CVE-2023-38203
Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Qlik Sense path traversal flaw lets unauthenticated attackers create anonymous sessions to hit unauthorized endpoints.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Qlik Sense HTTP tunneling vulnerability allows privilege escalation and arbitrary HTTP requests on the backend server.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC and Gateway suffered a critical buffer overflow vulnerability that was actively exploited in the wild and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA and Firepower Threat Defense suffered an unpatched unauthorized access vulnerability allowing remote brute-force attacks and clientless SSL VPN sessions.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Sentry's insufficiently restrictive Apache HTTPD configuration allowed attackers to bypass authentication controls on its administrative interface.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager Mobile suffered an authentication bypass allowing unauthenticated access to PII and device configuration.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC and Gateway suffered an unauthenticated remote code execution vulnerability that was actively exploited in the wild and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows Search vulnerability allowed attackers to bypass MOTW protections and execute remote code via malicious files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows privilege escalation flaw allowed attackers to run elevated processes, directly enabling ransomware campaigns.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An attacker can bypass Windows SmartScreen's Mark of the Web defenses using a specially crafted malicious file.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A YAML deserialization flaw in IBM Aspera Faspex allowed remote attackers to execute code, leading to ransomware-linked incidents.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched privilege escalation flaw in the Windows CLFS driver was actively exploited in the wild to enable ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unauthenticated attacker could compromise Oracle E-Business Suite via an unspecified vulnerability in Oracle Web Applications Desktop Integrator.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server privilege escalation vulnerability (CVE-2022-41080) chainable with RCE CVE-2022-41082 enables full system compromise.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A bypass vulnerability in Microsoft Defender SmartScreen allowed attackers to evade Mark of the Web protections via a crafted malicious file.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows Print Spooler flaw allowed attackers to escalate privileges to SYSTEM, directly enabling ransomware deployments.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched bypass in Windows' Mark of the Web feature allowed ransomware actors to evade security controls and execute malicious code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco AnyConnect's IPC channel allowed attackers with valid Windows credentials to execute SYSTEM-level code via DLL hijacking.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco AnyConnect for Windows mishandles directory paths, allowing attackers with valid credentials to copy malicious files to arbitrary locations with system-level privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server's ProxyNotShell SSRF vulnerability, when chained with CVE-2022-41082, enables remote code execution and was actively exploited in the wild for ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server's ProxyNotShell vulnerability allowed authenticated remote code execution, enabling ransomware attacks when chained with CVE-2022-41040.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched RCE flaw in Microsoft's Windows Support Diagnostic Tool allowed attackers to execute arbitrary code via URL protocol calls from applications like Word.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote sandbox bypass in Oracle JRE allowed attackers to execute arbitrary code, leading to ransomware outbreaks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle JRE applet permission flaw allowed remote attackers to execute arbitrary commands on vulnerable systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A double dereference vulnerability in Microsoft Silverlight allowed remote attackers to execute code via crafted HTML objects.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Silverlight's remote code execution vulnerability was actively exploited in the wild and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An incomplete block on the JBoss Web Console allowed unauthenticated attackers to access sensitive information via HTTP verbs beyond GET and POST.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Red Hat JBoss JMX-Console allowed remote attackers to bypass authentication by exploiting incomplete access control on non-GET/POST HTTP methods.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Fusion Middleware's WebCenter Forms Recognition component suffered an unspecified vulnerability allowing remote attackers to compromise confidentiality, integrity, and availability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IBM InfoSphere BigInsights APIs accepted invalid input allowing attackers to read, write, modify, or delete data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Internet Explorer/Edge vulnerability allowed attackers to detect files on user systems, linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's SMBv1 vulnerability (CVE-2017-0147) allowed attackers to steal sensitive data from Windows processes via crafted packets, and was actively exploited in ransomware attacks, demonstrating a critical failure to secure a core Windows component.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed privilege escalation via improper hard link handling, actively exploited in ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft component, Update Notification Manager, had a privilege escalation vulnerability actively exploited in ransomware attacks, allowing attackers to gain elevated system access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed privilege escalation via improper privilege management in AppX deployments, actively exploited and linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Workspace ONE Access suffered a server-side template injection vulnerability enabling remote code execution and actively exploited by ransomware actors.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows driver vulnerability allows privilege escalation and is actively exploited in ransomware attacks, impacting CMMC compliance for DIB organizations using vulnerable systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Active Directory vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.