KEV topic
KEV entries with known ransomware use
KEV entries where CISA has confirmed use in known ransomware campaigns. Active threat actors have chained these vulnerabilities into ransomware operations — treat patching as a same-week priority, not a "next maintenance window" task. Cross-section across every vendor and product type in the catalog. Updated daily from the CISA KEV catalog.
SonicWall SMA1000 Appliances: 2 CVEsPatch nowadded Jul 14, 2026
- CVE-2026-15409Known ransomware use
SonicWall SMA1000 Appliances Server-Side Request Forgery Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA1000 Appliances contain a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to potentially cause the appliance to make requests to unintended location.
- CVE-2026-15410Known ransomware use
SonicWall SMA1000 Appliances Code Injection Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA1000 Appliances contain a code injection vulnerability which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands.
CVE-2026-45659 · Microsoft SharePoint ServerDeserialization of Untrusted Data VulnerabilityKnown ransomware usePatch nowAdded to KEV Jul 1, 2026
Microsoft SharePoint Server Deserialization of Untrusted Data Vulnerability
Affects anyone running Microsoft SharePoint Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint Server contains a deserialization of untrusted data vulnerability which allows an authorized attacker to execute code over a network.
CVE-2026-0257 · Palo Alto Networks PAN-OSAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV May 29, 2026
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability that allows attackers to bypass security restrictions and establish an unauthorized VPN connection.
CVE-2026-33825 · Microsoft DefenderInsufficient Granularity of Access Control VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 22, 2026
Microsoft Defender Insufficient Granularity of Access Control Vulnerability
Affects anyone running Microsoft Defender. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Defender contains an insufficient granularity of access control vulnerability that could allow an authorized attacker to escalate privileges locally.
CVE-2023-21529 · Microsoft Exchange ServerDeserialization of Untrusted Data VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 13, 2026
Microsoft Exchange Server Deserialization of Untrusted Data Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains a deserialization of untrusted data that allows an authenticated attacker to achieve remote code execution.
CVE-2026-20131 · Cisco Secure Firewall Management Center (FMC)Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 19, 2026
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management Deserialization of Untrusted Data Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain a deserialization of untrusted data vulnerability in the web-based management interface that could allow an unauthenticated, remote attacker to execute arbitrary Java code as root on an affected device.
Microsoft SharePoint: 2 CVEsPatch nowadded Jul 22, 2025
- CVE-2025-49706Known ransomware use
Microsoft SharePoint Improper Authentication Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains an improper authentication vulnerability that allows an authorized attacker to perform spoofing over a network. Successfully exploitation could allow an attacker to view sensitive information and make some changes to disclosed information. This vulnerability could be chained with CVE-2025-49704. CVE-2025-53771 is a patch bypass for CVE-2025-49706, and the updates for CVE-2025-53771 include more robust protection than those for CVE-2025-49706.
- CVE-2025-49704Known ransomware use
Microsoft SharePoint Code Injection Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a code injection vulnerability that could allow an authorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-49706. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
CVE-2025-53770 · Microsoft SharePointDeserialization of Untrusted Data VulnerabilityKnown ransomware usePatch nowAdded to KEV Jul 20, 2025
Microsoft SharePoint Deserialization of Untrusted Data Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network. This vulnerability could be chained with CVE-2025-53771. CVE-2025-53770 is a patch bypass for CVE-2025-49704, and the updates for CVE-2025-53770 include more robust protection than those for CVE-2025-49704.
CVE-2019-6693 · Fortinet FortiOSUse of Hard-Coded Credentials VulnerabilityKnown ransomware usePatch nowAdded to KEV Jun 25, 2025
Fortinet FortiOS Use of Hard-Coded Credentials Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS contains a use of hard-coded credentials vulnerability that could allow an attacker to cipher sensitive data in FortiOS configuration backup file via knowledge of the hard-coded key.
CVE-2025-29824 · Microsoft WindowsCommon Log File System (CLFS) Driver Use-After-Free VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 8, 2025
Microsoft Windows Common Log File System (CLFS) Driver Use-After-Free Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) Driver contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.
- KB5055519
- KB5055526
- KB5055518
- KB5055528
- +10 more
CVE-2025-22457 · Ivanti Connect Secure, Policy Secure, and ZTA GatewaysStack-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 4, 2025
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contains a stack-based buffer overflow vulnerability that allows a remote unauthenticated attacker to achieve remote code execution.
CVE-2025-24472 · Fortinet FortiOS and FortiProxyAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 18, 2025
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that allows a remote attacker to gain super-admin privileges via crafted CSF proxy requests.
