target entity

Microsoft

381 source-linked records in the current knowledge graph.

high

CVE-2026-58644: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-58644EPSS 1.5%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2026-56155: Microsoft Active Directory Federation Services Insufficient Granularity of Access Control Vulnerability

Microsoft Active Directory Federation Services contains an insufficient granularity of access control vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-56155EPSS 0.4%Active Directory Federation ServicesMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-56164: Microsoft SharePoint Server Missing Authentication for Critical Function Vulnerability

Microsoft SharePoint contains a missing authentication for critical function vulnerability that allows an unauthorized attacker to elevate privileges over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-56164EPSS 5.6%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2026-45659: Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network. Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

CVE-2026-45659EPSS 3.2%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2008-4250: Microsoft Windows Buffer Overflow Vulnerability

Microsoft Windows contains a buffer overflow vulnerability in the Windows Server Service that allows remote attackers to execute arbitrary code via a crafted RPC request that triggers an overflow during path canonicalization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2008-4250EPSS 98.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2009-1537: Microsoft DirectX NULL Byte Overwrite Vulnerability

Microsoft DirectX contains a NULL byte overwrite vulnerability in the QuickTime Movie Parser Filter in quartz.dll in DirectShow which could allow remote attackers to execute arbitrary code via a crafted QuickTime media file. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2009-1537EPSS 51.2%DirectXMicrosoft
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2010-0249: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code by accessing a pointer associated with a deleted object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-0249EPSS 91.9%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0806: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains an use-after-free vulnerability that could allow remote attackers to execute arbitrary code via vectors involving access to an invalid pointer after the deletion of an object. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-0806EPSS 82.2%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-41091: Microsoft Defender Link Following Vulnerability

Microsoft Defender contains a link following vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-41091EPSS 8.4%DefenderMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-45498: Microsoft Defender Denial of Service Vulnerability

Microsoft Defender contains an unspecified vulnerability that allows for denial of service. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-45498EPSS 63.1%DefenderMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-42897: Microsoft Exchange Server Cross-Site Scripting Vulnerability

Microsoft Exchange Server contains a cross-site scripting vulnerability during web page generation in Outlook Web Access and when certain interaction conditions are met, arbitrary JavaScript can be executed in the browser context. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-42897EPSS 5.6%Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-32202: Microsoft Windows Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-32202EPSS 64.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-33825: Microsoft Defender Insufficient Granularity of Access Control Vulnerability

Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-33825EPSS 6.7%DefenderMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2009-0238: Microsoft Office Remote Code Execution

Microsoft Office Excel contains a remote code execution vulnerability that could allow an attacker to take complete control of an affected system if a user opens a specially crafted Excel file that includes a malformed object. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2009-0238EPSS 43.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2026-32201: Microsoft SharePoint Server Improper Input Validation Vulnerability

Microsoft SharePoint Server contains an improper input validation vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-32201EPSS 22.8%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2012-1854: Microsoft Visual Basic for Applications Insecure Library Loading Vulnerability

Microsoft Visual Basic for Applications (VBA) contains an insecure library loading vulnerability that could allow for remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2012-1854EPSS 21.0%MicrosoftVisual Basic for Applications (VBA)
CISA KEV ↗ · unattributed attribution
high

CVE-2025-60710: Microsoft Windows Link Following Vulnerability

Microsoft Windows contains a link following vulnerability that allows for privilege escalation Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-60710EPSS 4.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-21529: Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability

Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-21529EPSS 62.1%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36424: Microsoft Windows Out-of-Bounds Read Vulnerability

Microsoft Windows Common Log File System Driver contains an out-of-bounds read vulnerability that could allow a threat actor for privileges escalation Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2023-36424EPSS 12.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20963: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint contains a deserialization of untrusted data vulnerability that allows an unauthorized attacker to execute code over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20963EPSS 29.4%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2008-0015: Microsoft Windows Video ActiveX Control Remote Code Execution Vulnerability

Microsoft Windows Video ActiveX Control contains a remote code execution vulnerability. An attacker could exploit the vulnerability by constructing a specially crafted Web page. When a user views the Web page, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the logged-on user. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2008-0015EPSS 76.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability

