Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A memory corruption bug in Google Chromium V8's JSON.stringify function leaked internal data to script code, causing corruption across multiple Chromium-based browsers.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2021-11-03
A Chromium input validation flaw allowed attackers to force browsers to navigate to malicious URLs via crafted HTML pages.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
A remote attacker could extract sensitive data from Chromium browser processes via a crafted HTML page due to an unpatched memory disclosure flaw.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A use-after-free vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A use-after-free vulnerability in Google Chromium Portals allowed sandbox escapes via crafted HTML pages after the renderer process was compromised.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
KEV
2021-11-03
An unpatched privilege escalation flaw in Windows Update Medic Service was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2021-11-03
Trend Micro Apex One and Worry-Free Business Security suffered an improper input validation flaw enabling privilege escalation.
AFFECTS 2
Trend Micro Cloud One for GovernmentTrend Micro Vision One for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2021-11-03
Trend Micro Apex One and Worry-Free Business Security suffered an improper input validation flaw allowing remote attackers to upload arbitrary files.
AFFECTS 2
Trend Micro Cloud One for GovernmentTrend Micro Vision One for Government
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A memory corruption vulnerability in the Windows Scripting Engine was actively exploited in the wild, leading to potential remote code execution.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
KEV
2021-11-03
An unpatched Windows kernel privilege escalation vulnerability was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A remote code execution vulnerability in Microsoft Windows MSHTML was actively exploited in the wild, allowing attackers to execute arbitrary code on unpatched systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#rce#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
A privilege escalation flaw in Microsoft's Desktop Window Manager was actively exploited in the wild, allowing attackers to escalate privileges on Windows systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
An unpatched Windows kernel privilege escalation vulnerability was actively exploited in the wild, allowing attackers to escalate privileges without remote code execution.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
An unpatched privilege escalation flaw in Windows NTFS allowed attackers to gain elevated access via a crafted application.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2021-11-03
A Windows kernel vulnerability allowed attackers to read kernel memory from user mode, exposing sensitive data.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
KEV
2021-11-03
Microsoft Enhanced Cryptographic Provider privilege escalation vulnerability (CVE-2021-31201) was actively exploited in the wild, allowing attackers to escalate privileges on affected systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2021-11-03
Microsoft Enhanced Cryptographic Provider privilege escalation vulnerability (CVE-2021-31199) was actively exploited in the wild, allowing attackers to escalate privileges on affected systems.
AFFECTS 4
Azure Commercial CloudAzure Government (includes Dynamics 365)Microsoft Office 365 GCC HighOffice 365 Multi-Tenant & Supporting Services
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#privilege-escalation
Exploited
⌖ KEV
KEV
2021-11-03
A use-after-free flaw in Chromium's Indexed DB API allowed sandbox escapes after a renderer compromise, but required prior compromise and was not a zero-day.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
An out-of-bounds write vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#ransomware
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A type confusion vulnerability in Google Chromium V8 allowed remote attackers to exploit heap corruption via crafted HTML pages, affecting multiple Chromium-based browsers.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#rce
Exploited
⌖ KEV
⚡ RCE
KEV
2021-11-03
A use-after-free vulnerability in Google Chromium WebGL allowed remote attackers to exploit heap corruption via a crafted HTML page, affecting multiple Chromium-based browsers.
AFFECTS 2
Google Services (Google Cloud Platform Products and underlying Infrastructure)Google Workspace
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
#exploited-in-wild#unpatched#rce