CVE-2025-26633 · Microsoft WindowsManagement Console (MMC) Improper Neutralization VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 11, 2025
Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.
- KB5053596
- KB5053603
- KB5053638
- KB5053606
- +12 more
CVE-2018-8639 · Microsoft WindowsWin32k Improper Resource Shutdown or Release VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 3, 2025
Microsoft Windows Win32k Improper Resource Shutdown or Release Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Win32k contains an improper resource shutdown or release vulnerability that allows for local, authenticated privilege escalation. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
- KB4471327
- KB4471324
- KB4471329
- KB4471323
- +10 more
CVE-2024-53704 · SonicWall SonicOSSSLVPN Improper Authentication VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 18, 2025
SonicWall SonicOS SSLVPN Improper Authentication Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SonicOS contains an improper authentication vulnerability in the SSLVPN authentication mechanism that allows a remote attacker to bypass authentication.
CVE-2025-23006 · SonicWall SMA1000 AppliancesDeserialization VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 24, 2025
SonicWall SMA1000 Appliances Deserialization Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA1000 Appliance Management Console (AMC) and Central Management Console (CMC) contain a deserialization of untrusted data vulnerability, which can enable a remote, unauthenticated attacker to execute arbitrary OS commands.
CVE-2024-55591 · Fortinet FortiOS and FortiProxyAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 14, 2025
Fortinet FortiOS and FortiProxy Authentication Bypass Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS and FortiProxy contain an authentication bypass vulnerability that may allow an unauthenticated, remote attacker to gain super-admin privileges via crafted requests to Node.js websocket module.
CVE-2025-0282 · Ivanti Connect Secure, Policy Secure, and ZTA GatewaysStack-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 8, 2025
Ivanti Connect Secure, Policy Secure, and ZTA Gateways Stack-Based Buffer Overflow Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Connect Secure, Policy Secure, and ZTA Gateways contain a stack-based buffer overflow which can lead to unauthenticated remote code execution.
Palo Alto Networks PAN-OS: 2 CVEsPatch nowadded Nov 18, 2024
- CVE-2024-0012Known ransomware use
Palo Alto Networks PAN-OS Management Interface Authentication Bypass Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains an authentication bypass vulnerability in the web-based management interface for several PAN-OS products, including firewalls and VPN concentrators.
- CVE-2024-9474Known ransomware use
Palo Alto Networks PAN-OS Management Interface OS Command Injection Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains an OS command injection vulnerability that allows for privilege escalation through the web-based management interface for several PAN products, including firewalls and VPN concentrators.
CVE-2024-49039 · Microsoft WindowsTask Scheduler Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 12, 2024
Microsoft Windows Task Scheduler Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Task Scheduler contains a privilege escalation vulnerability that can allow an attacker-provided, local application to escalate privileges outside of its AppContainer, and access privileged RPC functions.
- KB5046617
- KB5046696
- KB5046615
- KB5046616
- +6 more
CVE-2024-38094 · Microsoft SharePointDeserialization VulnerabilityKnown ransomware usePatch nowAdded to KEV Oct 22, 2024
Microsoft SharePoint Deserialization Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint contains a deserialization vulnerability that allows for remote code execution.
CVE-2024-30088 · Microsoft WindowsKernel TOCTOU Race Condition VulnerabilityKnown ransomware usePatch nowAdded to KEV Oct 15, 2024
Microsoft Windows Kernel TOCTOU Race Condition Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.
- KB5039217
- KB5039227
- KB5039330
- KB5039213
- +5 more
CVE-2024-40766 · SonicWall SonicOSImproper Access Control VulnerabilityKnown ransomware usePatch nowAdded to KEV Sep 9, 2024
SonicWall SonicOS Improper Access Control Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.
CVE-2024-26169 · Microsoft WindowsError Reporting Service Improper Privilege Management VulnerabilityKnown ransomware usePatch nowAdded to KEV Jun 13, 2024
Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Error Reporting Service contains an improper privilege management vulnerability that allows a local attacker with user permissions to gain SYSTEM privileges.
- KB5035849
- KB5035857
- KB5035959
- KB5035854
- +6 more
CVE-2024-30051 · Microsoft DWM Core LibraryPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV May 14, 2024
Microsoft DWM Core Library Privilege Escalation Vulnerability
Affects anyone running Microsoft DWM Core Library. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft DWM Core Library contains a privilege escalation vulnerability that allows an attacker to gain SYSTEM privileges.
- KB5037765
- KB5037782
- KB5037848
- KB5037770
- +4 more
CVE-2024-3400 · Palo Alto Networks PAN-OSCommand Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 12, 2024
Palo Alto Networks PAN-OS Command Injection Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS GlobalProtect feature contains a command injection vulnerability that allows an unauthenticated attacker to execute commands with root privileges on the firewall.
