CVE-2008-2992
A critical, actively exploited vulnerability in Adobe Acrobat and Reader allows for potential remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
A critical, actively exploited vulnerability in Adobe Acrobat and Reader allows for potential remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Java SE allowed remote code execution via a known vulnerability actively exploited in ransomware attacks, demonstrating a failure to patch critical systems promptly.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows Server vulnerability allowed local attackers to escalate privileges and execute arbitrary code, actively exploited and linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Internet Explorer's type confusion vulnerability allowed remote code execution and was actively exploited, highlighting the risks of using unsupported software in DIB environments.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical, actively exploited Windows VBScript engine vulnerability allows remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player, now end-of-life, contained a critical use-after-free vulnerability actively exploited by ransomware actors, leaving systems perpetually exposed.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical SMBv3 vulnerability allowed remote code execution, actively exploited and linked to ransomware attacks, impacting DIB organizations reliant on Microsoft infrastructure.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server had a remotely exploitable code execution vulnerability actively linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's SMBv1 vulnerability (CVE-2017-0144) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's SMBv1 vulnerability (CVE-2017-0145) allowed remote code execution and was actively exploited, often linked to ransomware attacks, impacting DIB organizations reliant on legacy Windows systems and SMB file sharing.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed privilege escalation to system-level access via improper symbolic link handling, actively exploited in ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Win32k vulnerability allowed privilege escalation and was actively exploited, likely in ransomware attacks, impacting Windows systems widely used in the DIB.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware's vRealize Operations Manager API had a critical SSRF vulnerability exploited in the wild, potentially leading to credential theft and system compromise.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical, actively exploited vulnerability in Palo Alto Networks PAN-OS allows remote code execution via GlobalProtect interfaces.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting Windows systems widely used in the DIB.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server's injection vulnerability was actively exploited and linked to ransomware attacks, impacting DIB organizations using this middleware.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to spoof installations, potentially delivering malware and compromising system integrity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A vulnerability in Red Hat JBoss Application Server allowed attackers to execute arbitrary code remotely, linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed authenticated users to escalate privileges, actively exploited and linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server vulnerabilities allowed authenticated attackers to execute remote code, impacting DIB organizations using the platform.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PrintNightmare allowed attackers to execute code with SYSTEM privileges on Windows systems via the Print Spooler service, actively exploited in ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Zerologon allowed attackers to gain domain administrator privileges without authentication, impacting virtually all Active Directory environments.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Office vulnerability allowed remote code execution via crafted files, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Exchange Server vulnerability allowed privilege escalation and was actively exploited in ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server vulnerabilities allowed attackers to bypass security features and potentially deploy ransomware, impacting DIB organizations reliant on email infrastructure.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix StoreFront Server had an unauthenticated XXE vulnerability actively exploited by ransomware actors, allowing data retrieval.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Edge and Internet Explorer suffered a memory corruption vulnerability exploited in ransomware attacks, allowing code execution with user privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to spoof the Local Security Authority and force domain controllers to authenticate against malicious servers using NTLM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An authenticated attacker can decrypt and escalate privileges within a Windows Active Directory domain via a Group Policy Preferences vulnerability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows CLFS driver vulnerability allows privilege escalation, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server's failure to generate unique keys allowed for remote code execution, exploited in the wild and linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Accellion FTA's OS command injection vulnerability allowed attackers to execute arbitrary commands, leading to data exfiltration and ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix Workspace software had a remote code execution vulnerability actively exploited by ransomware actors, allowing attackers to execute arbitrary code on affected systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Accellion FTA's SQL injection vulnerability was actively exploited, leading to data breaches and ransomware attacks affecting DIB organizations using the product.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.