CISA Known Exploited Vulnerabilities
1484
Total KEV

Known Exploited Vulnerabilities

Track actively exploited CVEs from the CISA catalog with remediation deadlines

1472
Overdue

Showing 50 of 1484 KEV entries

View official CISA catalog

CVE-2014-9163

7.8 ⚠️ OVERDUE

Stack-based buffer overflow in Adobe Flash Player before 13.0.0.259 and 14.x and 15.x before 15.0.0.246 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in December 2014.

apple adobe linux +1
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2014-9163

CVE-2015-0311

9.8 ⚠️ OVERDUE

Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Windows and OS X and through 11.2.202.438 on Linux allows remote attackers to execute arbitrary code via unknown vectors, as exploited in the wild in January 2015.

apple suse microsoft +2
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-0311

CVE-2015-0313

9.8 ⚠️ OVERDUE

Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in February 2015, a different vulnerability than CVE-2015-0315, CVE-2015-0320, and CVE-2015-0322.

apple suse microsoft +3
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-0313

CVE-2015-3113

9.8 ⚠️ OVERDUE

Heap-based buffer overflow in Adobe Flash Player before 13.0.0.296 and 14.x through 18.x before 18.0.0.194 on Windows and OS X and before 11.2.202.468 on Linux allows remote attackers to execute arbitrary code via unspecified vectors, as exploited in the wild in June 2015.

redhat apple suse +5
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-3113

CVE-2015-5122

9.8 ⚠️ OVERDUE

Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that leverages improper handling of the opaqueBackground property, as exploited in the wild in July 2015.

redhat apple suse +4
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-5122

CVE-2015-5123

9.8 ⚠️ OVERDUE

Use-after-free vulnerability in the BitmapData class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.x through 13.0.0.302 on Windows and OS X, 14.x through 18.0.0.203 on Windows and OS X, 11.x through 11.2.202.481 on Linux, and 12.x through 18.0.0.204 on Linux Chrome installations allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted Flash content that overrides a valueOf function, as exploited in the wild in July 2015.

redhat apple suse +4
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-5123

CVE-2015-2502

8.8 ⚠️ OVERDUE

Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.

microsoft
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-2502

CVE-2018-7602

9.8 ⚠️ OVERDUE 💀 Ransomware

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

debian drupal
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-7602

CVE-2018-20753

9.8 ⚠️ OVERDUE 💀 Ransomware

Kaseya VSA RMM before R9.3 9.3.0.35, R9.4 before 9.4.0.36, and R9.5 before 9.5.0.5 allows unprivileged remote attackers to execute PowerShell payloads on all managed devices. In January 2018, attackers actively exploited this vulnerability in the wild.

kaseya
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-20753

CVE-2022-24521

7.8 ⚠️ OVERDUE 💀 Ransomware

Windows Common Log File System Driver Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-04-13
Remediation Deadline
2022-05-04

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-24521

CVE-2017-11317

9.8 ⚠️ OVERDUE

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload encryption, which allows remote attackers to perform arbitrary file uploads or execute arbitrary code.

telerik
Added to KEV
2022-04-11
Remediation Deadline
2022-05-02

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-11317

CVE-2020-2509

9.8 ⚠️ OVERDUE

A command injection vulnerability has been reported to affect QTS and QuTS hero. If exploited, this vulnerability allows attackers to execute arbitrary commands in a compromised application. We have already fixed this vulnerability in the following versions: QTS 4.5.2.1566 Build 20210202 and later QTS 4.5.1.1495 Build 20201123 and later QTS 4.3.6.1620 Build 20210322 and later QTS 4.3.4.1632 Build 20210324 and later QTS 4.3.3.1624 Build 20210416 and later QTS 4.2.6 Build 20210327 and later QuTS hero h4.5.1.1491 build 20201119 and later

qnap
Added to KEV
2022-04-11
Remediation Deadline
2022-05-02

Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-2509

CVE-2021-27852

9.8 ⚠️ OVERDUE

Deserialization of Untrusted Data vulnerability in CheckboxWeb.dll of Checkbox Survey allows an unauthenticated remote attacker to execute arbitrary code. This issue affects: Checkbox Survey versions prior to 7.

checkbox
Added to KEV
2022-04-11
Remediation Deadline
2022-05-02

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-27852

CVE-2021-42278

7.5 ⚠️ OVERDUE 💀 Ransomware

Active Directory Domain Services Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-04-11
Remediation Deadline
2022-05-02

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-42278

CVE-2021-42287

7.5 ⚠️ OVERDUE 💀 Ransomware

Active Directory Domain Services Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-04-11
Remediation Deadline
2022-05-02

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-42287

CVE-2021-22600

6.6 ⚠️ OVERDUE

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

debian linux netapp
Added to KEV
2022-04-11
Remediation Deadline
2022-05-02

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-22600

CVE-2022-23176

8.8 ⚠️ OVERDUE

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3.