CVE-2023-24955 · Microsoft SharePoint ServerCode Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 26, 2024
Microsoft SharePoint Server Code Injection Vulnerability
Affects anyone running Microsoft SharePoint Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint Server contains a code injection vulnerability that allows an authenticated attacker with Site Owner privileges to execute code remotely.
CVE-2021-44529 · Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA)Code Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 25, 2024
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) Code Injection Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager Cloud Service Appliance (EPM CSA) contains a code injection vulnerability that allows an unauthenticated user to execute malicious code with limited permissions (nobody).
CVE-2023-48788 · Fortinet FortiClient EMSSQL Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 25, 2024
Fortinet FortiClient EMS SQL Injection Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
CVE-2024-21338 · Microsoft WindowsKernel Exposed IOCTL with Insufficient Access Control VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 4, 2024
Microsoft Windows Kernel Exposed IOCTL with Insufficient Access Control Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Kernel contains an exposed IOCTL with insufficient access control vulnerability within the IOCTL (input and output control) dispatcher in appid.sys that allows a local attacker to achieve privilege escalation.
- KB5034768
- KB5034770
- KB5034766
- KB5034763
- +2 more
CVE-2020-3259 · Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)ASA and FTD Information Disclosure VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 15, 2024
Cisco ASA and FTD Information Disclosure Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an information disclosure vulnerability. An attacker could retrieve memory contents on an affected device, which could lead to the disclosure of confidential information due to a buffer tracking issue when the software parses invalid URLs that are requested from the web services interface. This vulnerability affects only specific AnyConnect and WebVPN configurations.
CVE-2024-21412 · Microsoft WindowsInternet Shortcut Files Security Feature Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 13, 2024
Microsoft Windows Internet Shortcut Files Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Internet Shortcut Files contains an unspecified vulnerability that allows for a security feature bypass.
- KB5034766
- KB5034768
- KB5034763
- KB5034770
- +2 more
CVE-2024-21762 · Fortinet FortiOSOut-of-Bound Write VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 9, 2024
Fortinet FortiOS Out-of-Bound Write Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS contains an out-of-bound write vulnerability that allows a remote unauthenticated attacker to execute code or commands via specially crafted HTTP requests.
CVE-2024-21893 · Ivanti Connect Secure, Policy Secure, and NeuronsServer-Side Request Forgery (SSRF) VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 31, 2024
Ivanti Connect Secure, Policy Secure, and Neurons Server-Side Request Forgery (SSRF) Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) vulnerability in the SAML component that allows an attacker to access certain restricted resources without authentication.
CVE-2023-35082 · Ivanti Endpoint Manager Mobile (EPMM) and MobileIron CoreAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 18, 2024
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core Authentication Bypass Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager Mobile (EPMM) and MobileIron Core contain an authentication bypass vulnerability that allows unauthorized users to access restricted functionality or resources of the application.
Ivanti Connect Secure and Policy Secure: 2 CVEsPatch nowadded Jan 10, 2024
- CVE-2024-21887Known ransomware use
Ivanti Connect Secure and Policy Secure Command Injection Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure contain a command injection vulnerability in the web components of these products, which can allow an authenticated administrator to send crafted requests to execute code on affected appliances. This vulnerability can be leveraged in conjunction with CVE-2023-46805, an authenticated bypass issue.
- CVE-2023-46805Known ransomware use
Ivanti Connect Secure and Policy Secure Authentication Bypass Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure) and Ivanti Policy Secure gateways contain an authentication bypass vulnerability in the web component that allows an attacker to access restricted resources by bypassing control checks. This vulnerability can be leveraged in conjunction with CVE-2024-21887, a command injection vulnerability.
CVE-2023-29357 · Microsoft SharePoint ServerPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 10, 2024
Microsoft SharePoint Server Privilege Escalation Vulnerability
Affects anyone running Microsoft SharePoint Server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint Server contains an unspecified vulnerability that allows an unauthenticated attacker, who has gained access to spoofed JWT authentication tokens, to use them for executing a network attack. This attack bypasses authentication, enabling the attacker to gain administrator privileges.
Adobe ColdFusion: 2 CVEsPatch nowadded Jan 8, 2024
- CVE-2023-38203Known ransomware use
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
- CVE-2023-29300Known ransomware use
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.