Microsoft Configuration Manager contains an SQL injection vulnerability. An unauthenticated attacker could exploit this vulnerability by sending specially crafted requests to the target environment which are processed in an unsafe manner enabling the attacker to execute commands on the server and/or underlying database. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-43468EPSS 61.1%Configuration ManagerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21513: Microsoft MSHTML Framework Protection Mechanism Failure Vulnerability

Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21513EPSS 15.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21525: Microsoft Windows NULL Pointer Dereference Vulnerability

Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21525EPSS 5.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21510: Microsoft Windows Shell Protection Mechanism Failure Vulnerability

Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21510EPSS 25.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21533: Microsoft Windows Improper Privilege Management Vulnerability

Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21533EPSS 3.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21519: Microsoft Windows Type Confusion Vulnerability

Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21519EPSS 2.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21514: Microsoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability

Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21514EPSS 1.5%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2026-21509: Microsoft Office Security Feature Bypass Vulnerability

Microsoft Office contains a security feature bypass vulnerability in which reliance on untrusted inputs in a security decision in Microsoft Office could allow an unauthorized attacker to bypass a security feature locally. Some of the impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-21509EPSS 72.2%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2026-20805: Microsoft Windows Information Disclosure Vulnerability

Microsoft Windows Desktop Windows Manager contains an information disclosure vulnerability that allows an authorized attacker to disclose information locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2026-20805EPSS 5.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2009-0556: Microsoft Office PowerPoint Code Injection Vulnerability

Microsoft Office PowerPoint contains a code injection vulnerability that allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an invalid index value that triggers memory corruption. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2009-0556EPSS 67.5%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2025-62221: Microsoft Windows Use After Free Vulnerability

Microsoft Windows Cloud Files Mini Filter Driver contains a use after free vulnerability that can allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-62221EPSS 2.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-62215: Microsoft Windows Race Condition Vulnerability

Microsoft Windows Kernel contains a race condition vulnerability that allows a local attacker with low-level privileges to escalate privileges. Successful exploitation of this vulnerability could enable the attacker to gain SYSTEM-level access. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-62215EPSS 6.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-59287: Microsoft Windows Server Update Service (WSUS) Deserialization of Untrusted Data Vulnerability

Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-59287EPSS 100.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-33073: Microsoft Windows SMB Client Improper Access Control Vulnerability

Microsoft Windows SMB Client contains an improper access control vulnerability that could allow for privilege escalation. An attacker could execute a specially crafted malicious script to coerce the victim machine to connect back to the attack system using SMB and authenticate. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-33073EPSS 65.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24990: Microsoft Windows Untrusted Pointer Dereference Vulnerability

Microsoft Windows Agere Modem Driver contains an untrusted pointer dereference vulnerability that allows for privilege escalation. An attacker who successfully exploited this vulnerability could gain administrator privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24990EPSS 6.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-59230: Microsoft Windows Improper Access Control Vulnerability

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-59230EPSS 2.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2010-3962: Microsoft Internet Explorer Uninitialized Memory Corruption Vulnerability

Microsoft Internet Explorer contains an uninitialized memory corruption vulnerability that could allow for remote code execution. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2010-3962EPSS 96.9%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2021-43226: Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows Common Log File System Driver contains a privilege escalation vulnerability that could allow a local, privileged attacker to bypass certain security mechanisms. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2021-43226EPSS 3.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3918: Microsoft Windows Out-of-Bounds Write Vulnerability

Microsoft Windows contains an out-of-bounds write vulnerability in the InformationCardSigninHelper Class ActiveX control, icardie.dll. An attacker could exploit the vulnerability by constructing a specially crafted webpage. When a user views the webpage, the vulnerability could allow remote code execution. An attacker who successfully exploited this vulnerability could gain the same user rights as the current user. The impacted product could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3918EPSS 73.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2011-3402: Microsoft Windows Remote Code Execution Vulnerability