watchguard
Added to KEV
2022-04-11
Remediation Deadline
2022-05-02

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-23176

CVE-2021-39793

7.8 ⚠️ OVERDUE

In kbase_jd_user_buf_pin_pages of mali_kbase_mem.c, there is a possible out of bounds write due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-210470189References: N/A

google
Added to KEV
2022-04-11
Remediation Deadline
2022-05-02

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-39793

CVE-2017-0148

8.1 ⚠️ OVERDUE 💀 Ransomware

The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote Code Execution Vulnerability." This vulnerability is different from those described in CVE-2017-0143, CVE-2017-0144, CVE-2017-0145, and CVE-2017-0146.

microsoft siemens
Added to KEV
2022-04-06
Remediation Deadline
2022-04-27

Notes: https://nvd.nist.gov/vuln/detail/CVE-2017-0148

CVE-2021-3156

7.8 ⚠️ OVERDUE

Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.

synology mcafee fedoraproject +5
Added to KEV
2022-04-06
Remediation Deadline
2022-04-27

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-3156

CVE-2021-31166

9.8 ⚠️ OVERDUE

HTTP Protocol Stack Remote Code Execution Vulnerability

microsoft
Added to KEV
2022-04-06
Remediation Deadline
2022-04-27

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-31166

CVE-2021-45382

9.8 ⚠️ OVERDUE

A Remote Command Execution (RCE) vulnerability exists in all series H/W revisions D-link DIR-810L, DIR-820L/LW, DIR-826L, DIR-830L, and DIR-836L routers via the DDNS function in ncc2 binary file. Note: DIR-810L, DIR-820L, DIR-830L, DIR-826L, DIR-836L, all hardware revisions, have reached their End of Life ("EOL") /End of Service Life ("EOS") Life-Cycle and as such this issue will not be patched.

dlink
Added to KEV
2022-04-04
Remediation Deadline
2022-04-25

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-45382

CVE-2022-22965

9.8 ⚠️ OVERDUE

A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to the exploit. However, the nature of the vulnerability is more general, and there may be other ways to exploit it.

cisco veritas oracle +2
Added to KEV
2022-04-04
Remediation Deadline
2022-04-25

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22965

CVE-2022-22674

5.5 ⚠️ OVERDUE

An out-of-bounds read issue existed that led to the disclosure of kernel memory. This was addressed with improved input validation. This issue is fixed in macOS Monterey 12.3.1, Security Update 2022-004 Catalina, macOS Big Sur 11.6.6. A local user may be able to read kernel memory.

apple
Added to KEV
2022-04-04
Remediation Deadline
2022-04-25

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22674

CVE-2022-22675

7.8 ⚠️ OVERDUE

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in tvOS 15.5, watchOS 8.6, macOS Big Sur 11.6.6, macOS Monterey 12.3.1, iOS 15.4.1 and iPadOS 15.4.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited..

apple
Added to KEV
2022-04-04
Remediation Deadline
2022-04-25

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-22675

CVE-2022-26871

9.8 ⚠️ OVERDUE

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

trendmicro
Added to KEV
2022-03-31
Remediation Deadline
2022-04-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-26871

CVE-2018-10561

9.8 ⚠️ OVERDUE

An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

dasannetworks
Added to KEV
2022-03-31
Remediation Deadline
2022-04-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-10561

CVE-2018-10562

9.8 ⚠️ OVERDUE 💀 Ransomware

An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.

dasannetworks
Added to KEV
2022-03-31
Remediation Deadline
2022-04-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2018-10562

CVE-2021-21551

8.8 ⚠️ OVERDUE

Dell dbutil_2_3.sys driver contains an insufficient access control vulnerability which may lead to escalation of privileges, denial of service, or information disclosure. Local authenticated user access is required.

dell
Added to KEV
2022-03-31
Remediation Deadline
2022-04-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-21551

CVE-2021-28799

10.0 ⚠️ OVERDUE 💀 Ransomware

An improper authorization vulnerability has been reported to affect QNAP NAS running HBS 3 (Hybrid Backup Sync. ) If exploited, the vulnerability allows remote attackers to log in to a device. This issue affects: QNAP Systems Inc. HBS 3 versions prior to v16.0.0415 on QTS 4.5.2; versions prior to v3.0.210412 on QTS 4.3.6; versions prior to v3.0.210411 on QTS 4.3.4; versions prior to v3.0.210411 on QTS 4.3.3; versions prior to v16.0.0419 on QuTS hero h4.5.1; versions prior to v16.0.0419 on QuTScloud c4.5.1~c4.5.4. This issue does not affect: QNAP Systems Inc. HBS 2 . QNAP Systems Inc. HBS 1.3 .

qnap
Added to KEV
2022-03-31
Remediation Deadline
2022-04-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-28799

CVE-2021-34484

7.8 ⚠️ OVERDUE

Windows User Profile Service Elevation of Privilege Vulnerability

microsoft
Added to KEV
2022-03-31
Remediation Deadline
2022-04-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2021-34484

CVE-2022-1040

9.8 ⚠️ OVERDUE

An authentication bypass vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v18.5 MR3 and older.