CVE-2023-20269 · Cisco Adaptive Security Appliance and Firepower Threat DefenseUnauthorized Access VulnerabilityKnown ransomware usePatch nowAdded to KEV Sep 13, 2023
Cisco Adaptive Security Appliance and Firepower Threat Defense Unauthorized Access Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Adaptive Security Appliance and Firepower Threat Defense contain an unauthorized access vulnerability that could allow an unauthenticated, remote attacker to conduct a brute force attack in an attempt to identify valid username and password combinations or establish a clientless SSL VPN session with an unauthorized user.
CVE-2023-38035 · Ivanti SentryAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Aug 22, 2023
Ivanti Sentry Authentication Bypass Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Sentry, formerly known as MobileIron Sentry, contains an authentication bypass vulnerability that may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
CVE-2023-35078 · Ivanti Endpoint Manager Mobile (EPMM)Endpoint Manager Mobile Authentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Jul 25, 2023
Ivanti Endpoint Manager Mobile Authentication Bypass Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. An attacker with access to these API paths can access personally identifiable information (PII) such as names, phone numbers, and other mobile device details for users on a vulnerable system. An attacker can also make other configuration changes including installing software and modifying security profiles on registered devices.
CVE-2023-36884 · Microsoft WindowsSearch Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Jul 17, 2023
Microsoft Windows Search Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Search contains an unspecified vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file, leading to remote code execution.
- KB5029247
- KB5029250
- KB5029367
- KB5029253
- +12 more
CVE-2023-27997 · Fortinet FortiOS and FortiProxy SSL-VPNHeap-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Jun 13, 2023
Fortinet FortiOS and FortiProxy SSL-VPN Heap-Based Buffer Overflow Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or commands via specifically crafted requests.
CVE-2023-28252 · Microsoft WindowsCommon Log File System (CLFS) Driver Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 11, 2023
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
- KB5025229
- KB5025230
- KB5025221
- KB5025224
- +11 more
CVE-2019-1388 · Microsoft WindowsCertificate Dialog Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 7, 2023
Microsoft Windows Certificate Dialog Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Certificate Dialog contains a privilege escalation vulnerability, allowing attackers to run processes in an elevated context.
- KB4525237
- KB4523205
- KB4525241
- KB4524570
- +10 more
CVE-2023-24880 · Microsoft WindowsSmartScreen Security Feature Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 14, 2023
Microsoft Windows SmartScreen Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
- KB5023702
- KB5023705
- KB5023786
- KB5023696
- +3 more
CVE-2023-23376 · Microsoft WindowsCommon Log File System (CLFS) Driver Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 14, 2023
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
- KB5022840
- KB5022842
- KB5022921
- KB5022834
- +12 more
CVE-2022-41080 · Microsoft Exchange ServerPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 10, 2023
Microsoft Exchange Server Privilege Escalation Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution.
CVE-2022-44698 · Microsoft DefenderSmartScreen Security Feature Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Dec 13, 2022
Microsoft Defender SmartScreen Security Feature Bypass Vulnerability
Affects anyone running Microsoft Defender. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Defender SmartScreen contains a security feature bypass vulnerability that could allow an attacker to evade Mark of the Web (MOTW) defenses via a specially crafted malicious file.
- KB5021237
- KB5021233
- KB5021249
- KB5021234
- +1 more
CVE-2022-42475 · Fortinet FortiOSHeap-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Dec 13, 2022
Fortinet FortiOS Heap-Based Buffer Overflow Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Multiple versions of Fortinet FortiOS SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute arbitrary code or commands via specifically crafted requests.
Microsoft Windows: 2 CVEsPatch nowadded Nov 8, 2022
- CVE-2022-41073Known ransomware use
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows an attacker to gain SYSTEM-level privileges.
- KB5019966
- KB5019959
- KB5019081
- KB5019080
- +12 more
- CVE-2022-41091Known ransomware use
Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features.
- KB5019966
- KB5019959
- KB5019081
- KB5019080
- +4 more
Cisco AnyConnect Secure: 2 CVEsPatch nowadded Oct 24, 2022
- CVE-2020-3153Known ransomware use
Cisco AnyConnect Secure Mobility Client for Windows Uncontrolled Search Path Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks.
- CVE-2020-3433Known ransomware use
Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges.
CVE-2022-40684 · Fortinet Multiple ProductsAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Oct 11, 2022
Fortinet Multiple Products Authentication Bypass Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS, FortiProxy, and FortiSwitchManager contain an authentication bypass vulnerability that could allow an unauthenticated attacker to perform operations on the administrative interface via specially crafted HTTP or HTTPS requests.
Microsoft Exchange Server: 2 CVEsPatch nowadded Sep 30, 2022
- CVE-2022-41082Known ransomware use
Microsoft Exchange Server Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for authenticated remote code execution. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41040 which allows for the remote code execution.