Microsoft Windows Kernel contains an unspecified vulnerability in the TrueType font parsing engine in win32k.sys in the kernel-mode drivers that allows remote attackers to execute arbitrary code via crafted font data in a Word document or web page. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2011-3402EPSS 78.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2007-0671: Microsoft Office Excel Remote Code Execution Vulnerability

Microsoft Office Excel contains a remote code execution vulnerability that can be exploited when a specially crafted Excel file is opened. This malicious file could be delivered as an email attachment or hosted on a malicious website. An attacker could leverage this vulnerability by creating a specially crafted Excel file, which, when opened, allowing an attacker to execute remote code on the affected system. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2007-0671EPSS 42.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3893: Microsoft Internet Explorer Resource Management Errors Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows for remote code execution. The impacted products could be end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue product utilization. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2013-3893EPSS 85.9%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2025-49704: Microsoft SharePoint Code Injection Vulnerability

Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. Required action: Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-49704CVE-2025-49706EPSS 100.0%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2025-49706: Microsoft SharePoint Improper Authentication Vulnerability

Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706. Required action: Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-49704CVE-2025-49706EPSS 99.9%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2025-53770: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704. Required action: Disconnect public-facing versions of SharePoint Server that have reached their end-of-life (EOL) or end-of-service (EOS) to include SharePoint Server 2013 and earlier versions. For supported versions, please follow the mitigations according to CISA (URL listed below in Notes) and vendor instructions (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

CVE-2025-49704CVE-2025-53770EPSS 100.0%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2025-33053: Microsoft Windows External Control of File Name or Path Vulnerability

Microsoft Windows contains an external control of file name or path vulnerability that could allow an attacker to execute code from a remote WebDAV location specified by the WorkingDirectory attribute of Internet Shortcut files. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-33053EPSS 81.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32709: Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to escalate privileges to administrator. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32709EPSS 1.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-30397: Microsoft Windows Scripting Engine Type Confusion Vulnerability

Microsoft Windows Scripting Engine contains a type confusion vulnerability that allows an unauthorized attacker to execute code over a network via a specially crafted URL. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-30397EPSS 21.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32706: Microsoft Windows Common Log File System (CLFS) Driver Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a heap-based buffer overflow vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32706EPSS 2.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-32701: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-32701EPSS 1.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-30400: Microsoft Windows DWM Core Library Use-After-Free Vulnerability

Microsoft Windows DWM Core Library contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-30400EPSS 1.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24054: Microsoft Windows NTLM Hash Disclosure Spoofing Vulnerability

Microsoft Windows NTLM contains an external control of file name or path vulnerability that allows an unauthorized attacker to perform spoofing over a network. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24054EPSS 59.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-29824: Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability

Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-29824EPSS 13.5%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24993: Microsoft Windows NTFS Heap-Based Buffer Overflow Vulnerability

Microsoft Windows New Technology File System (NTFS) contains a heap-based buffer overflow vulnerability that allows an unauthorized attacker to execute code locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24993EPSS 2.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24991: Microsoft Windows NTFS Out-Of-Bounds Read Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an out-of-bounds read vulnerability that allows an authorized attacker to disclose information locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24991EPSS 1.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24985: Microsoft Windows Fast FAT File System Driver Integer Overflow Vulnerability

Microsoft Windows Fast FAT File System Driver contains an integer overflow or wraparound vulnerability that allows an unauthorized attacker to execute code locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24985EPSS 3.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24984: Microsoft Windows NTFS Information Disclosure Vulnerability

Microsoft Windows New Technology File System (NTFS) contains an insertion of sensitive Information into log file vulnerability that allows an unauthorized attacker to disclose information with a physical attack. An attacker who successfully exploited this vulnerability could potentially read portions of heap memory. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24984EPSS 1.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24983: Microsoft Windows Win32k Use-After-Free Vulnerability

Microsoft Windows Win32 Kernel Subsystem contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24983EPSS 1.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-26633: Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-26633EPSS 31.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2018-8639: Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability

Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2018-8639EPSS 22.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-49035: Microsoft Partner Center Improper Access Control Vulnerability

