CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2021-40449

Ransomware

Microsoft Windows Win32k Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2021-11-17

Due Date: 2021-12-01

Description:

Unspecified vulnerability allows for an authenticated user to escalate privileges.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2021-42321

Ransomware

Microsoft Exchange Server Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Exchange

Added: 2021-11-17

Due Date: 2021-12-01

Description:

An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-184 CWE-502

CVE-2021-42292

Microsoft Excel Security Feature Bypass

Vendor: Microsoft

Product: Office

Added: 2021-11-17

Due Date: 2021-12-01

Description:

A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-357

CVE-2021-27104

Ransomware

Accellion FTA OS Command Injection Vulnerability

Vendor: Accellion

Product: FTA

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-78

CVE-2021-27102

Ransomware

Accellion FTA OS Command Injection Vulnerability

Vendor: Accellion

Product: FTA

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-78

CVE-2021-27101

Ransomware

Accellion FTA SQL Injection Vulnerability

Vendor: Accellion

Product: FTA

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-89 CWE-138

CVE-2021-27103

Ransomware

Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

Vendor: Accellion

Product: FTA

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-918

CVE-2021-21017

Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-122

CVE-2021-28550

Adobe Acrobat and Reader Use-After-Free Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2018-4939

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2018-15961

Adobe ColdFusion Unrestricted File Upload Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-434

CVE-2018-4878

Ransomware

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-416

CVE-2020-5735

Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

Vendor: Amcrest

Product: Cameras and Network Video Recorder (NVR)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-121

CVE-2019-2215

Android Kernel Use-After-Free Vulnerability

Vendor: Android

Product: Android Kernel

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2020-0041

Android Kernel Out-of-Bounds Write Vulnerability

Vendor: Android

Product: Android Kernel

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20