CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2009-1862

Adobe Acrobat and Reader, Flash Player Unspecified Vulnerability

Vendor: Adobe

Product: Acrobat and Reader, Flash Player

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Adobe Acrobat and Reader and Adobe Flash Player allows remote attackers to execute code or cause denial-of-service (DoS).

Required Action:

For Adobe Acrobat and Reader, apply updates per vendor instructions. For Adobe Flash Player, the impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-94

CVE-2009-0563

Microsoft Office Buffer Overflow Vulnerability

Vendor: Microsoft

Product: Office

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2009-0557

Microsoft Office Object Record Corruption Vulnerability

Vendor: Microsoft

Product: Office

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Microsoft Office contains an object record corruption vulnerability that allows remote attackers to execute code via a crafted Excel file with a malformed record object.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2008-0655

Adobe Acrobat and Reader Unspecified Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Adobe Acrobat and Reader contains an unespecified vulnerability described as a design flaw which could allow a specially crafted file to be printed silently an arbitrary number of times.

Required Action:

Apply updates per vendor instructions.

CVE-2007-5659

Adobe Acrobat and Reader Buffer Overflow Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Adobe Acrobat and Reader contain a buffer overflow vulnerability that allows remote attackers to execute code via a PDF file with long arguments to unspecified JavaScript methods.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2006-2492

Microsoft Word Malformed Object Pointer Vulnerability

Vendor: Microsoft

Product: Word

Added: 2022-06-08

Due Date: 2022-06-22

Description:

Microsoft Word and Microsoft Works Suites contain a malformed object pointer which allows attackers to execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-120

CVE-2022-26134

Ransomware

Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability

Vendor: Atlassian

Product: Confluence Server/Data Center

Added: 2022-06-02

Due Date: 2022-06-06

Description:

Atlassian Confluence Server and Data Center contain a remote code execution vulnerability that allows for an unauthenticated attacker to perform remote code execution.

Required Action:

Immediately block all internet traffic to and from affected products AND apply the update per vendor instructions [https://confluence.atlassian.com/doc/confluence-security-advisory-2022-06-02-1130377146.html] OR remove the affected products by the due date on the right. Note: Once the update is successfully deployed, agencies can reassess the internet blocking rules.

CWEs:

CWE-917

CVE-2019-3010

Oracle Solaris Privilege Escalation Vulnerability

Vendor: Oracle

Product: Solaris

Added: 2022-05-25

Due Date: 2022-06-15

Description:

Oracle Solaris component: XScreenSaver contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CVE-2016-3393

Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-05-25

Due Date: 2022-06-15

Description:

A remote code execution vulnerability exists due to the way the Windows GDI component handles objects in the memory. An attacker who successfully exploits this vulnerability could take control of the affected system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2016-7256

Microsoft Windows Open Type Font Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-05-25

Due Date: 2022-06-15

Description:

A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploits this vulnerability could take control of the affected system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2016-1010

Adobe Flash Player and AIR Integer Overflow Vulnerability

Vendor: Adobe

Product: Flash Player and AIR

Added: 2022-05-25

Due Date: 2022-06-15

Description:

Integer overflow vulnerability in Adobe Flash Player and AIR allows attackers to execute code.

Required Action:

The impacted products are end-of-life and should be disconnected if still in use.

CWEs:

CWE-190

CVE-2016-0984

Adobe Flash Player and AIR Use-After-Free Vulnerability

Vendor: Adobe

Product: Flash Player and AIR

Added: 2022-05-25

Due Date: 2022-06-15

Description:

Use-after-free vulnerability in Adobe Flash Player and Adobe AIR allows attackers to execute code.

Required Action:

The impacted products are end-of-life and should be disconnected if still in use.

CWEs:

CWE-416

CVE-2016-0034

Ransomware

Microsoft Silverlight Runtime Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Silverlight

Added: 2022-05-25

Due Date: 2022-06-15

Description:

Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).

Required Action:

The impacted products are end-of-life and should be disconnected if still in use.

CWEs:

CWE-20

CVE-2015-0310

Adobe Flash Player ASLR Bypass Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2022-05-25

Due Date: 2022-06-15

Description:

Adobe Flash Player does not properly restrict discovery of memory addresses, which allows attackers to bypass the address space layout randomization (ASLR) protection mechanism.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-264

CVE-2015-0016

Microsoft Windows TS WebProxy Directory Traversal Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-05-25

Due Date: 2022-06-15

Description:

Directory traversal vulnerability in the TS WebProxy (TSWbPrxy) component in Microsoft Windows allows remote attackers to escalate privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22