sophos
Added to KEV
2022-03-31
Remediation Deadline
2022-04-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2022-1040

CVE-2010-4398

7.8 ⚠️ OVERDUE

Stack-based buffer overflow in the RtlQueryRegistryValues function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 allows local users to gain privileges, and bypass the User Account Control (UAC) feature, via a crafted REG_BINARY value for a SystemDefaultEUDCFont registry key, aka "Driver Improper Interaction with Windows Kernel Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-21

Notes: https://nvd.nist.gov/vuln/detail/CVE-2010-4398

CVE-2011-2005

7.8 ⚠️ OVERDUE

afd.sys in the Ancillary Function Driver in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate user-mode input passed to kernel mode, which allows local users to gain privileges via a crafted application, aka "Ancillary Function Driver Elevation of Privilege Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2011-2005

CVE-2012-2034

7.5 ⚠️ OVERDUE

Adobe Flash Player before 10.3.183.20 and 11.x before 11.3.300.257 on Windows and Mac OS X; before 10.3.183.20 and 11.x before 11.2.202.236 on Linux; before 11.1.111.10 on Android 2.x and 3.x; and before 11.1.115.9 on Android 4.x, and Adobe AIR before 3.3.0.3610, allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2037.

redhat apple suse +5
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-2034

CVE-2012-5076

9.8 ⚠️ OVERDUE

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allows remote attackers to affect confidentiality, integrity, and availability, related to JAX-WS.

suse oracle
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-5076

CVE-2012-0518

4.7 ⚠️ OVERDUE

Unspecified vulnerability in the Oracle Application Server Single Sign-On component in Oracle Fusion Middleware 10.1.4.3.0 allows remote attackers to affect integrity via unknown vectors related to Redirects, a different vulnerability than CVE-2012-3175.

oracle
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-0518

CVE-2012-2539

7.8 ⚠️ OVERDUE

Microsoft Word 2003 SP3, 2007 SP2 and SP3, and 2010 SP1; Word Viewer; Office Compatibility Pack SP2 and SP3; and Office Web Apps 2010 SP1 allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted RTF data, aka "Word RTF 'listoverridecount' Remote Code Execution Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2012-2539

CVE-2013-2551

8.8 ⚠️ OVERDUE 💀 Ransomware

Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted web site that triggers access to a deleted object, as demonstrated by VUPEN during a Pwn2Own competition at CanSecWest 2013, aka "Internet Explorer Use After Free Vulnerability," a different vulnerability than CVE-2013-1308 and CVE-2013-1309.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-2551

CVE-2013-2729

9.8 ⚠️ OVERDUE

Integer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2727.

suse adobe redhat
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-2729

CVE-2013-3660

7.8 ⚠️ OVERDUE

The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-3660

CVE-2013-2465

9.8 ⚠️ OVERDUE 💀 Ransomware

Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and earlier, and 5.0 Update 45 and earlier, and OpenJDK 7, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to 2D. NOTE: the previous information is from the June 2013 CPU. Oracle has not commented on claims from another vendor that this issue allows remote attackers to bypass the Java sandbox via vectors related to "Incorrect image channel verification" in 2D.

suse oracle sun
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-2465

CVE-2013-1690

8.8 ⚠️ OVERDUE

Mozilla Firefox before 22.0, Firefox ESR 17.x before 17.0.7, Thunderbird before 17.0.7, and Thunderbird ESR 17.x before 17.0.7 do not properly handle onreadystatechange events in conjunction with page reloading, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted web site that triggers an attempt to execute data at an unmapped memory location.

redhat mozilla suse +3
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2013-1690

CVE-2015-1770

8.8 ⚠️ OVERDUE

Microsoft Office 2013 SP1 and 2013 RT SP1 allows remote attackers to execute arbitrary code via a crafted Office document, aka "Microsoft Office Uninitialized Memory Use Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-1770

CVE-2015-2419

8.8 ⚠️ OVERDUE

JScript 9 in Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "JScript9 Memory Corruption Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-2419

CVE-2015-2426

8.8 ⚠️ OVERDUE

Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted OpenType font, aka "OpenType Font Driver Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2015-2426

CVE-2016-0040

7.8 ⚠️ OVERDUE

The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to gain privileges via a crafted application, aka "Windows Elevation of Privilege Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0040

CVE-2016-0151

7.8 ⚠️ OVERDUE 💀 Ransomware

The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 mismanages process tokens, which allows local users to gain privileges via a crafted application, aka "Windows CSRSS Security Feature Bypass Vulnerability."

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0151

CVE-2016-0189

7.5 ⚠️ OVERDUE

The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 9 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-0189

CVE-2016-7200

8.8 ⚠️ OVERDUE

The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-7201, CVE-2016-7202, CVE-2016-7203, CVE-2016-7208, CVE-2016-7240, CVE-2016-7242, and CVE-2016-7243.

microsoft
Added to KEV
2022-03-28
Remediation Deadline
2022-04-18

Notes: https://nvd.nist.gov/vuln/detail/CVE-2016-7200