CVE-2025-32701
A use-after-free vulnerability in the Microsoft CLFS driver allows local privilege escalation and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
A use-after-free vulnerability in the Microsoft CLFS driver allows local privilege escalation and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows Scripting Engine vulnerability allows remote code execution via a crafted URL, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Broadcom Brocade Fabric OS vulnerability allows local admins to execute arbitrary code with root privileges, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allows attackers to spoof network traffic using NTLM hash disclosure, currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco's Smart Licensing Utility shipped with hardcoded credentials, allowing unauthorized remote access and administrative control.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A logic error in Google Chromium's Mojo sandbox allows for potential escape, impacting browsers like Chrome and Edge and actively being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver's UIUtilJavaScriptJS contained a directory traversal vulnerability allowing unauthorized file access via query string manipulation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Juniper Junos OS allowed local attackers with high privileges to inject arbitrary code due to improper isolation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A physical attack on Microsoft Windows systems can expose heap memory via an NTFS information disclosure vulnerability currently being actively exploited by adversaries.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A recently exploited Windows NTFS vulnerability allows local information disclosure to authorized attackers, impacting DIB organizations reliant on Windows systems for data storage and processing.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows NTFS heap buffer overflow vulnerability is actively being exploited, allowing local code execution by an attacker.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows integer overflow vulnerability is actively being exploited for local code execution, impacting DIB organizations reliant on Windows systems and potentially violating CMMC requirements for data protection and incident response.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows kernel vulnerability allows local privilege escalation and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware ESXi and Workstation vulnerabilities allow code execution with local admin privileges, and are currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware virtualization products have an information disclosure vulnerability actively exploited in the wild, potentially allowing memory leakage from privileged virtual machines.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Small Business routers have a command injection vulnerability actively exploited by attackers to gain root access remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's Partner Center had a privilege escalation vulnerability actively exploited in the wild, allowing attackers to gain elevated access to systems and data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Agile PLM has a deserialization vulnerability actively exploited by attackers to compromise systems via HTTP network access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's deserialization vulnerability (CVE-2017-3066) enabled arbitrary code execution, actively exploited in the wild, demonstrating a recurring security weakness in the platform.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Power Pages has an improper access control vulnerability actively exploited in the wild, allowing privilege escalation and bypassing user registration controls.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Palo Alto Networks PAN-OS vulnerability allows authenticated attackers to read arbitrary files on the system, potentially exposing sensitive data and configurations.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A zero-day authentication bypass vulnerability in Palo Alto Networks PAN-OS allowed unauthenticated attackers network access to invoke PHP scripts, bypassing authentication controls entirely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allows privilege escalation and potential data deletion, currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows driver vulnerability allows local privilege escalation to SYSTEM, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Outlook's improper input validation allows attackers to bypass Protected View and execute code remotely, currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft .NET Framework vulnerability allows attackers to expose sensitive information and potentially execute code remotely, currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Hyper-V NT Kernel Integration VSP contains a heap-based buffer overflow allowing local attackers to gain SYSTEM privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows Hyper-V NT Kernel Integration VSP use-after-free vulnerability allows local attackers to gain SYSTEM privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BeyondTrust PRA/RS allows attackers with admin access to upload malware and execute OS commands via command injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server was exploited in the wild via CVE-2020-2883, an unauthenticated RCE flaw in its IIOP/T3 protocols.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS allows unauthenticated remote reboots via malicious DNS packet parsing flaws.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BeyondTrust PRA/RS allows unauthenticated attackers to execute commands as site users via command injection.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows kernel-mode driver vulnerability CVE-2024-35250 allows local privilege escalation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows CLFS driver heap-based buffer overflow allows local privilege escalation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle PLM SDK allows unauthenticated file disclosure via incorrect authorization in Process Extension.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.