CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2016-3715

ImageMagick Arbitrary File Deletion Vulnerability

Vendor: ImageMagick

Product: ImageMagick

Added: 2021-11-03

Due Date: 2022-05-03

Description:

ImageMagick contains an unspecified vulnerability that could allow users to delete files by using ImageMagick's 'ephemeral' pseudo protocol, which deletes files after reading.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2016-3718

ImageMagick Server-Side Request Forgery (SSRF) Vulnerability

Vendor: ImageMagick

Product: ImageMagick

Added: 2021-11-03

Due Date: 2022-05-03

Description:

ImageMagick contains an unspecified vulnerability that allows attackers to perform server-side request forgery (SSRF) via a crafted image.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2020-15505

Ivanti MobileIron Multiple Products Remote Code Execution Vulnerability

Vendor: Ivanti

Product: MobileIron Multiple Products

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Ivanti MobileIron's Core & Connector, Sentry, and Monitor and Reporting Database (RDB) products contain an unspecified vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-706

CVE-2021-30116

Ransomware

Kaseya Virtual System/Server Administrator (VSA) Information Disclosure Vulnerability

Vendor: Kaseya

Product: Virtual System/Server Administrator (VSA)

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Kaseya Virtual System/Server Administrator (VSA) contains an information disclosure vulnerability allowing an attacker to obtain the sessionId that can be used to execute further attacks against the system.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-522

CVE-2020-7961

Liferay Portal Deserialization of Untrusted Data Vulnerability

Vendor: Liferay

Product: Liferay Portal

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Liferay Portal contains a deserialization of untrusted data vulnerability that allows remote attackers to execute code via JSON web services.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2021-23874

McAfee Total Protection (MTP) Improper Privilege Management Vulnerability

Vendor: McAfee

Product: McAfee Total Protection (MTP)

Added: 2021-11-03

Due Date: 2021-11-17

Description:

McAfee Total Protection (MTP) contains an improper privilege management vulnerability that allows a local user to gain elevated privileges and execute code, bypassing MTP self-defense.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-284

CVE-2021-22506

Micro Focus Access Manager Information Leakage Vulnerability

Vendor: Micro Focus

Product: Micro Focus Access Manager

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Micro Focus Access Manager contains an information leakage vulnerability resulting from a SAML service provider redirection issue when the Assertion Consumer Service URL is used.

Required Action:

Apply updates per vendor instructions.

CVE-2021-22502

Micro Focus Operation Bridge Report (OBR) Remote Code Execution Vulnerability

Vendor: Micro Focus

Product: Operation Bridge Reporter (OBR)

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Micro Focus Operation Bridge Report (OBR) contains an unspecified vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-78

CVE-2014-1812

Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-255

CVE-2021-38647

Ransomware

Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Open Management Infrastructure (OMI)

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-1390

CVE-2016-0167

Ransomware

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Win32k

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-264

CVE-2020-0878

Ransomware

Microsoft Edge and Internet Explorer Memory Corruption Vulnerability

Vendor: Microsoft

Product: Edge and Internet Explorer

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-31955

Microsoft Windows Kernel Information Disclosure Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Microsoft Windows Kernel contains an unspecified vulnerability that allows for information disclosure. Successful exploitation allows attackers to read the contents of kernel memory from a user-mode process.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-497

CVE-2021-1647

Microsoft Defender Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Defender

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Microsoft Defender contains an unspecified vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-122 CWE-1285

CVE-2021-33739

Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Microsoft Desktop Window Manager (DWM) Core Library contains an unspecified vulnerability that allows for privilege escalation.

Required Action:

Apply updates per vendor instructions.