Microsoft Partner Center contains an improper access control vulnerability that allows an attacker to escalate privileges. Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2024-49035EPSS 1.3%MicrosoftPartner Center
CISA KEV ↗ · unattributed attribution
high

CVE-2025-24989: Microsoft Power Pages Improper Access Control Vulnerability

Microsoft Power Pages contains an improper access control vulnerability that allows an unauthorized attacker to elevate privileges over a network potentially bypassing the user registration control. Required action: Apply mitigations per vendor instructions, follow BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

CVE-2025-24989EPSS 1.7%MicrosoftPower Pages
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21418: Microsoft Windows Ancillary Function Driver for WinSock Heap-Based Buffer Overflow Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains a heap-based buffer overflow vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-21418EPSS 1.5%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2025-21391: Microsoft Windows Storage Link Following Vulnerability

Microsoft Windows Storage contains a link following vulnerability that could allow for privilege escalation. This vulnerability could allow an attacker to delete data including data that results in the service being unavailable. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2025-21391EPSS 2.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21413: Microsoft Outlook Improper Input Validation Vulnerability

Microsoft Outlook contains an improper input validation vulnerability that allows for remote code execution. Successful exploitation of this vulnerability would allow an attacker to bypass the Office Protected View and open in editing mode rather than protected mode. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21413EPSS 94.7%MicrosoftOffice Outlook
CISA KEV ↗ · unattributed attribution
high

CVE-2024-29059: Microsoft .NET Framework Information Disclosure Vulnerability

Microsoft .NET Framework contains an information disclosure vulnerability that exposes the ObjRef URI to an attacker, ultimately enabling remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-29059EPSS 98.6%.NET FrameworkMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43451: Microsoft Windows NTLMv2 Hash Disclosure Spoofing Vulnerability

Microsoft Windows contains an NTLMv2 hash spoofing vulnerability that could result in disclosing a user's NTLMv2 hash to an attacker via a file open operation. The attacker could then leverage this hash to impersonate that user. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-43451EPSS 81.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-49039: Microsoft Windows Task Scheduler Privilege Escalation Vulnerability

Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-49039EPSS 13.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38094: Microsoft SharePoint Deserialization Vulnerability

Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38094EPSS 47.8%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2024-30088: Microsoft Windows Kernel TOCTOU Race Condition Vulnerability

Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-30088EPSS 68.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43573: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-43573EPSS 43.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0618: Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2020-0618EPSS 99.0%MicrosoftSQL Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-43461: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38112CVE-2024-43461EPSS 84.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38217: Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability

Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38217EPSS 9.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38226: Microsoft Publisher Protection Mechanism Failure Vulnerability

Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38226EPSS 2.7%MicrosoftPublisher
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38107: Microsoft Windows Power Dependency Coordinator Privilege Escalation Vulnerability

Microsoft Windows Power Dependency Coordinator contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to obtain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38107EPSS 1.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38106: Microsoft Windows Kernel Privilege Escalation Vulnerability

Microsoft Windows Kernel contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Successful exploitation of this vulnerability requires an attacker to win a race condition. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38106EPSS 6.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38193: Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38193EPSS 27.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38213: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience via a malicious file. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38213EPSS 13.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38178: Microsoft Windows Scripting Engine Memory Corruption Vulnerability

Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38178EPSS 39.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38189: Microsoft Project Remote Code Execution Vulnerability

Microsoft Project contains an unspecified vulnerability that allows for remote code execution via a malicious file. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38189EPSS 7.9%MicrosoftProject
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0824: Microsoft COM for Windows Deserialization of Untrusted Data Vulnerability

Microsoft COM for Windows contains a deserialization of untrusted data vulnerability that allows for privilege escalation and remote code execution via a specially crafted file or script. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2018-0824EPSS 73.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2012-4792: Microsoft Internet Explorer Use-After-Free Vulnerability

Microsoft Internet Explorer contains a use-after-free vulnerability that allows a remote attacker to execute arbitrary code via a crafted web site that triggers access to an object that (1) was not properly allocated or (2) is deleted, as demonstrated by a CDwnBindInfo object. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2012-4792EPSS 78.8%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38080: Microsoft Windows Hyper-V Privilege Escalation Vulnerability

