CISA Catalog
Data sourced from the official CISA Known Exploited Vulnerabilities Catalog. Federal agencies are required to remediate these vulnerabilities by the due date per BOD 22-01.
KEV Entries
1,619
Ransomware Use
327
Overdue
1,615
Vendors
266
Products
655
377 results · Page 6/16
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Microsoft · Windows
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Graphic Component Privilege Escalation Vulnerability
Microsoft · Windows
Microsoft Windows Graphic Component contains an unspecified vulnerability that allows for privilege escalation.
Required Action
Apply updates per vendor instructions.
Microsoft Exchange Server Privilege Escalation Vulnerability
Microsoft · Exchange Server
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Advanced Local Procedure Call (ALPC) Privilege Escalation Vulnerability
Microsoft · Windows
Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation.
Required Action
Apply updates per vendor instructions.
Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
Microsoft · Defender
Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Microsoft · Windows
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Microsoft · Windows
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Microsoft · Windows
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
Required Action
Apply updates per vendor instructions.
Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability
Microsoft · Windows
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Scripting Languages Remote Code Execution Vulnerability
Microsoft · Windows
Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution.
Required Action
Apply updates per vendor instructions.
Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability
Microsoft · Windows COM+ Event System Service
Microsoft Windows COM+ Event System Service contains an unspecified vulnerability that allows for privilege escalation.
Required Action
Apply updates per vendor instructions.
Microsoft Exchange Server Remote Code Execution Vulnerability
Microsoft · Exchange Server
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.
Required Action
Apply updates per vendor instructions.
Microsoft Exchange Server Server-Side Request Forgery Vulnerability
Microsoft · Exchange Server
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Remote Code Execution Vulnerability
Microsoft · Windows
Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Microsoft · Windows
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
Required Action
Apply updates per vendor instructions.
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
Microsoft · Active Directory
An authenticated user could manipulate attributes on computer accounts they own or manage, and acquire a certificate from Active Directory Certificate Services that would allow for privilege escalation to SYSTEM.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Runtime Remote Code Execution Vulnerability
Microsoft · Windows
Microsoft Windows Runtime contains an unspecified vulnerability that allows for remote code execution.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft · Windows
A remote code execution vulnerability exists when Microsoft Windows MSDT is called using the URL protocol from a calling application.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability
Microsoft · Windows
Microsoft Windows CSRSS contains an unspecified vulnerability that allows for privilege escalation to SYSTEM privileges.
Required Action
Apply updates per vendor instructions.
Microsoft Windows LSA Spoofing Vulnerability
Microsoft · Windows
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM.
Required Action
Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Microsoft · Windows
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
Required Action
Apply updates per vendor instructions.
Microsoft Office Buffer Overflow Vulnerability
Microsoft · Office
Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via crafted PNG data in an Office document.
Required Action
Apply updates per vendor instructions.
Microsoft Internet Explorer Use-After-Free Vulnerability
Microsoft · Internet Explorer
Microsoft Internet Explorer contains a use-after-free vulnerability that allows remote attackers to execute code via a crafted web site.
Required Action
Apply updates per vendor instructions.
Microsoft XML Core Services Memory Corruption Vulnerability
Microsoft · XML Core Services
Microsoft XML Core Services contains a memory corruption vulnerability which could allow for remote code execution.
Required Action
Apply updates per vendor instructions.
Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability
Microsoft · Windows
The Authenticode Signature Verification function in Microsoft Windows (WinVerifyTrust) does not properly validate the digest of a signed portable executable (PE) file, which allows user-assisted remote attackers to execute code.
Required Action
Apply updates per vendor instructions.