Known Exploited
Dashboard / Known Exploited
CVE-2020-1020
Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1020
CVE-2021-38645
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-38645
CVE-2021-34523
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-34523
CVE-2017-7269
Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-7269
CVE-2021-36948
Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-36948
CVE-2021-38649
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-38649
CVE-2020-0688
Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0688
CVE-2017-0143
Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-0143
CVE-2016-7255
Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
Note: https://nvd.nist.gov/vuln/detail/CVE-2016-7255
CVE-2019-0708
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0708
CVE-2021-34473
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-34473
CVE-2020-1464
Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1464
CVE-2021-1732
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-1732
CVE-2021-34527
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
Note: Reference CISA's ED 21-04 (https://www.cisa.gov/news-events/directives/ed-21-04-mitigate-windows-print-spooler-service-vulnerability) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-04. https://nvd.nist.gov/vuln/detail/CVE-2021-34527
CVE-2021-31207
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-31207
CVE-2019-0803
Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0803
CVE-2020-1040
Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1040
CVE-2021-28310
Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-28310
CVE-2020-1350
Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.
Note: Reference CISA's ED 20-03 (https://www.cisa.gov/news-events/directives/ed-20-03-mitigate-windows-dns-server-remote-code-execution-vulnerability-july-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-03. https://nvd.nist.gov/vuln/detail/CVE-2020-1350
CVE-2021-26411
Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-26411
CVE-2019-0859
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0859
CVE-2021-40444
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-40444
CVE-2017-8759
Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-8759
CVE-2018-8653
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8653
CVE-2019-0797
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0797
CVE-2021-36942
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-36942
CVE-2019-1215
Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1215
CVE-2018-0798
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0798
CVE-2018-0802
Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.
Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0802
CVE-2012-0158
Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2012-0158
CVE-2015-1641
Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2015-1641
CVE-2021-27085
Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27085
CVE-2019-0541
Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0541
CVE-2017-11882
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-11882
CVE-2020-0674
Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0674
CVE-2021-27059
Microsoft Office contains an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27059
CVE-2019-1367
Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1367
CVE-2017-0199
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-0199
CVE-2020-1380
Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1380
CVE-2019-1429
Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.
Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1429
CVE-2017-11774
Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.
Note: https://nvd.nist.gov/vuln/detail/CVE-2017-11774
CVE-2020-0968
Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0968
CVE-2020-1472
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.
Note: Reference CISA's ED 20-04 (https://www.cisa.gov/news-events/directives/ed-20-04-mitigate-netlogon-elevation-privilege-vulnerability-august-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-04. https://nvd.nist.gov/vuln/detail/CVE-2020-1472
CVE-2021-26855
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Note: Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26855
CVE-2021-26858
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Note: Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26858
CVE-2021-27065
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
Note: Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-27065
CVE-2020-1054
Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.
Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1054
CVE-2021-1675
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-1675
CVE-2021-34448
Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.
Note: https://nvd.nist.gov/vuln/detail/CVE-2021-34448
CVE-2020-0601
Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.
Note: Reference CISA's ED 20-02 (https://www.cisa.gov/news-events/directives/ed-20-02-mitigate-windows-vulnerabilities-january-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-02. https://nvd.nist.gov/vuln/detail/CVE-2020-0601