Microsoft Windows Hyper-V contains a privilege escalation vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38080EPSS 7.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-38112: Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains a spoofing vulnerability that has a high impact to confidentiality, integrity, and availability. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-38112EPSS 84.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2024-29988: Microsoft SmartScreen Prompt Security Feature Bypass Vulnerability

Microsoft SmartScreen Prompt contains a security feature bypass vulnerability that allows an attacker to bypass the Mark of the Web (MotW) feature. This vulnerability can be chained with CVE-2023-38831 and CVE-2024-21412 to execute a malicious file. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-38831CVE-2024-21412EPSS 97.8%MicrosoftSmartScreen Prompt
CISA KEV ↗ · unattributed attribution
high

CVE-2022-38028: Microsoft Windows Print Spooler Privilege Escalation Vulnerability

Microsoft Windows Print Spooler service contains a privilege escalation vulnerability. An attacker may modify a JavaScript constraints file and execute it with SYSTEM-level permissions. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2022-38028EPSS 14.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-24955: Microsoft SharePoint Server Code Injection Vulnerability

Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-24955EPSS 85.4%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21338: Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability

Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21338EPSS 51.9%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2023-29360: Microsoft Streaming Service Untrusted Pointer Dereference Vulnerability

Microsoft Streaming Service contains an untrusted pointer dereference vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-29360EPSS 22.1%MicrosoftStreaming Service
CISA KEV ↗ · unattributed attribution
high

CVE-2024-21351: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that allows an attacker to bypass the SmartScreen user experience and inject code to potentially gain code execution, which could lead to some data exposure, lack of system availability, or both. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2024-21351EPSS 30.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-29357: Microsoft SharePoint Server Privilege Escalation Vulnerability

Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-29357EPSS 99.6%MicrosoftSharePoint Server
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36025: Microsoft Windows SmartScreen Security Feature Bypass Vulnerability

Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to bypass Windows Defender SmartScreen checks and their associated prompts. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36025EPSS 88.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-28229: Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability

Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability that allows an attacker to gain specific limited SYSTEM privileges. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-28229EPSS 1.9%MicrosoftWindows CNG Key Isolation Service
CISA KEV ↗ · unattributed attribution
high

CVE-2023-36884: Microsoft Windows Search Remote Code Execution Vulnerability

Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CVE-2023-36884EPSS 99.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2023-35311: Microsoft Outlook Security Feature Bypass Vulnerability

Microsoft Outlook contains a security feature bypass vulnerability that allows an attacker to bypass the Microsoft Outlook Security Notice prompt. Required action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.

CVE-2023-35311EPSS 15.5%MicrosoftOutlook
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3163: Microsoft Internet Explorer Memory Corruption Vulnerability

Microsoft Internet Explorer contains a memory corruption vulnerability that allows remote attackers to execute code or cause a denial of service via a crafted website. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2013-3163EPSS 70.7%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2022-41080: Microsoft Exchange Server Privilege Escalation Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. Required action: Apply updates per vendor instructions.

CVE-2022-41080CVE-2022-41082EPSS 100.0%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2022-41082: Microsoft Exchange Server Remote Code Execution Vulnerability

Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution. Required action: Apply updates per vendor instructions.

CVE-2022-41040CVE-2022-41082EPSS 100.0%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2010-2568: Microsoft Windows Remote Code Execution Vulnerability

Microsoft Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the operating system displays the icon of a malicious shortcut file. An attacker who successfully exploited this vulnerability could execute code as the logged-on user. Required action: Apply updates per vendor instructions.

CVE-2010-2568EPSS 91.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2022-26925: Microsoft Windows LSA Spoofing Vulnerability

Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability where an attacker can coerce the domain controller to authenticate to the attacker using NTLM. Required action: Apply remediation actions outlined in CISA guidance [https://www.cisa.gov/guidance-applying-june-microsoft-patch].

CVE-2022-26925EPSS 10.5%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2022-30190: Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability

A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application. Required action: Apply updates per vendor instructions.