- CVE-2022-41040Known ransomware use
Microsoft Exchange Server Server-Side Request Forgery Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server allows for server-side request forgery. Dubbed "ProxyNotShell," this vulnerability is chainable with CVE-2022-41082 which allows for remote code execution.
CVE-2018-13374 · Fortinet FortiOS and FortiADCImproper Access Control VulnerabilityKnown ransomware usePatch nowAdded to KEV Sep 8, 2022
Fortinet FortiOS and FortiADC Improper Access Control Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS and FortiADC contain an improper access control vulnerability that allows attackers to obtain the LDAP server login credentials configured in FortiGate by pointing a LDAP server connectivity test request to a rogue LDAP server.
CVE-2022-30190 · Microsoft WindowsSupport Diagnostic Tool (MSDT) Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Jun 14, 2022
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An attacker who successfully exploits this vulnerability can run code with the privileges of the calling application.
- KB5014692
- KB5014699
- KB5014678
- KB5014697
- +8 more
Microsoft Silverlight: 2 CVEsPatch nowadded May 25, 2022
- CVE-2016-0034Known ransomware use
Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Affects anyone running Microsoft Silverlight. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Silverlight mishandles negative offsets during decoding, which allows attackers to execute remote code or cause a denial-of-service (DoS).
- CVE-2013-0074Known ransomware use
Microsoft Silverlight Double Dereference Vulnerability
Affects anyone running Microsoft Silverlight. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Silverlight does not properly validate pointers during HTML object rendering, which allows remote attackers to execute code via a crafted Silverlight application.
CVE-2016-3351 · Microsoft Internet Explorer and EdgeInformation Disclosure VulnerabilityKnown ransomware usePatch nowAdded to KEV May 24, 2022
Microsoft Internet Explorer and Edge Information Disclosure Vulnerability
Affects anyone using Microsoft Edge as their browser. The browser is the entry point for cloud apps (accounting SaaS, client portals, banking) — exploitation can lead to session theft or stored-credential exposure for everything you log into through it.
An information disclosure vulnerability exists in the way that certain functions in Internet Explorer and Edge handle objects in memory. The vulnerability could allow an attacker to detect specific files on the user's computer.
- KB3185319
- KB3185611
- KB3185614
- KB3189866
CVE-2017-0147 · Microsoft SMBv1 serverWindows SMBv1 Information Disclosure VulnerabilityKnown ransomware usePatch nowAdded to KEV May 24, 2022
Microsoft Windows SMBv1 Information Disclosure Vulnerability
Affects anyone running Microsoft SMBv1 server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
The SMBv1 server in Microsoft Windows allows remote attackers to obtain sensitive information from process memory via a crafted packet.
- KB4012606
- KB4013198
- KB4013429
- KB4012215
- +6 more
CVE-2020-0638 · Microsoft Update Notification ManagerPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV May 23, 2022
Microsoft Update Notification Manager Privilege Escalation Vulnerability
Affects anyone running Microsoft Update Notification Manager. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Update Notification Manager contains an unspecified vulnerability that allows for privilege escalation.
- KB4534276
- KB4534293
- KB4534273
- KB4528760
Microsoft Windows: 2 CVEsPatch nowadded May 23, 2022
- CVE-2019-1385Known ransomware use
Microsoft Windows AppX Deployment Extensions Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows AppX Deployment Extensions improperly performs privilege management, resulting in access to system files.
- KB4525237
- KB4523205
- KB4525241
- KB4524570
- CVE-2019-1130Known ransomware use
Microsoft Windows AppX Deployment Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows AppX Deployment Service (AppXSVC) improperly handles hard links.
- KB4507450
- KB4507435
- KB4507469
- KB4507455
- +7 more
CVE-2022-24521 · Microsoft WindowsCLFS Driver Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 13, 2022
Microsoft Windows CLFS Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) Driver contains an unspecified vulnerability that allows for privilege escalation.
- KB5012647
- KB5012591
- KB5012599
- KB5012604
- +11 more
Microsoft Active Directory: 2 CVEsPatch nowadded Apr 11, 2022
- CVE-2021-42287Known ransomware use
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
Affects anyone running Microsoft Active Directory. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
- KB5007206
- KB5007205
- KB5007186
- KB5007192
- +8 more
- CVE-2021-42278Known ransomware use
Microsoft Active Directory Domain Services Privilege Escalation Vulnerability
Affects anyone running Microsoft Active Directory. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Active Directory Domain Services contains an unspecified vulnerability that allows for privilege escalation.
