CVE-2020-0938
A remote code execution flaw in the Windows Adobe Font Manager Library allowed attackers to execute arbitrary code on vulnerable systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
A remote code execution flaw in the Windows Adobe Font Manager Library allowed attackers to execute arbitrary code on vulnerable systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Windows Installer privilege escalation via symbolic link processing allows attackers to bypass access restrictions and add/remove files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's Scripting Engine had a memory corruption vulnerability allowing remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft .NET Framework remote code execution vulnerability allows attackers to execute arbitrary code on vulnerable systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows CryptoAPI spoofing vulnerability allowed attackers to use fake code-signing certificates to sign malicious executables and decrypt user connections.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IBM Planning Analytics allowed unauthenticated remote code execution via configuration overwrite, enabling root-level access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro OfficeScan suffered a directory traversal vulnerability allowing remote code execution via zip file extraction.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Small Business RV320 and RV325 routers suffered an information disclosure flaw allowing attackers to download router configurations and diagnostic data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's scripting engine had a memory corruption flaw allowing remote code execution, which was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in the Windows CLFS driver was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Windows Error Reporting allowed kernel-mode code execution, listed in CISA's KEV catalog as actively exploited.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability allows kernel-mode code execution via improper memory handling.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A kernel-mode privilege escalation flaw in Microsoft Win32k allowed attackers to execute arbitrary code with system privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Win32k privilege escalation vulnerability allows kernel-mode code execution via improper memory handling.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A kernel-mode privilege escalation flaw in Microsoft Win32k allowed attackers to execute arbitrary code with system privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft MSHTML engine had an improper input validation flaw allowing remote code execution via malicious Office documents.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's Scripting Engine suffered a memory corruption vulnerability allowing remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion suffered a deserialization of untrusted data vulnerability allowing remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's unrestricted file upload flaw allowed remote code execution, enabling attackers to upload and execute malicious files on vulnerable systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Microsoft Office allowed remote code execution when chained with another vulnerability, and was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office memory corruption flaw allows remote code execution and is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA suffered a DoS vulnerability from improper HTTP URL input validation that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS and IOS XE Smart Install allows unauthenticated remote attackers to execute code, causing device reloads, DoS, or full compromise.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft .NET Framework RCE vulnerability (CVE-2017-8759) was actively exploited in the wild, allowing attackers to take full control of systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A buffer overflow in Microsoft IIS 6.0 on Windows Server 2003 R2 allowed remote attackers to execute code via a malformed PROPFIND request.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory handling flaw in Microsoft Outlook allowed attackers to bypass security features and execute arbitrary commands.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver's XXE vulnerability allowed authenticated attackers to read arbitrary files and execute remote code.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Win32k kernel-mode driver flaw allowed privilege escalation to kernel-mode code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver's CrashFileDownloadServlet allowed remote attackers to read arbitrary files via directory traversal.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Office OLE DLL side loading vulnerability allowed remote code execution by improperly validating input before loading libraries.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A remote code execution flaw in Windows Media Center allowed attackers to execute arbitrary code via malicious .mcl files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server suffered a remote code execution vulnerability via deserialization of untrusted data that was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A memory corruption flaw in Microsoft Office allowed remote code execution when processing rich text format files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Fusion Middleware Reports Developer contains an unspecified vulnerability allowing remote attackers to compromise confidentiality and integrity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft MSCOMCTL.OCX contained a remote code execution vulnerability that allowed attackers to take full control of affected systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver's unauthenticated Invoker Servlet allowed remote code execution via HTTP/HTTPS requests.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A kernel-mode privilege escalation flaw in Microsoft Win32k allowed attackers to execute arbitrary code in kernel mode.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Microsoft's OMI within Azure VM Management Extensions was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Microsoft's OMI within Azure VM Management Extensions was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A privilege escalation vulnerability in Microsoft's OMI within Azure VM Management Extensions was actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.