CVE-2022-30190EPSS 99.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2009-0563: Microsoft Office Buffer Overflow Vulnerability

Microsoft Office contains a buffer overflow vulnerability that allows remote attackers to execute code via a Word document with a crafted tag containing an invalid length field. Required action: Apply updates per vendor instructions.

CVE-2009-0563EPSS 63.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2014-4077: Microsoft IME Japanese Privilege Escalation Vulnerability

Microsoft Input Method Editor (IME) Japanese is a keyboard with Japanese characters that can be enabled on Windows systems as it is included by default (with the default set as disabled). IME Japanese contains an unspecified vulnerability when IMJPDCT.EXE (IME for Japanese) is installed which allows attackers to bypass a sandbox and perform privilege escalation. Required action: Apply updates per vendor instructions.

CVE-2014-4077EPSS 47.7%Input Method Editor (IME) JapaneseMicrosoft
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2013-3896: Microsoft Silverlight Information Disclosure Vulnerability

Microsoft Silverlight does not properly validate pointers during access to Silverlight elements, which allows remote attackers to obtain sensitive information via a crafted Silverlight application. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2013-3896EPSS 69.6%MicrosoftSilverlight
CISA KEV ↗ · unattributed attribution
high

CVE-2013-0074: Microsoft Silverlight Double Dereference Vulnerability

Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application. Required action: The impacted product is end-of-life and should be disconnected if still in use.

CVE-2013-0074EPSS 81.9%MicrosoftSilverlight
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3298: Microsoft Internet Explorer Messaging API Information Disclosure Vulnerability

An information disclosure vulnerability exists when the Microsoft Internet Messaging API improperly handles objects in memory. An attacker who successfully exploited this vulnerability could allow the attacker to test for the presence of files on disk. Required action: Apply updates per vendor instructions.

CVE-2016-3298EPSS 32.8%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1027: Microsoft Windows Kernel Privilege Escalation Vulnerability

An elevation of privilege vulnerability exists in the way that the Windows Kernel handles objects in memory. An attacker who successfully exploited the vulnerability could execute code with elevated permissions. Required action: Apply updates per vendor instructions.

CVE-2020-1027EPSS 4.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0676: Microsoft Internet Explorer Information Disclosure Vulnerability

An information disclosure vulnerability exists when Internet Explorer improperly handles objects in memory. An attacker who successfully exploited this vulnerability could test for the presence of files on disk. Required action: Apply updates per vendor instructions.

CVE-2019-0676EPSS 7.5%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0880: Microsoft Windows Privilege Escalation Vulnerability

A local elevation of privilege vulnerability exists in how splwow64.exe handles certain calls. An attacker who successfully exploited the vulnerability could elevate privileges on an affected system from low-integrity to medium-integrity. Required action: Apply updates per vendor instructions.

CVE-2019-0880EPSS 2.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2018-8589: Microsoft Win32k Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles calls to Win32k.sys. An attacker who successfully exploited this vulnerability could run remote code in the security context of the local system. Required action: Apply updates per vendor instructions.

CVE-2018-8589EPSS 3.0%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2016-7201: Microsoft Edge Memory Corruption Vulnerability

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2016-7201EPSS 79.7%EdgeMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7200: Microsoft Edge Memory Corruption Vulnerability

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2016-7200EPSS 82.5%EdgeMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-0189: Microsoft Internet Explorer Memory Corruption Vulnerability

The Microsoft JScript nd VBScript engines, as used in Internet Explorer and other products, allow attackers to execute remote code or cause a denial of service (memory corruption) via a crafted web site. Required action: Apply updates per vendor instructions.

CVE-2016-0189EPSS 93.2%Internet ExplorerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2013-3660: Microsoft Win32k Privilege Escalation Vulnerability

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft does not properly initialize a pointer for the next object in a certain list, which allows local users to gain privileges. Required action: Apply updates per vendor instructions.

CVE-2013-3660EPSS 39.6%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-0903: Microsoft GDI Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system. Required action: Apply updates per vendor instructions.

