CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2023-28432

MinIO Information Disclosure Vulnerability

Vendor: MinIO

Product: MinIO

Added: 2023-04-21

Due Date: 2023-05-12

Description:

MinIO contains a vulnerability in a cluster deployment where MinIO returns all environment variables, which allows for information disclosure.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2023-27350

Ransomware

PaperCut MF/NG Improper Access Control Vulnerability

Vendor: PaperCut

Product: MF/NG

Added: 2023-04-21

Due Date: 2023-05-12

Description:

PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2023-2136

Google Chrome Skia Integer Overflow Vulnerability

Vendor: Google

Product: Chromium Skia

Added: 2023-04-21

Due Date: 2023-05-12

Description:

Google Chromium Skia contains an integer overflow vulnerability that allows a remote attacker, who has compromised the renderer process, to potentially perform a sandbox escape via a crafted HTML page. This vulnerability affects Google Chrome and ChromeOS, Android, Flutter, and possibly other products.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-190

CVE-2017-6742

Cisco IOS and IOS XE Software SNMP Remote Code Execution Vulnerability

Vendor: Cisco

Product: IOS and IOS XE Software

Added: 2023-04-19

Due Date: 2023-05-10

Description:

The Simple Network Management Protocol (SNMP) subsystem of Cisco IOS and IOS XE contains a vulnerability that could allow an authenticated, remote attacker to remotely execute code on an affected system or cause an affected system to reload.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2019-8526

Apple macOS Use-After-Free Vulnerability

Vendor: Apple

Product: macOS

Added: 2023-04-17

Due Date: 2023-05-08

Description:

Apple macOS contains a use-after-free vulnerability that could allow for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2023-2033

Google Chromium V8 Type Confusion Vulnerability

Vendor: Google

Product: Chromium V8

Added: 2023-04-17

Due Date: 2023-05-08

Description:

Google Chromium V8 Engine contains a type confusion vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843

CVE-2023-20963

Android Framework Privilege Escalation Vulnerability

Vendor: Android

Product: Framework

Added: 2023-04-13

Due Date: 2023-05-04

Description:

Android Framework contains an unspecified vulnerability that allows for privilege escalation after updating an app to a higher Target SDK with no additional execution privileges needed.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-295

CVE-2023-29492

Novi Survey Insecure Deserialization Vulnerability

Vendor: Novi Survey

Product: Novi Survey

Added: 2023-04-13

Due Date: 2023-05-04

Description:

Novi Survey contains an insecure deserialization vulnerability that allows remote attackers to execute code on the server in the context of the service account.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2023-28252

Ransomware

Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-04-11

Due Date: 2023-05-02

Description:

Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-122

CVE-2023-28205

Apple Multiple Products WebKit Use-After-Free Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2023-04-10

Due Date: 2023-05-01

Description:

Apple iOS, iPadOS, macOS, and Safari WebKit contain a use-after-free vulnerability that leads to code execution when processing maliciously crafted web content. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2023-28206

Apple iOS, iPadOS, and macOS IOSurfaceAccelerator Out-of-Bounds Write Vulnerability

Vendor: Apple

Product: iOS, iPadOS, and macOS

Added: 2023-04-10

Due Date: 2023-05-01

Description:

Apple iOS, iPadOS, and macOS IOSurfaceAccelerator contain an out-of-bounds write vulnerability that allows an app to execute code with kernel privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-27876

Ransomware

Veritas Backup Exec Agent File Access Vulnerability

Vendor: Veritas

Product: Backup Exec Agent

Added: 2023-04-07

Due Date: 2023-04-28

Description:

Veritas Backup Exec (BE) Agent contains a file access vulnerability that could allow an attacker to specially craft input parameters on a data management protocol command to access files on the BE Agent machine.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-287

CVE-2021-27877

Ransomware

Veritas Backup Exec Agent Improper Authentication Vulnerability

Vendor: Veritas

Product: Backup Exec Agent

Added: 2023-04-07

Due Date: 2023-04-28

Description:

Veritas Backup Exec (BE) Agent contains an improper authentication vulnerability that could allow an attacker unauthorized access to the BE Agent via SHA authentication scheme.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-287

CVE-2021-27878

Ransomware

Veritas Backup Exec Agent Command Execution Vulnerability

Vendor: Veritas

Product: Backup Exec Agent

Added: 2023-04-07

Due Date: 2023-04-28

Description:

Veritas Backup Exec (BE) Agent contains a command execution vulnerability that could allow an attacker to use a data management protocol command to execute a command on the BE Agent machine.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-287

CVE-2019-1388

Ransomware

Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2023-04-07

Due Date: 2023-04-28

Description:

Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-269