CVE-2021-21985
VMware vCenter Server RCE due to unpatched input validation flaw
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
VMware vCenter Server RCE due to unpatched input validation flaw
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware ESXi and Horizon DaaS products contained a heap-based buffer overflow vulnerability actively exploited by attackers to achieve remote code execution (RCE).
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PrintNightmare allowed attackers to execute code with SYSTEM privileges on Windows systems via the Print Spooler service, actively exploited in ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix ADC, Gateway, and SD-WAN appliances had a critical, unauthenticated code execution vulnerability actively exploited in the wild, potentially allowing attackers to take control of systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical, actively exploited vulnerability in Microsoft's SMBv1 allowed for remote code execution, impacting many DIB systems still running vulnerable Windows versions.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware's vCenter Server had a file upload vulnerability actively exploited by ransomware actors, allowing code execution over port 443.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA/FTD devices were vulnerable to XSS, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware vCenter Server RCE due to unpatched plugin exploited in wild
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Win32k vulnerability allowed privilege escalation, actively exploited and linked to ransomware attacks, impacting DIB organizations using Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
BlueKeep (CVE-2019-0708) allows unauthenticated remote code execution via RDP, actively exploited and linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server's failure to generate unique keys allowed for remote code execution, exploited in the wild and linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware ESXi's OpenSLP service had a remotely exploitable use-after-free vulnerability linked to ransomware activity, requiring immediate patching and network segmentation review.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Accellion FTA's OS command injection vulnerability was actively exploited, likely contributing to ransomware attacks and data breaches affecting numerous DIB organizations and FedRAMP vendors who used it as a component in their systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Accellion FTA's SSRF vulnerability was actively exploited, linked to ransomware attacks, impacting DIB organizations using the platform for data transfer and storage.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Pulse Connect Secure's use-after-free vulnerability allowed unauthenticated attackers to execute code remotely, and is actively being exploited in ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server vulnerabilities allowed attackers to execute code remotely, often as part of ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Exchange Server vulnerabilities (ProxyLogon) enabled widespread remote code execution, actively exploited by ransomware groups.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A critical, actively exploited memory corruption vulnerability in Microsoft Internet Explorer allowed for remote code execution, highlighting the risks of using unsupported software in DIB environments.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint's failure to validate application package markup allowed for remote code execution, actively exploited in the wild and linked to ransomware activity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Edge and Internet Explorer suffered a memory corruption vulnerability exploited in ransomware attacks, allowing code execution with user privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Pulse Connect Secure allowed unauthenticated attackers to read arbitrary files via a specially crafted URI, and was actively exploited in the wild, often linked to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Accellion FTA's SQL injection vulnerability was actively exploited, leading to data breaches and ransomware attacks affecting DIB organizations using the product.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Accellion FTA's OS command injection vulnerability allowed attackers to execute arbitrary commands, leading to data exfiltration and ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Office memory corruption vulnerability allowed for remote code execution and was actively exploited, likely contributing to ransomware attacks.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Win32k vulnerability allows privilege escalation and is actively exploited in ransomware attacks, impacting DIB organizations using Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A deserialization of untrusted data vulnerability in Microsoft Entra ID allowed remote code execution over a network.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unauthenticated attackers exploited a path traversal flaw in VMware vCenter to execute arbitrary code and establish persistent backdoors.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A double free vulnerability in Microsoft's Internet Key Exchange (IKE) Service Extensions allows remote code execution and is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint's weak authentication flaw lets attackers bypass security controls over a network.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in the Windows Ancillary Function Driver for WinSock allows local privilege escalation and is actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ASA/FTD devices have an unpatched heap inspection vulnerability allowing remote denial of service.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
IBM Langflow Code Injection Vulnerability allows RCE.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco FMC shipped with a hardcoded password allowing unauthenticated remote login to sensitive data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint RCE due to untrusted data deserialization
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft SharePoint RCE due to untrusted data deserialization
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle E-Business Suite exposed to unauthenticated attacks via HTTP, potentially allowing takeover of Oracle Payments.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Unpatched RCE in SharePoint Server
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Authorized attackers can elevate privileges in Microsoft AD FS due to insufficient access control granularity.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco IOS 12.4 devices are actively exploited in the wild via a cross-site request forgery vulnerability enabling remote command execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion allows arbitrary code execution via path traversal, enabling attackers to run commands as the current user.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.