CVE-2023-21674
Microsoft Windows ALPC flaw exploited in wild for privilege escalation
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Actively-exploited / critical CVEs correlated to FedRAMP-authorized products, read by dex — the gist, which products are hit, and what to do. Sorted with those under active attack (CISA KEV) first. Click a CVE for full detail.
Microsoft Windows ALPC flaw exploited in wild for privilege escalation
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Citrix ADC & Gateway AD auth bypass exploited
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium GPU heap buffer overflow allowed remote attacker to escape sandbox
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle Fusion Middleware exposed to unauthenticated RCE via HTTP
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Mark of the Web in Windows exploited for bypassing security features
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CVE-2022-41128: Unpatched RCE in JScript9
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CVE-2022-41125: Unpatched Windows CNG Key Isolation Service Privilege Escalation exploit active in wild
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium V8 Engine had a type confusion vulnerability actively exploited in the wild
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft's COM+ Event System Service allowed for unauthorized escalation of privileges.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CVE-2010-2568: Remote code execution in Windows due to shortcut parsing flaw
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro's Apex One and Apex One as a Service exposed to remote code execution due to improper validation of rollback mechanisms, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows CLFS Driver allows unauthorized escalation of privileges
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium Mojo allows remote attackers to escape the sandbox via a crafted HTML page.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Oracle WebLogic Server RCE due to unpatched vulnerability
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
VMware Tanzu Spring Cloud Function RCE
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Palo Alto Networks PAN-OS suffered an active RDoS attack due to URL filtering policy misconfiguration.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Google Chromium Intents CVE-2022-2856 allows remote code execution via malicious HTML pages
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Authenticated users could exploit a Microsoft Active Directory Domain Services (AD DS) vulnerability for privilege escalation to SYSTEM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Palo Alto Networks PAN-OS vulnerability allowed for chained remote code execution, actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
CVE-2022-21971: Microsoft Windows Runtime RCE actively exploited
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP's NetWeaver products exploited for HTTP request smuggling
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allows remote code execution via specially crafted URLs, actively exploited in the wild and impacting CMMC compliance efforts.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to escalate privileges to SYSTEM, actively exploited in the wild and impacting DIB organizations using Windows systems.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Windows vulnerability allowed attackers to spoof authentication, potentially granting them unauthorized access to domain resources using NTLM.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Red Hat Polkit vulnerability allowed privilege escalation, actively exploited in the wild, impacting systems relying on it for authorization.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Chromium PopupBlocker vulnerability allowed attackers to bypass navigation restrictions via crafted iframes, impacting multiple browsers including Chrome and Edge, and actively exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver allowed attackers to steal user information via HTTP requests, and remains actively exploited despite being years old.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A SQL injection vulnerability in SAP NetWeaver allowed attackers to execute arbitrary SQL commands remotely.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
SAP NetWeaver's unrestricted file upload vulnerability allows attackers to upload arbitrary files, potentially leading to system compromise and data exfiltration.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A heap corruption vulnerability in Google's Chromium V8 engine was actively exploited, impacting browsers like Chrome and Edge, potentially allowing attackers to execute arbitrary code via crafted HTML pages.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A double-free vulnerability in Adobe Acrobat and Reader allowed for potential remote code execution, actively exploited in the wild and impacting DIB organizations reliant on these products.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A 2009 Microsoft Office buffer overflow flaw allowed remote attackers to execute code via crafted Word documents.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Chromium V8 out-of-bounds write vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers including Chrome and Edge, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Chromium V8 vulnerability allowed remote code execution via crafted HTML, impacting multiple browsers and potentially DIB organizations using them for web access or internal tools.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
An integer overflow in Adobe Flash Player allowed remote code execution, and its end-of-life status means no patches exist for this vulnerability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A Microsoft Internet Explorer use-after-free vulnerability allows remote code execution via a crafted website, and is currently being exploited in the wild.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Flash Player's unpatched memory corruption vulnerability allowed remote attackers to execute code, a critical flaw in an end-of-life product that remains a perpetual security liability.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A malformed Excel file could trigger remote code execution in Microsoft Office via an object record corruption flaw.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
A decade-old Microsoft XML Core Services vulnerability is actively exploited, enabling remote code execution.
▸ DO Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.