CVE-2019-0903EPSS 21.7%Graphics Device Interface (GDI)Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2019-1322: Microsoft Windows Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Required action: Apply updates per vendor instructions.

CVE-2019-1322EPSS 19.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0543: Microsoft Windows Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context. Required action: Apply updates per vendor instructions.

CVE-2019-0543EPSS 4.7%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3309: Microsoft Windows Kernel Privilege Escalation Vulnerability

A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2016-3309EPSS 20.6%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2018-8581: Microsoft Exchange Server Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server. Required action: Apply updates per vendor instructions.

CVE-2018-8581EPSS 27.4%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2017-8540: Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability

The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016, Microsoft Exchange Server 2013 and 2016, does not properly scan a specially crafted file leading to memory corruption. aka "Microsoft Malware Protection Engine Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions.

CVE-2017-8540EPSS 72.0%Malware Protection EngineMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2017-11826: Microsoft Office Remote Code Execution Vulnerability

A remote code execution vulnerability exists in Microsoft Office software when the software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. Required action: Apply updates per vendor instructions.

CVE-2017-11826EPSS 81.5%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2017-0001: Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability

The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607 allows local users to gain privileges Required action: Apply updates per vendor instructions.

CVE-2017-0001EPSS 3.1%Graphics Device Interface (GDI)Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7262: Microsoft Office Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists when Microsoft Office improperly handles input. An attacker who successfully exploited the vulnerability could execute arbitrary commands. Required action: Apply updates per vendor instructions.

CVE-2016-7262EPSS 58.2%ExcelMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-0099: Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability

A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator. Required action: Apply updates per vendor instructions.

CVE-2016-0099EPSS 37.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2015-1701: Microsoft Win32k Privilege Escalation Vulnerability

An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2015-1701EPSS 56.2%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2012-1856: Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability

The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office allows remote attackers to execute arbitrary code via a crafted (1) document or (2) web page that triggers system-state corruption. Required action: Apply updates per vendor instructions.

CVE-2012-1856EPSS 72.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2011-1889: Microsoft Forefront TMG Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the Forefront Threat Management Gateway (TMG) Firewall Client Winsock provider that could allow code execution in the security context of the client application. Required action: Apply updates per vendor instructions.

CVE-2011-1889EPSS 48.4%Forefront Threat Management Gateway (TMG)Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2010-0232: Microsoft Windows Kernel Exception Handler Vulnerability

The kernel in Microsoft Windows, when access to 16-bit applications is enabled on a 32-bit x86 platform, does not properly validate certain BIOS calls, which allows local users to gain privileges. Required action: Apply updates per vendor instructions.

CVE-2010-0232EPSS 29.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2002-0367: Microsoft Windows Privilege Escalation Vulnerability

smss.exe debugging subsystem in Microsoft Windows does not properly authenticate programs that connect to other programs, which allows local users to gain administrator or SYSTEM privileges. Required action: Apply updates per vendor instructions.

CVE-2002-0367EPSS 5.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2020-0796: Microsoft SMBv3 Remote Code Execution Vulnerability

A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client. Required action: Apply updates per vendor instructions.

CVE-2020-0796EPSS 99.8%MicrosoftSMBv3
CISA KEV ↗ · unattributed attribution
high

CVE-2021-33766: Microsoft Exchange Server Information Disclosure

Microsoft Exchange Server contains an information disclosure vulnerability which can allow an unauthenticated attacker to steal email traffic from target. Required action: Apply updates per vendor instructions.

CVE-2021-33766EPSS 97.5%Exchange ServerMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2014-1812: Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability

Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain. Required action: Apply updates per vendor instructions.

CVE-2014-1812EPSS 65.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0938: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. Required action: Apply updates per vendor instructions.

CVE-2020-0938EPSS 69.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1020: Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability

Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities. Required action: Apply updates per vendor instructions.

CVE-2020-1020EPSS 65.0%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2017-7269: Microsoft Windows Server Buffer Overflow Vulnerability

Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request. Required action: Apply updates per vendor instructions.

