CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2012-1535

Adobe Flash Player Arbitrary Code Execution Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Unspecified vulnerability in Adobe Flash Player allows remote attackers to execute arbitrary code or cause a denial of service via crafted SWF content.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-0507

Ransomware

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Vendor: Oracle

Product: Java SE

Added: 2022-03-03

Due Date: 2022-03-24

Description:

An incorrect type vulnerability exists in the Concurrency component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CVE-2011-3544

Oracle Java SE Runtime Environment (JRE) Arbitrary Code Execution Vulnerability

Vendor: Oracle

Product: Java SE JDK and JRE

Added: 2022-03-03

Due Date: 2022-03-24

Description:

An access control vulnerability exists in the Applet Rhino Script Engine component of Oracle's Java Runtime Environment allows an attacker to remotely execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CVE-2011-1889

Microsoft Forefront TMG Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Forefront Threat Management Gateway (TMG)

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2011-0611

Adobe Flash Player Remote Code Execution Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Adobe Flash Player contains a vulnerability that allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via crafted Flash content.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-843

CVE-2010-3333

Microsoft Office Stack-based Buffer Overflow Vulnerability

Vendor: Microsoft

Product: Office

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A stack-based buffer overflow vulnerability exists in the parsing of RTF data in Microsoft Office and earlier allows an attacker to perform remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2010-0232

Microsoft Windows Kernel Exception Handler Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264

CVE-2010-0188

Ransomware

Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability

Vendor: Adobe

Product: Reader and Acrobat

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2009-3129

Microsoft Excel Featheader Record Memory Corruption Vulnerability

Vendor: Microsoft

Product: Excel

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Microsoft Office Excel allows remote attackers to execute arbitrary code via a spreadsheet with a FEATHEADER record containing an invalid cbHdrData size element that affects a pointer offset.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-94

CVE-2009-1123

Microsoft Windows Improper Input Validation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-03

Due Date: 2022-03-24

Description:

The kernel in Microsoft Windows does not properly validate changes to unspecified kernel objects, which allows local users to gain privileges via a crafted application.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2008-3431

Oracle VirtualBox Insufficient Input Validation Vulnerability

Vendor: Oracle

Product: VirtualBox

Added: 2022-03-03

Due Date: 2022-03-24

Description:

An input validation vulnerability exists in the VBoxDrv.sys driver of Sun xVM VirtualBox which allows attackers to locally execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264

CVE-2008-2992

Adobe Reader and Acrobat Input Validation Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2022-03-03

Due Date: 2022-03-24

Description:

Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2004-0210

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-03

Due Date: 2022-03-24

Description:

A privilege elevation vulnerability exists in the POSIX subsystem. This vulnerability could allow a logged on user to take complete control of the system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-120

CVE-2002-0367

Microsoft Windows Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2022-03-03

Due Date: 2022-03-24

Description:

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges.

Required Action:

Apply updates per vendor instructions.

CVE-2022-24682

Ransomware

Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting Vulnerability

Vendor: Synacor

Product: Zimbra Collaborate Suite (ZCS)

Added: 2022-02-25

Due Date: 2022-03-11

Description:

Synacor Zimbra Collaboration Suite (ZCS) contains a cross-site scripting (XSS) vulnerability in the Calendar feature that allows an attacker to execute arbitrary code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-79 CWE-116