Known Exploited

    Dashboard / Known Exploited

    Filters
    8.8
    High

    CVE-2020-1020

    Microsoft Windows Adobe Font Manager Library contains an unspecified vulnerability when handling specially crafted multi-master fonts (Adobe Type 1 PostScript format) that allows for remote code execution for all systems except Windows 10. For systems running Windows 10, an attacker who successfully exploited the vulnerability could execute code in an AppContainer sandbox context with limited privileges and capabilities.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1020

    7.8
    High

    CVE-2021-38645

    Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-38645

    9
    Critical

    CVE-2021-34523

    Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-34523

    9.8
    Critical

    CVE-2017-7269

    Microsoft Windows Server 2003 R2 contains a buffer overflow vulnerability in Internet Information Services (IIS) 6.0 which allows remote attackers to execute code via a long header beginning with "If: <http://" in a PROPFIND request.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-7269

    7.8
    High

    CVE-2021-36948

    Microsoft Windows Update Medic Service contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-36948

    7
    High

    CVE-2021-38649

    Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing privilege escalation.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-38649

    8.8
    High

    CVE-2020-0688

    Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0688

    8.8
    High

    CVE-2017-0143

    Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-0143

    7.8
    High

    CVE-2016-7255

    Microsoft Win32k kernel-mode driver fails to properly handle objects in memory which allows for privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2016-7255

    9.8
    Critical

    CVE-2019-0708

    Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0708

    9.1
    Critical

    CVE-2021-34473

    Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-34473

    7.8
    High

    CVE-2020-1464

    Microsoft Windows contains a spoofing vulnerability when Windows incorrectly validates file signatures, allowing an attacker to bypass security features and load improperly signed files.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1464

    7.8
    High

    CVE-2021-1732

    Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-1732

    8.8
    High

    CVE-2021-34527

    Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: Reference CISA's ED 21-04 (https://www.cisa.gov/news-events/directives/ed-21-04-mitigate-windows-print-spooler-service-vulnerability) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-04. https://nvd.nist.gov/vuln/detail/CVE-2021-34527

    6.6
    Medium

    CVE-2021-31207

    Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-31207

    7.8
    High

    CVE-2019-0803

    Microsoft Win32k contains an unspecified vulnerability due to it failing to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0803

    9
    Critical

    CVE-2020-1040

    Microsoft Hyper-V RemoteFX vGPU contains an improper input validation vulnerability due to the host server failing to properly validate input from an authenticated user on a guest operating system. Successful exploitation allows for remote code execution on the host operating system.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1040

    7.8
    High

    CVE-2021-28310

    Microsoft Windows Win32k contains an unspecified vulnerability that allows for privilege escalation.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-28310

    10
    Critical

    CVE-2020-1350

    Microsoft Windows DNS Servers fail to properly handle requests, allowing an attacker to perform remote code execution in the context of the Local System Account. The vulnerability is also known under the moniker of SIGRed.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: Reference CISA's ED 20-03 (https://www.cisa.gov/news-events/directives/ed-20-03-mitigate-windows-dns-server-remote-code-execution-vulnerability-july-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-03. https://nvd.nist.gov/vuln/detail/CVE-2020-1350

    8.8
    High

    CVE-2021-26411

    Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-26411

    7.8
    High

    CVE-2019-0859

    Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel mode.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0859

    8.8
    High

    CVE-2021-40444

    Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-40444

    7.8
    High

    CVE-2017-8759

    Microsoft .NET Framework contains a remote code execution vulnerability when processing untrusted input that could allow an attacker to take control of an affected system.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-8759

    7.5
    High

    CVE-2018-8653

    Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-8653

    7.8
    High

    CVE-2019-0797

    Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0797

    7.5
    High

    CVE-2021-36942

    Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-36942

    7.8
    High

    CVE-2019-1215

    Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1215

    8.8
    High

    CVE-2018-0798

    Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0802.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0798

    7.8
    High

    CVE-2018-0802

    Microsoft Office contains a memory corruption vulnerability due to the way objects are handled in memory. Successful exploitation allows for remote code execution in the context of the current user. This vulnerability is known to be chained with CVE-2018-0798.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2018-0802

    8.8
    High

    CVE-2012-0158

    Microsoft MSCOMCTL.OCX contains an unspecified vulnerability that allows for remote code execution, allowing an attacker to take complete control of an affected system under the context of the current user.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2012-0158

    7.8
    High

    CVE-2015-1641

    Microsoft Office contains a memory corruption vulnerability due to failure to properly handle rich text format files in memory. Successful exploitation allows for remote code execution in the context of the current user.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2015-1641

    8.8
    High

    CVE-2021-27085

    Microsoft Internet Explorer contains an unspecified vulnerability that allows for remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27085

    8.8
    High

    CVE-2019-0541

    Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-0541

    7.8
    High

    CVE-2017-11882

    Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-11882

    7.5
    High

    CVE-2020-0674

    Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0674

    7.6
    High

    CVE-2021-27059

    Microsoft Office contains an unspecified vulnerability that allows for remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-27059

    7.5
    High

    CVE-2019-1367

    Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1367

    7.8
    High

    CVE-2017-0199

    Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-0199

    7.8
    High

    CVE-2020-1380

    Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1380

    7.5
    High

    CVE-2019-1429

    Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2019-1429

    7.8
    High

    CVE-2017-11774

    Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2017-11774

    7.5
    High

    CVE-2020-0968

    Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-0968

    5.5
    Medium

    CVE-2020-1472

    Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: Reference CISA's ED 20-04 (https://www.cisa.gov/news-events/directives/ed-20-04-mitigate-netlogon-elevation-privilege-vulnerability-august-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-04. https://nvd.nist.gov/vuln/detail/CVE-2020-1472

    9.1
    Critical

    CVE-2021-26855

    Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26855

    7.8
    High

    CVE-2021-26858

    Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-26858

    7.8
    High

    CVE-2021-27065

    Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: Reference CISA's ED 21-02 (https://www.cisa.gov/news-events/directives/ed-21-02-mitigate-microsoft-exchange-premises-product-vulnerabilities) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 21-02. https://nvd.nist.gov/vuln/detail/CVE-2021-27065

    7
    High

    CVE-2020-1054

    Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2020-1054

    7.8
    High

    CVE-2021-1675

    Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-1675

    6.8
    Medium

    CVE-2021-34448

    Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: https://nvd.nist.gov/vuln/detail/CVE-2021-34448

    8.1
    High

    CVE-2020-0601

    Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall.

    Alert Date:3 Nov 2021
    Action:Apply updates per vendor instructions.

    Note: Reference CISA's ED 20-02 (https://www.cisa.gov/news-events/directives/ed-20-02-mitigate-windows-vulnerabilities-january-2020-patch-tuesday) for further guidance and requirements. Note: The due date for addressing this vulnerability aligns with the requirements outlined in ED 20-02. https://nvd.nist.gov/vuln/detail/CVE-2020-0601

    Items Per Page