CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2016-3298

Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-05-24

Due Date: 2022-06-14

Description:

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-200

CVE-2022-20821

Cisco IOS XR Open Port Vulnerability

Vendor: Cisco

Product: IOS XR

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Cisco IOS XR software health check opens TCP port 6379 by default on activation. An attacker can connect to the Redis instance on the open port and allow access to the Redis instance that is running within the NOSi container.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-923

CVE-2021-1048

Android Kernel Use-After-Free Vulnerability

Vendor: Android

Product: Kernel

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Android kernel contains a use-after-free vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2021-0920

Android Kernel Race Condition Vulnerability

Vendor: Android

Product: Kernel

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Android kernel contains a race condition, which allows for a use-after-free vulnerability. Exploitation can allow for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-362 CWE-416

CVE-2021-30883

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2020-1027

Microsoft Windows Kernel Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-05-23

Due Date: 2022-06-13

Description:

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2020-0638

Ransomware

Microsoft Update Notification Manager Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Update Notification Manager

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CVE-2019-7286

Apple Multiple Products Memory Corruption Vulnerability

Vendor: Apple

Product: Multiple Products

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Apple iOS, macOS, watchOS, and tvOS contain a memory corruption vulnerability that could allow for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2019-7287

Apple iOS Memory Corruption Vulnerability

Vendor: Apple

Product: iOS

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Apple iOS contains a memory corruption vulnerability which could allow an attacker to perform remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2019-0676

Microsoft Internet Explorer Information Disclosure Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2022-05-23

Due Date: 2022-06-13

Description:

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk.

Required Action:

Apply updates per vendor instructions.

CVE-2019-5786

Google Chrome Blink Use-After-Free Vulnerability

Vendor: Google

Product: Chrome Blink

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Google Chrome Blink contains a heap use-after-free vulnerability that allows an attacker to potentially perform out of bounds memory access via a crafted HTML page.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2019-0703

Microsoft Windows SMB Information Disclosure Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-05-23

Due Date: 2022-06-13

Description:

An information disclosure vulnerability exists in the way that the Windows SMB Server handles certain requests, which could lead to information disclosure from the server.

Required Action:

Apply updates per vendor instructions.

CVE-2019-0880

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-05-23

Due Date: 2022-06-13

Description:

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity.

Required Action:

Apply updates per vendor instructions.

CVE-2019-13720

Google Chrome WebAudio Use-After-Free Vulnerability

Vendor: Google

Product: Chrome WebAudio

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Google Chrome WebAudio contains a use-after-free vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2019-11707

Mozilla Firefox and Thunderbird Type Confusion Vulnerability

Vendor: Mozilla

Product: Firefox and Thunderbird

Added: 2022-05-23

Due Date: 2022-06-13

Description:

Mozilla Firefox and Thunderbird contain a type confusion vulnerability that can occur when manipulating JavaScript objects due to issues in Array.pop, allowing for an exploitable crash.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-843