- KB5007206
- KB5007205
- KB5007186
- KB5007192
- +8 more
CVE-2017-0148 · Microsoft SMBv1 serverSMBv1 Server Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Apr 6, 2022
Microsoft SMBv1 Server Remote Code Execution Vulnerability
Affects anyone running Microsoft SMBv1 server. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
The SMBv1 server in Microsoft allows remote attackers to execute arbitrary code via crafted packets.
- KB4012606
- KB4013198
- KB4013429
- KB4012215
- +6 more
CVE-2021-20028 · SonicWall Secure Remote Access (SRA)SQL Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 28, 2022
SonicWall Secure Remote Access (SRA) SQL Injection Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall Secure Remote Access (SRA) products contain an improper neutralization of a SQL Command leading to SQL injection.
CVE-2021-38646 · Microsoft OfficeAccess Connectivity Engine Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 28, 2022
Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability
Affects anyone using Microsoft 365 or Office to compose, store, or send email, documents, or spreadsheets. In a small practice, that's typically where client communications, engagement letters, and case notes live — credential compromise here means an attacker reads everything that platform stores.
Microsoft Office Access Connectivity Engine contains an unspecified vulnerability which can allow for remote code execution.
- KB5001997
- KB5001958
CVE-2016-0151 · Microsoft Client-Server Run-time Subsystem (CSRSS)Windows CSRSS Security Feature Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 28, 2022
Microsoft Windows CSRSS Security Feature Bypass Vulnerability
Affects anyone running Microsoft Client-Server Run-time Subsystem (CSRSS). Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
The Client-Server Run-time Subsystem (CSRSS) in Microsoft mismanages process tokens, which allows local users to gain privileges via a crafted application.
- KB3147461
- KB3147458
- KB3146723
Microsoft DirectX Graphics Kernel (DXGKRNL): 2 CVEsPatch nowadded Mar 28, 2022
- CVE-2018-8406Known ransomware use
Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability
Affects anyone running Microsoft DirectX Graphics Kernel (DXGKRNL). Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
- KB4343885
- KB4343909
- KB4343897
- KB4343892
- +1 more
- CVE-2018-8405Known ransomware use
Microsoft DirectX Graphics Kernel Privilege Escalation Vulnerability
Affects anyone running Microsoft DirectX Graphics Kernel (DXGKRNL). Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
An elevation of privilege vulnerability exists when the DirectX Graphics Kernel (DXGKRNL) driver improperly handles objects in memory.
- KB4343885
- KB4343909
- KB4343897
- KB4343892
- +3 more
Microsoft Windows: 2 CVEsPatch nowadded Mar 28, 2022
- CVE-2018-8440Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
An elevation of privilege vulnerability exists when Windows improperly handles calls to Advanced Local Procedure Call (ALPC).
- KB4457138
- KB4457128
- KB4457142
- KB4457132
- +9 more
- CVE-2017-0213Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows COM Aggregate Marshaler allows for privilege escalation when an attacker runs a specially crafted application.
- KB4019474
- KB4019473
- KB4019472
- KB4019264
- +7 more
CVE-2013-2551 · Microsoft Internet ExplorerUse-After-Free VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 28, 2022
Microsoft Internet Explorer Use-After-Free Vulnerability
Affects anyone running Microsoft Internet Explorer. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Use-after-free vulnerability in Microsoft Internet Explorer allows remote attackers to execute remote code via a crafted web site that triggers access to a deleted object.
Microsoft Windows: 2 CVEsPatch nowadded Mar 25, 2022
- CVE-2022-21999Known ransomware use
Microsoft Windows Print Spooler Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler contains an unspecified vulnerability which can allow for privilege escalation.
- KB5010351
- KB5010345
- KB5010342
- KB5010354
- +12 more
- CVE-2017-0146Known ransomware use
Microsoft Windows SMB Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
The SMBv1 server in Microsoft Windows allows remote attackers to perform remote code execution.
- KB4012606
- KB4013198
- KB4013429
- KB4012215
- +6 more
CVE-2020-2021 · Palo Alto Networks PAN-OSAuthentication Bypass VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 25, 2022
Palo Alto Networks PAN-OS Authentication Bypass Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Palo Alto Networks PAN-OS contains a vulnerability in SAML which allows an attacker to bypass authentication.
CVE-2010-2861 · Adobe ColdFusionDirectory Traversal VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 25, 2022
Adobe ColdFusion Directory Traversal Vulnerability
Affects anyone running Adobe ColdFusion. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.
Microsoft Windows: 10 CVEsPatch nowadded Mar 15, 2022
- CVE-2017-0101Known ransomware use
Microsoft Windows Transaction Manager Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows Transaction Manager improperly handles objects in memory.
