CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2021-31010

Apple iOS, macOS, watchOS Sandbox Bypass Vulnerability

Vendor: Apple

Product: iOS, macOS, watchOS

Added: 2022-08-25

Due Date: 2022-09-15

Description:

In affected versions of Apple iOS, macOS, and watchOS, a sandboxed process may be able to circumvent sandbox restrictions.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-502

CVE-2020-36193

PEAR Archive_Tar Improper Link Resolution Vulnerability

Vendor: PEAR

Product: Archive_Tar

Added: 2022-08-25

Due Date: 2022-09-15

Description:

PEAR Archive_Tar Tar.php allows write operations with directory traversal due to inadequate checking of symbolic links. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22 CWE-59

CVE-2020-28949

PEAR Archive_Tar Deserialization of Untrusted Data Vulnerability

Vendor: PEAR

Product: Archive_Tar

Added: 2022-08-25

Due Date: 2022-09-15

Description:

PEAR Archive_Tar allows an unserialization attack because phar: is blocked but PHAR: is not blocked. PEAR stands for PHP Extension and Application Repository and it is an open-source framework and distribution system for reusable PHP components with known usage in third-party products such as Drupal Core and Red Hat Linux.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-74

CVE-2022-0028

Palo Alto Networks PAN-OS Reflected Amplification Denial-of-Service Vulnerability

Vendor: Palo Alto Networks

Product: PAN-OS

Added: 2022-08-22

Due Date: 2022-09-12

Description:

A Palo Alto Networks PAN-OS URL filtering policy misconfiguration could allow a network-based attacker to conduct reflected and amplified TCP denial-of-service (RDoS) attacks.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-940

CVE-2022-22536

SAP Multiple Products HTTP Request Smuggling Vulnerability

Vendor: SAP

Product: Multiple Products

Added: 2022-08-18

Due Date: 2022-09-08

Description:

SAP NetWeaver Application Server ABAP, SAP NetWeaver Application Server Java, ABAP Platform, SAP Content Server and SAP Web Dispatcher allow HTTP request smuggling. An unauthenticated attacker can prepend a victim's request with arbitrary data, allowing for function execution impersonating the victim or poisoning intermediary Web caches.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-444

CVE-2022-32894

Apple iOS and macOS Out-of-Bounds Write Vulnerability

Vendor: Apple

Product: iOS and macOS

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow an application to execute code with kernel privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-787

CVE-2022-32893

Apple iOS and macOS Out-of-Bounds Write Vulnerability

Vendor: Apple

Product: iOS and macOS

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Apple iOS and macOS contain an out-of-bounds write vulnerability that could allow for remote code execution when processing malicious crafted web content.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-787

CVE-2022-2856

Google Chromium Intents Insufficient Input Validation Vulnerability

Vendor: Google

Product: Chromium Intents

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Google Chromium Intents contains an insufficient validation of untrusted input vulnerability that allows a remote attacker to browse to a malicious website via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2022-26923

Microsoft Active Directory Domain Services Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Active Directory

Added: 2022-08-18

Due Date: 2022-09-08

Description:

An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-295

CVE-2022-21971

Microsoft Windows Runtime Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-824

CVE-2017-15944

Palo Alto Networks PAN-OS Remote Code Execution Vulnerability

Vendor: Palo Alto Networks

Product: PAN-OS

Added: 2022-08-18

Due Date: 2022-09-08

Description:

Palo Alto Networks PAN-OS contains multiple, unspecified vulnerabilities which can allow for remote code execution when chained.

Required Action:

Apply updates per vendor instructions.

CVE-2022-27925

Ransomware

Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2022-08-11

Due Date: 2022-09-01

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains flaw in the mboximport functionality, allowing an authenticated attacker to upload arbitrary files to perform remote code execution. This vulnerability was chained with CVE-2022-37042 which allows for unauthenticated remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22

CVE-2022-37042

Ransomware

Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass Vulnerability

Vendor: Synacor

Product: Zimbra Collaboration Suite (ZCS)

Added: 2022-08-11

Due Date: 2022-09-01

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains an authentication bypass vulnerability in MailboxImportServlet. This vulnerability was chained with CVE-2022-27925 which allows for unauthenticated remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-23

CVE-2022-34713

Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-08-09

Due Date: 2022-08-30

Description:

A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.

Required Action:

Apply updates per vendor instructions.

CVE-2022-30333

Ransomware

RARLAB UnRAR Directory Traversal Vulnerability

Vendor: RARLAB

Product: UnRAR

Added: 2022-08-09

Due Date: 2022-08-30

Description:

RARLAB UnRAR on Linux and UNIX contains a directory traversal vulnerability, allowing an attacker to write to files during an extract (unpack) operation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-22 CWE-59