CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2012-2539

Microsoft Word Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Word

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Microsoft Word allows attackers to execute remote code or cause a denial-of-service (DoS) via crafted RTF data.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-399

CVE-2012-2034

Adobe Flash Player Memory Corruption Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Adobe Flash Player contains a memory corruption vulnerability that allows for remote code execution or denial-of-service (DoS).

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-119

CVE-2012-0518

Oracle Fusion Middleware Unspecified Vulnerability

Vendor: Oracle

Product: Fusion Middleware

Added: 2022-03-28

Due Date: 2022-04-18

Description:

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware allows remote attackers to affect integrity via Unknown vectors

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-601

CVE-2011-2005

Microsoft Ancillary Function Driver (afd.sys) Improper Input Validation Vulnerability

Vendor: Microsoft

Product: Ancillary Function Driver (afd.sys)

Added: 2022-03-28

Due Date: 2022-04-18

Description:

afd.sys in the Ancillary Function Driver in Microsoft Windows does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264

CVE-2010-4398

Microsoft Windows Kernel Stack-Based Buffer Overflow Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-28

Due Date: 2022-04-21

Description:

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows allows local users to gain privileges, and bypass the User Account Control (UAC) feature.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2022-26318

WatchGuard Firebox and XTM Appliances Arbitrary Code Execution

Vendor: WatchGuard

Product: Firebox and XTM Appliances

Added: 2022-03-25

Due Date: 2022-04-15

Description:

On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-122

CVE-2022-26143

MiCollab, MiVoice Business Express Access Control Vulnerability

Vendor: Mitel

Product: MiCollab, MiVoice Business Express

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A vulnerability has been identified in MiCollab and MiVoice Business Express that may allow a malicious actor to gain unauthorized access to sensitive information and services, cause performance degradations or a denial of service condition on the affected system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-306 CWE-406

CVE-2022-21999

Ransomware

Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-40 CWE-1386

CVE-2021-42237

Ransomware

Sitecore XP Remote Command Execution Vulnerability

Vendor: Sitecore

Product: XP

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Sitcore XP contains an insecure deserialization vulnerability which can allow for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2021-22941

Ransomware

Citrix ShareFile Improper Access Control Vulnerability

Vendor: Citrix

Product: ShareFile

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Improper Access Control in Citrix ShareFile storage zones controller may allow an unauthenticated attacker to remotely compromise the storage zones controller.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2020-9377

D-Link DIR-610 Devices Remote Command Execution

Vendor: D-Link

Product: DIR-610 Devices

Added: 2022-03-25

Due Date: 2022-04-15

Description:

D-Link DIR-610 devices allow remote code execution via the cmd parameter to command.php.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-78

CVE-2020-9054

Zyxel Multiple NAS Devices OS Command Injection Vulnerability

Vendor: Zyxel

Product: Multiple Network-Attached Storage (NAS) Devices

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Multiple Zyxel network-attached storage (NAS) devices contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78

CVE-2020-7247

OpenSMTPD Remote Code Execution Vulnerability

Vendor: OpenBSD

Product: OpenSMTPD

Added: 2022-03-25

Due Date: 2022-04-15

Description:

smtp_mailaddr in smtp_session.c in OpenSMTPD, as used in OpenBSD and other products, allows remote attackers to execute arbitrary commands as root via a crafted SMTP session.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-755 CWE-78

CVE-2020-5410

VMware Tanzu Spring Cloud Config Directory Traversal Vulnerability

Vendor: VMware Tanzu

Product: Spring Cloud Configuration (Config) Server

Added: 2022-03-25

Due Date: 2022-04-15

Description:

Spring, by VMware Tanzu, Cloud Config contains a path traversal vulnerability that allows applications to serve arbitrary configuration files.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-23

CVE-2020-25223

Sophos SG UTM Remote Code Execution Vulnerability

Vendor: Sophos

Product: SG UTM

Added: 2022-03-25

Due Date: 2022-04-15

Description:

A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-78