- KB4012215
- KB4012212
- KB4011981
- CVE-2019-0543Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4480973
- KB4480966
- KB4480116
- KB4480978
- +10 more
- CVE-2019-1064Known ransomware use
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4503279
- KB4503286
- KB4503327
- KB4503284
- +2 more
- CVE-2019-0841Known ransomware use
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4493474
- KB4493464
- KB4493509
- KB4493441
- CVE-2019-1315Known ransomware use
Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows Error Reporting manager improperly handles hard links. An attacker who successfully exploited this vulnerability could overwrite a targeted file leading to an elevated status.
- KB4520010
- KB4520008
- KB4519338
- KB4520004
- +11 more
- CVE-2019-1129Known ransomware use
Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows AppXSVC improperly handles hard links. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4507450
- KB4507435
- KB4507469
- KB4507455
- +1 more
- CVE-2016-3309Known ransomware use
Microsoft Windows Kernel Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows kernel fails to properly handle objects in memory. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
- KB3177725
- KB3176492
- KB3176493
- KB3176495
- CVE-2019-1405Known ransomware use
Microsoft Windows Universal Plug and Play (UPnP) Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows UPnP service improperly allows COM object creation.
- KB4525237
- KB4523205
- KB4525241
- KB4524570
- +10 more
- CVE-2019-1322Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when Windows improperly handles authentication requests. An attacker who successfully exploited this vulnerability could run processes in an elevated context.
- KB4517389
- KB4520008
- KB4519338
- CVE-2019-1253Known ransomware use
Microsoft Windows AppX Deployment Server Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists when the Windows AppX Deployment Server improperly handles junctions.
- KB4516068
- KB4516058
- KB4512578
- KB4516066
- +1 more
Microsoft Win32k: 2 CVEsPatch nowadded Mar 15, 2022
- CVE-2018-8120Known ransomware use
Microsoft Win32k Privilege Escalation Vulnerability
Affects anyone running Microsoft Win32k. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory.
- KB4103718
- KB4103712
- KB4131188
- CVE-2015-2546Known ransomware use
Microsoft Win32k Memory Corruption Vulnerability
Affects anyone running Microsoft Win32k. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
The kernel-mode driver in Microsoft Windows OS and Server allows local users to gain privileges via a crafted application.
CVE-2019-1069 · Microsoft Task SchedulerPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 15, 2022
Microsoft Task Scheduler Privilege Escalation Vulnerability
Affects anyone running Microsoft Task Scheduler. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
A privilege escalation vulnerability exists in the way the Task Scheduler Service validates certain file operations.
- KB4503279
- KB4503286
- KB4503327
- KB4503284
- +3 more
CVE-2009-3960 · Adobe BlazeDSInformation Disclosure VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 7, 2022
Adobe BlazeDS Information Disclosure Vulnerability
Affects anyone running Adobe BlazeDS. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe BlazeDS, which is utilized in LifeCycle and Coldfusion, contains a vulnerability that allows for information disclosure.
Adobe Flash Player: 2 CVEsPatch nowadded Mar 3, 2022
- CVE-2016-1019Known ransomware use
Adobe Flash Player Arbitrary Code Execution Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Flash Player allows remote attackers to cause a denial of service or possibly execute arbitrary code.
- CVE-2015-7645Known ransomware use
Adobe Flash Player Arbitrary Code Execution Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Flash Player allows remote attackers to execute arbitrary code via a crafted SWF file.
CVE-2018-8581 · Microsoft Exchange ServerPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 3, 2022
Microsoft Exchange Server Privilege Escalation Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
A privilege escalation vulnerability exists in Microsoft Exchange Server. An attacker who successfully exploited this vulnerability could attempt to impersonate any other user of the Exchange server.
CVE-2010-0188 · Adobe Reader and AcrobatArbitrary Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 3, 2022
Adobe Reader and Acrobat Arbitrary Code Execution Vulnerability
Affects anyone opening, editing, or signing PDFs in Adobe Acrobat or Reader. For a CPA or legal practice, PDFs are typically client tax returns, engagement letters, signed agreements, and discovery documents — opening a malicious PDF runs attacker code in the user's session, which can pivot to file shares or email.
Unspecified vulnerability in Adobe Reader and Acrobat allows attackers to cause a denial of service or possibly execute arbitrary code.
CVE-2008-2992 · Adobe Acrobat and ReaderReader and Acrobat Input Validation VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 3, 2022
Adobe Reader and Acrobat Input Validation Vulnerability
Affects anyone opening, editing, or signing PDFs in Adobe Acrobat or Reader. For a CPA or legal practice, PDFs are typically client tax returns, engagement letters, signed agreements, and discovery documents — opening a malicious PDF runs attacker code in the user's session, which can pivot to file shares or email.
