CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2022-22536

SAP Multiple Products HTTP Request Smuggling Vulnerability

Vendor: SAP

Product: Multiple Products

Added: 2022-08-18

Due Date: 2022-09-08

Description:

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-444

CVE-2022-32894

Apple iOS and macOS Out-of-Bounds Write Vulnerability

Vendor: Apple

Product: iOS and macOS

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-787

CVE-2022-32893

Apple iOS and macOS Out-of-Bounds Write Vulnerability

Vendor: Apple

Product: iOS and macOS

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-787

CVE-2022-2856

Google Chromium Intents Insufficient Input Validation Vulnerability

Vendor: Google

Product: Chromium Intents

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2022-26923

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Active Directory

Added: 2022-08-18

Due Date: 2022-09-08

Description:

An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-295

CVE-2022-21971

Microsoft Windows Runtime Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-824

CVE-2017-15944

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Vendor: Palo Alto Networks

Product: PAN-OS

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.

Required Action:

Apply updates per vendor instructions.

CVE-2022-27925

Ransomware

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2022-08-11

Due Date: 2022-09-01

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2022-37042

Ransomware

Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2022-08-11

Due Date: 2022-09-01

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-23

CVE-2022-34713

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-08-09

Due Date: 2022-08-30

Description:

A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.

Required Action:

Apply updates per vendor instructions.

CVE-2022-30333

Ransomware

RARLAB UnRAR Directory Traversal Vulnerability

Vendor: RARLAB

Product: UnRAR

Added: 2022-08-09

Due Date: 2022-08-30

Description:

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22 CWE-59

CVE-2022-27924

Ransomware

Synacor Zimbra Collaboration Suite (ZCS) Command Injection Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2022-08-04

Due Date: 2022-08-25

Description:

Synacor Zimbra Collaboration Suite (ZCS) allows an attacker to inject memcache commands into a targeted instance which causes an overwrite of arbitrary cached entries.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-93

CVE-2022-26138

Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability

Vendor: Atlassian

Product: Confluence

Added: 2022-07-29

Due Date: 2022-08-19

Description:

Atlassian Questions For Confluence App has hard-coded credentials, exposing the username and password in plaintext. A remote unauthenticated attacker can use these credentials to log into Confluence and access all content accessible to users in the confluence-users group.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-798

CVE-2022-22047

Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-07-12

Due Date: 2022-08-02

Description:

Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-426

CVE-2022-26925

Microsoft Windows LSA Spoofing Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-07-01

Due Date: 2022-07-22

Description:

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.

Required Action:

Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].

CWEs:

CWE-306