CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2017-0210

Microsoft Internet Explorer Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-05-24

Due Date: 2022-06-14

Description:

A privilege escalation vulnerability exists when Internet Explorer does not properly enforce cross-domain policies, which could allow an attacker to access information.

Required Action:

Apply updates per vendor instructions.

CVE-2017-8291

Artifex Ghostscript Type Confusion Vulnerability

Vendor: Artifex

Product: Ghostscript

Added: 2022-05-24

Due Date: 2022-06-14

Description:

Artifex Ghostscript allows -dSAFER bypass and remote command execution via .rsdparams type confusion with a "/OutputFile.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-704

CVE-2017-8543

Microsoft Windows Search Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-05-24

Due Date: 2022-06-14

Description:

Microsoft Windows allows an attacker to take control of the affected system when Windows Search fails to handle objects in memory.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-281

CVE-2017-18362

Ransomware

Kaseya VSA SQL Injection Vulnerability

Vendor: Kaseya

Product: Virtual System/Server Administrator (VSA)

Added: 2022-05-24

Due Date: 2022-06-14

Description:

ConnectWise ManagedITSync integration for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct access to the Kaseya VSA database.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-89

CVE-2016-0162

Microsoft Internet Explorer Information Disclosure Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-05-24

Due Date: 2022-06-14

Description:

An information disclosure vulnerability exists when Internet Explorer does not properly handle JavaScript. The vulnerability could allow an attacker to detect specific files on the user's computer.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2016-3351

Ransomware

Microsoft Internet Explorer and Edge Information Disclosure Vulnerability

Vendor: Microsoft

Product: Internet Explorer and Edge

Added: 2022-05-24

Due Date: 2022-06-14

Description:

An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2016-4655

Apple iOS Information Disclosure Vulnerability

Vendor: Apple

Product: iOS

Added: 2022-05-24

Due Date: 2022-06-14

Description:

The Apple iOS kernel allows attackers to obtain sensitive information from memory via a crafted application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2016-4656

Apple iOS Memory Corruption Vulnerability

Vendor: Apple

Product: iOS

Added: 2022-05-24

Due Date: 2022-06-14

Description:

A memory corruption vulnerability in Apple iOS kernel allows attackers to execute code in a privileged context or cause a denial-of-service (DoS) via a crafted application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264

CVE-2016-4657

Apple iOS Webkit Memory Corruption Vulnerability

Vendor: Apple

Product: iOS

Added: 2022-05-24

Due Date: 2022-06-14

Description:

Apple iOS WebKit contains a memory corruption vulnerability that allows attackers to execute remote code or cause a denial-of-service (DoS) via a crafted web site. This vulnerability could impact HTML parsers that use WebKit, including but not limited to Apple Safari and non-Apple products which rely on WebKit for HTML processing.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2016-6366

Cisco Adaptive Security Appliance (ASA) SNMP Buffer Overflow Vulnerability

Vendor: Cisco

Product: Adaptive Security Appliance (ASA)

Added: 2022-05-24

Due Date: 2022-06-14

Description:

A buffer overflow vulnerability in the Simple Network Management Protocol (SNMP) code of Cisco ASA software could allow an attacker to cause a reload of the affected system or to remotely execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2016-6367

Cisco Adaptive Security Appliance (ASA) CLI Remote Code Execution Vulnerability

Vendor: Cisco

Product: Adaptive Security Appliance (ASA)

Added: 2022-05-24

Due Date: 2022-06-14

Description:

A vulnerability in the command-line interface (CLI) parser of Cisco ASA software could allow an authenticated, local attacker to create a denial-of-service (DoS) condition or potentially execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-77

CVE-2016-3298

Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-05-24

Due Date: 2022-06-14

Description:

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2022-20821

Cisco IOS XR Open Port Vulnerability

Vendor: Cisco

Product: IOS XR

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-923

CVE-2021-1048

Android Kernel Use-After-Free Vulnerability

Vendor: Android

Product: Kernel

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Android kernel contains a use-after-free vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2021-0920

Android Kernel Race Condition Vulnerability

Vendor: Android

Product: Kernel

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-362 CWE-416