CVE-2017-7269EPSS 99.8%Internet Information Services (IIS)Microsoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-7255: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2016-7255EPSS 81.0%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0708: Microsoft Remote Desktop Services Remote Code Execution Vulnerability

Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep. Required action: Apply updates per vendor instructions.

CVE-2019-0708EPSS 100.0%MicrosoftRemote Desktop Services
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1464: Microsoft Windows Spoofing Vulnerability

Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files. Required action: Apply updates per vendor instructions.

CVE-2020-1464EPSS 41.1%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2021-34527: Microsoft Windows Print Spooler Remote Code Execution Vulnerability

Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare. Required action: Apply updates per vendor instructions.

CVE-2021-34527EPSS 99.8%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0803: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2019-0803EPSS 45.2%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1040: Microsoft Hyper-V RemoteFX vGPU Remote Code Execution Vulnerability

Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system. Required action: Apply updates per vendor instructions.

CVE-2020-1040EPSS 6.9%Hyper-V RemoteFXMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1350: Microsoft Windows DNS Server Remote Code Execution Vulnerability

Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed. Required action: Apply updates per vendor instructions.

CVE-2020-1350EPSS 92.2%MicrosoftWindows
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0797: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2019-0797EPSS 1.9%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2019-1215: Microsoft Windows Privilege Escalation Vulnerability

Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges. Required action: Apply updates per vendor instructions.

CVE-2019-1215EPSS 19.3%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2018-0798: Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802. Required action: Apply updates per vendor instructions.

CVE-2018-0798CVE-2018-0802EPSS 95.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2018-0802: Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798. Required action: Apply updates per vendor instructions.

CVE-2018-0798CVE-2018-0802EPSS 95.1%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2012-0158: Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability

Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user. Required action: Apply updates per vendor instructions.

CVE-2012-0158EPSS 100.0%MSCOMCTL.OCXMicrosoft
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2015-1641: Microsoft Office Memory Corruption Vulnerability

Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user. Required action: Apply updates per vendor instructions.

CVE-2015-1641EPSS 96.8%MicrosoftOffice
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1472: Microsoft Netlogon Privilege Escalation Vulnerability

Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon. Required action: Apply updates per vendor instructions.

CVE-2020-1472EPSS 99.5%MicrosoftNetlogon
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1054: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2020-1054EPSS 52.8%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2020-0601: Microsoft Windows CryptoAPI Spoofing Vulnerability

Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. Required action: Apply updates per vendor instructions.

CVE-2020-0601EPSS 89.4%MicrosoftWindows
CISA KEV ↗ · unattributed attribution · 1 IOC
high

CVE-2019-0604: Microsoft SharePoint Remote Code Execution Vulnerability

Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. Required action: Apply updates per vendor instructions.

CVE-2019-0604EPSS 99.9%MicrosoftSharePoint
CISA KEV ↗ · unattributed attribution
high

CVE-2019-0808: Microsoft Win32k Privilege Escalation Vulnerability

Microsoft Win32k contains a privilege escalation vulnerability due to the component failing to properly handle objects in memory. Successful exploitation allows an attacker to run code in kernel mode. Required action: Apply updates per vendor instructions.

CVE-2019-0808EPSS 53.3%MicrosoftWin32k
CISA KEV ↗ · unattributed attribution
high

CVE-2020-1147: Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability

Microsoft .NET Framework, Microsoft SharePoint, and Visual Studio contain a remote code execution vulnerability when the software fails to check the source markup of XML file input. Successful exploitation allows an attacker to execute code in the context of the process responsible for deserialization of the XML content. Required action: Apply updates per vendor instructions.

CVE-2020-1147EPSS 94.2%.NET Framework, SharePoint, Visual StudioMicrosoft
CISA KEV ↗ · unattributed attribution
high

CVE-2016-3235: Microsoft Office OLE DLL Side Loading Vulnerability

Microsoft Office Object Linking & Embedding (OLE) dynamic link library (DLL) contains a side loading vulnerability due to it improperly validating input before loading libraries. Successful exploitation allows for remote code execution. Required action: Apply updates per vendor instructions.

CVE-2016-3235EPSS 43.4%MicrosoftOffice
CISA KEV ↗ · unattributed attribution