allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A race condition in Google Chromium allows remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap buffer overflow in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader suffered a heap-based buffer overflow allowing unauthenticated remote code execution, a known critical flaw repeatedly exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Defender contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco HyperFlex HX installer VM had insufficient input validation allowing command execution as tomcat8 user.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco HyperFlex HX installer VM suffered a command injection flaw allowing root-level code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and OfficeScan servers suffered an authentication bypass allowing remote attackers to write data and bypass root login.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents had a content validation escape vulnerability allowing attackers to manipulate agent client components.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and OfficeScan suffered a remote code execution vulnerability in a migration tool component that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authenticated attacker could execute arbitrary code via uncontrolled gzip extraction in Ivanti Pulse Connect Secure.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.