CVE-2020-16010
A heap buffer overflow in Chrome for Android UI allowed sandbox escapes after a renderer compromise, but lacked RCE and zero-day status.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
A heap buffer overflow in Chrome for Android UI allowed sandbox escapes after a renderer compromise, but lacked RCE and zero-day status.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A type confusion vulnerability in Google's Chromium V8 engine allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap buffer overflow in Google Chrome's FreeType font rendering library was actively exploited in the wild as part of an exploit chain.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti MobileIron products suffered a remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server contains an unspecified vulnerability in the Console component with high impacts to confidentilaity, integrity, and availability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server contains an unspecified vulnerability, which is assessed to allow for remote code execution, based on this vulnerability being related to CVE-2020-14750.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Solaris and Oracle ZFS Storage Appliance Kit contain an unspecified vulnerability causing high impacts to confidentiality, integrity, and availability of affected systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server contains an unspecified vulnerability allowing an unauthenticated attacker to perform remote code execution. This vulnerability is related to CVE-2020-14882.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CVE-2020-1464 is a Windows spoofing vulnerability that allows attackers to bypass security features and load improperly signed files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's scripting engine had a memory corruption flaw allowing remote code execution, which was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows DNS Servers suffered a remote code execution flaw (CVE-2020-1350, SIGRed) that allowed attackers to execute arbitrary code as the Local System Account.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsib
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Hyper-V RemoteFX vGPU suffered an improper input validation flaw allowing authenticated guest users to execute remote code on the host.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution flaw in Windows' Adobe Font Manager Library allowed attackers to execute arbitrary code on systems running Windows 10 and earlier.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An unpatched Windows kernel privilege escalation flaw allowed attackers to execute arbitrary code in kernel mode.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Internet Explorer's Scripting Engine allowed remote code execution, and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution flaw in the Windows Adobe Font Manager Library allowed attackers to execute arbitrary code on vulnerable systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Windows Installer privilege escalation via symbolic link processing allows attackers to bypass access restrictions and add/remove files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's Scripting Engine had a memory corruption vulnerability allowing remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it ap
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IBM Planning Analytics allowed unauthenticated remote code execution via configuration overwrite, enabling root-level access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Small Business RV320 and RV325 routers suffered an information disclosure flaw allowing attackers to download router configurations and diagnostic data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's scripting engine had a memory corruption flaw allowing remote code execution, which was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Common Log File System (CLFS) driver improperly handles objects in memory which can allow for privilege escalation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco HyperFlex HX installer VM suffered a command injection flaw allowing root-level code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Error Reporting (WER) contains a privilege escalation vulnerability due to the way it handles files, allowing for code execution in kernel mode.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability allows kernel-mode code execution via improper memory handling.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability allows kernel-mode code execution via improper memory handling.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A kernel-mode privilege escalation flaw in Microsoft Win32k allowed attackers to execute arbitrary code with system privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco HyperFlex HX installer VM had insufficient input validation allowing command execution as tomcat8 user.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft MSHTML engine had an improper input validation flaw allowing remote code execution via malicious Office documents.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's Scripting Engine suffered a memory corruption vulnerability allowing remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Defender contained an unpatched remote code execution vulnerability that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader suffered a heap-based buffer overflow allowing unauthenticated remote code execution, a known critical flaw repeatedly exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.