CVE-2024-8069
Citrix Session Recording exposed RCE due to untrusted data deserialization, exploited in the wild by unauthenticated attackers on the same intranet
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Citrix Session Recording exposed RCE due to untrusted data deserialization, exploited in the wild by unauthenticated attackers on the same intranet
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix Session Recording exposed to unauthorized privilege escalation due to improper access controls.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One suffered OS command injection, allowing remote attackers to upload and execute malicious code pre-authenticatedly.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
End-of-life IE allowed remote code execution due to unpatched vulnerabilities
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Excel allowed remote code execution through malicious files.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ISE API flaw allows RCE and root privileges
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco ISE API RCE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium ANGLE and GPU input validation flaw exploited remotely
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 had a type confusion vulnerability exploited in the wild
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix NetScaler ADC and Gateway suffered a buffer overflow that led to unintended control flow and Denial of Service, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows exposed to remote code execution via malicious WebDAV shortcuts
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 OOB Read/Write Vuln exploited
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti EPMM API code injection allows remote execution of arbitrary code by authenticated attackers
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti EPMM API flaw allows unauthorized access via crafted requests
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver Visual Composer Metadata Uploader had an unpatched deserialization vulnerability exploited in the wild, impacting confidentiality, integrity, and availability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in the Microsoft CLFS driver allows local privilege escalation and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows Scripting Engine vulnerability allows remote code execution via a crafted URL, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows CLFS driver vulnerability is actively exploited, enabling privilege escalation locally.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A use-after-free vulnerability in the Windows DWM Core Library allows local privilege escalation and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows driver vulnerability allows privilege escalation to administrator, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Broadcom Brocade Fabric OS vulnerability allows local admins to execute arbitrary code with root privileges, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allows attackers to spoof network traffic using NTLM hash disclosure, currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco's Smart Licensing Utility shipped with hardcoded credentials, allowing unauthorized remote access and administrative control.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A logic error in Google Chromium's Mojo sandbox allows for potential escape, impacting browsers like Chrome and Edge and actively being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver's UIUtilJavaScriptJS contained a directory traversal vulnerability allowing unauthorized file access via query string manipulation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Juniper Junos OS allowed local attackers with high privileges to inject arbitrary code due to improper isolation.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows integer overflow vulnerability is actively being exploited for local code execution, impacting DIB organizations reliant on Windows systems and potentially violating CMMC requirements for data protection and incident response.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows kernel vulnerability allows local privilege escalation and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A physical attack on Microsoft Windows systems can expose heap memory via an NTFS information disclosure vulnerability currently being actively exploited by adversaries.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows NTFS heap buffer overflow vulnerability is actively being exploited, allowing local code execution by an attacker.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A recently exploited Windows NTFS vulnerability allows local information disclosure to authorized attackers, impacting DIB organizations reliant on Windows systems for data storage and processing.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Ivanti Endpoint Manager has a path traversal vulnerability allowing unauthenticated attackers to leak sensitive information remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware ESXi and Workstation vulnerabilities allow code execution with local admin privileges, and are currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware virtualization products have an information disclosure vulnerability actively exploited in the wild, potentially allowing memory leakage from privileged virtual machines.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Cisco Small Business routers have a command injection vulnerability actively exploited by attackers to gain root access remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's Partner Center had a privilege escalation vulnerability actively exploited in the wild, allowing attackers to gain elevated access to systems and data.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion's deserialization vulnerability (CVE-2017-3066) enabled arbitrary code execution, actively exploited in the wild, demonstrating a recurring security weakness in the platform.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Agile PLM has a deserialization vulnerability actively exploited by attackers to compromise systems via HTTP network access.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.