CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2018-19949

Ransomware

QNAP NAS File Station Command Injection Vulnerability

Vendor: QNAP

Product: Network Attached Storage (NAS)

Added: 2022-05-24

Due Date: 2022-06-14

Description:

A command injection vulnerability affecting QNAP NAS File Station could allow remote attackers to run commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-77 CWE-78

CVE-2018-19943

Ransomware

QNAP NAS File Station Cross-Site Scripting Vulnerability

Vendor: QNAP

Product: Network Attached Storage (NAS)

Added: 2022-05-24

Due Date: 2022-06-14

Description:

A cross-site scripting vulnerability affecting QNAP NAS File Station could allow remote attackers to inject malicious code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-79 CWE-80

CVE-2017-0147

Ransomware

Microsoft Windows SMBv1 Information Disclosure Vulnerability

Vendor: Microsoft

Product: SMBv1 server

Added: 2022-05-24

Due Date: 2022-06-14

Description:

The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2017-0022

Microsoft XML Core Services Information Disclosure Vulnerability

Vendor: Microsoft

Product: XML Core Services

Added: 2022-05-24

Due Date: 2022-06-14

Description:

Microsoft XML Core Services (MSXML) improperly handles objects in memory, allowing attackers to test for files on disk via a crafted web site.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2017-0005

Microsoft Windows Graphics Device Interface (GDI) Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-05-24

Due Date: 2022-06-14

Description:

The Graphics Device Interface (GDI) in Microsoft Windows allows local users to gain privileges via a crafted application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-0149

Microsoft Internet Explorer Memory Corruption Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-05-24

Due Date: 2022-06-14

Description:

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial-of-service (DoS) via a crafted website.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2017-0210

Microsoft Internet Explorer Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-05-24

Due Date: 2022-06-14

Description:

A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.

Required Action:

Apply updates per vendor instructions.

CVE-2017-8291

Artifex Ghostscript Type Confusion Vulnerability

Vendor: Artifex

Product: Ghostscript

Added: 2022-05-24

Due Date: 2022-06-14

Description:

Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-704

CVE-2017-8543

Microsoft Windows Search Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-05-24

Due Date: 2022-06-14

Description:

Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-281

CVE-2017-18362

Ransomware

Kaseya VSA SQL Injection Vulnerability

Vendor: Kaseya

Product: Virtual System/Server Administrator (VSA)

Added: 2022-05-24

Due Date: 2022-06-14

Description:

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-89

CVE-2016-0162

Microsoft Internet Explorer Information Disclosure Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-05-24

Due Date: 2022-06-14

Description:

An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2016-3351

Ransomware

Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

Vendor: Microsoft

Product: Internet Explorer and Edge

Added: 2022-05-24

Due Date: 2022-06-14

Description:

An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2016-4655

Apple iOS Information Disclosure Vulnerability

Vendor: Apple

Product: iOS

Added: 2022-05-24

Due Date: 2022-06-14

Description:

The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2016-4656

Apple iOS Memory Corruption Vulnerability

Vendor: Apple

Product: iOS

Added: 2022-05-24

Due Date: 2022-06-14

Description:

A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264

CVE-2016-4657

Apple iOS Webkit Memory Corruption Vulnerability

Vendor: Apple

Product: iOS

Added: 2022-05-24

Due Date: 2022-06-14

Description:

Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119