CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2021-42292

Microsoft Excel Security Feature Bypass

Vendor: Microsoft

Product: Office

Added: 2021-11-17

Due Date: 2021-12-01

Description:

A security feature bypass vulnerability in Microsoft Excel would allow a local user to perform arbitrary code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-357

CVE-2021-27104

Ransomware

Accellion FTA OS Command Injection Vulnerability

Vendor: Accellion

Product: FTA

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Accellion FTA contains an OS command injection vulnerability exploited via a crafted POST request to various admin endpoints.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-78

CVE-2021-27102

Ransomware

Accellion FTA OS Command Injection Vulnerability

Vendor: Accellion

Product: FTA

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Accellion FTA contains an OS command injection vulnerability exploited via a local web service call.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20 CWE-78

CVE-2021-27101

Ransomware

Accellion FTA SQL Injection Vulnerability

Vendor: Accellion

Product: FTA

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Accellion FTA contains a SQL injection vulnerability exploited via a crafted host header in a request to document_root.html.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-89 CWE-138

CVE-2021-27103

Ransomware

Accellion FTA Server-Side Request Forgery (SSRF) Vulnerability

Vendor: Accellion

Product: FTA

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Accellion FTA contains a server-side request forgery (SSRF) vulnerability exploited via a crafted POST request to wmProgressstat.html.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-918

CVE-2021-21017

Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Acrobat Acrobat and Reader contain a heap-based buffer overflow vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-122

CVE-2021-28550

Adobe Acrobat and Reader Use-After-Free Vulnerability

Vendor: Adobe

Product: Acrobat and Reader

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2018-4939

Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502

CVE-2018-15961

Adobe ColdFusion Unrestricted File Upload Vulnerability

Vendor: Adobe

Product: ColdFusion

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Adobe ColdFusion contains an unrestricted file upload vulnerability that could allow for code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-434

CVE-2018-4878

Ransomware

Adobe Flash Player Use-After-Free Vulnerability

Vendor: Adobe

Product: Flash Player

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.

Required Action:

The impacted product is end-of-life and should be disconnected if still in use.

CWEs:

CWE-416

CVE-2020-5735

Amcrest Cameras and NVR Stack-based Buffer Overflow Vulnerability

Vendor: Amcrest

Product: Cameras and Network Video Recorder (NVR)

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Amcrest cameras and NVR contain a stack-based buffer overflow vulnerability through port 37777 that allows an unauthenticated, remote attacker to crash the device and possibly execute code.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-121

CVE-2019-2215

Android Kernel Use-After-Free Vulnerability

Vendor: Android

Product: Android Kernel

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Android Kernel contains a use-after-free vulnerability in binder.c that allows for privilege escalation from an application to the Linux Kernel. This vulnerability was observed chained with CVE-2020-0041 and CVE-2020-0069 under exploit chain "AbstractEmu."

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416

CVE-2020-0041

Android Kernel Out-of-Bounds Write Vulnerability

Vendor: Android

Product: Android Kernel

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Android Kernel binder_transaction of binder.c contains an out-of-bounds write vulnerability due to an incorrect bounds check that could allow for local privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0069 under exploit chain "AbstractEmu."

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2020-0069

Mediatek Multiple Chipsets Insufficient Input Validation Vulnerability

Vendor: MediaTek

Product: Multiple Chipsets

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Multiple MediaTek chipsets contain an insufficient input validation vulnerability and have missing SELinux restrictions in the Command Queue drivers ioctl handlers. This causes an out-of-bounds write leading to privilege escalation. This vulnerability was observed chained with CVE-2019-2215 and CVE-2020-0041 under exploit chain "AbstractEmu."

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2017-9805

Apache Struts Deserialization of Untrusted Data Vulnerability

Vendor: Apache

Product: Struts

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Apache Struts REST Plugin uses an XStreamHandler with an instance of XStream for deserialization without any type filtering, which can lead to remote code execution when deserializing XML payloads.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-502