CISA Known Exploited Vulnerabilities

This dashboard displays the latest vulnerabilities published by the Cybersecurity & Infrastructure Security Agency (CISA).

CVE-2017-0199

Ransomware

Microsoft Office and WordPad Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Office and WordPad

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CVE-2020-1380

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2019-1429

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-416 CWE-787

CVE-2017-11774

Microsoft Office Outlook Security Feature Bypass Vulnerability

Vendor: Microsoft

Product: Office

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-119

CVE-2020-0968

Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability

Vendor: Microsoft

Product: Internet Explorer

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2020-1472

Ransomware

Microsoft Netlogon Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Netlogon

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-330

CVE-2021-26855

Ransomware

Microsoft Exchange Server Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Exchange Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-918

CVE-2021-26858

Ransomware

Microsoft Exchange Server Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Exchange Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

Required Action:

Apply updates per vendor instructions.

CVE-2021-27065

Ransomware

Microsoft Exchange Server Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Exchange Server

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-39

CVE-2020-1054

Microsoft Win32k Privilege Escalation Vulnerability

Vendor: Microsoft

Product: Win32k

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2021-1675

Ransomware

Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-285

CVE-2021-34448

Microsoft Windows Scripting Engine Memory Corruption Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2021-11-03

Due Date: 2021-11-17

Description:

Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-787

CVE-2020-0601

Microsoft Windows CryptoAPI Spoofing Vulnerability

Vendor: Microsoft

Product: Windows

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-295

CVE-2019-0604

Ransomware

Microsoft SharePoint Remote Code Execution Vulnerability

Vendor: Microsoft

Product: SharePoint

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-20

CVE-2020-0646

Microsoft .NET Framework Remote Code Execution Vulnerability

Vendor: Microsoft

Product: .NET Framework

Added: 2021-11-03

Due Date: 2022-05-03

Description:

Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution.

Required Action:

Apply updates per vendor instructions.

CWEs:

CWE-91