Adobe Acrobat and Reader contain an input validation issue in a JavaScript method that could potentially lead to remote code execution.
Microsoft Windows: 2 CVEsPatch nowadded Mar 3, 2022
- CVE-2021-41379Known ransomware use
Microsoft Windows Installer Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Installer contains an unspecified vulnerability that allows for privilege escalation.
- KB5007206
- KB5007189
- KB5007186
- KB5007205
- +11 more
- CVE-2016-0099Known ransomware use
Microsoft Windows Secondary Logon Service Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A privilege escalation vulnerability exists in Microsoft Windows if the Windows Secondary Logon Service fails to properly manage request handles in memory. An attacker who successfully exploited this vulnerability could run arbitrary code as an administrator.
CVE-2015-1701 · Microsoft Win32kPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Mar 3, 2022
Microsoft Win32k Privilege Escalation Vulnerability
Affects anyone running Microsoft Win32k. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
An unspecified vulnerability exists in the Win32k.sys kernel-mode driver in Microsoft Windows Server that allows a local attacker to execute arbitrary code with elevated privileges.
CVE-2019-0752 · Microsoft Internet ExplorerType Confusion VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 15, 2022
Microsoft Internet Explorer Type Confusion Vulnerability
Affects anyone running Microsoft Internet Explorer. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer
- KB4493451
- KB4493435
- KB4493474
- KB4493464
- +6 more
CVE-2018-8174 · Microsoft WindowsVBScript Engine Out-of-Bounds Write VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 15, 2022
Microsoft Windows VBScript Engine Out-of-Bounds Write Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution"
- KB4103727
- KB4103731
- KB4103721
- KB4103716
- +8 more
CVE-2018-15982 · Adobe Flash PlayerUse-After-Free VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 15, 2022
Adobe Flash Player Use-After-Free Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Flash Player com.adobe.tvsdk.mediacore.metadata Use After Free Vulnerability
CVE-2020-0796 · Microsoft SMBv3Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Feb 10, 2022
Microsoft SMBv3 Remote Code Execution Vulnerability
Affects anyone running Microsoft SMBv3. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
A remote code execution vulnerability exists in the way that the Microsoft Server Message Block 3.1.1 (SMBv3) protocol handles certain requests. An attacker who successfully exploited the vulnerability could gain the ability to execute code on the target server or client.
- KB4551762
Microsoft SMBv1: 2 CVEsPatch nowadded Feb 10, 2022
- CVE-2017-0144Known ransomware use
Microsoft SMBv1 Remote Code Execution Vulnerability
Affects anyone running Microsoft SMBv1. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
- KB4012598
- KB4012215
- KB4012212
- KB4012217
- +6 more
- CVE-2017-0145Known ransomware use
Microsoft SMBv1 Remote Code Execution Vulnerability
Affects anyone running Microsoft SMBv1. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
- KB4012606
- KB4013198
- KB4013429
- KB4012215
- +6 more
CVE-2021-20038 · SonicWall SMA 100 AppliancesStack-Based Buffer Overflow VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 28, 2022
SonicWall SMA 100 Appliances Stack-Based Buffer Overflow Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA 100 devies are vulnerable to an unauthenticated stack-based buffer overflow vulnerability where exploitation can result in code execution.
CVE-2020-0787 · Microsoft WindowsBackground Intelligent Transfer Service (BITS) Improper Privilege Management VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 28, 2022
Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this vulnerability to execute arbitrary code with system-level privileges.
- KB4540689
- KB4538461
- KB4540673
- KB4540681
- +10 more
CVE-2018-8453 · Microsoft Win32kPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 21, 2022
Microsoft Win32k Privilege Escalation Vulnerability
Affects anyone running Microsoft Win32k. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Windows Win32k contains a vulnerability that allows an attacker to escalate privileges.
- KB4462937
- KB4462919
- KB4462918
- KB4462922
- +10 more
Fortinet FortiOS and FortiProxy: 2 CVEsPatch nowadded Jan 10, 2022
- CVE-2018-13382Known ransomware use
Fortinet FortiOS and FortiProxy Improper Authorization
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
An Improper Authorization vulnerability in Fortinet FortiOS and FortiProxy under SSL VPN web portal allows an unauthenticated attacker to modify the password.
- CVE-2018-13383Known ransomware use
Fortinet FortiOS and FortiProxy Out-of-bounds Write
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
A heap buffer overflow in Fortinet FortiOS and FortiProxy may cause the SSL VPN web service termination for logged in users.
CVE-2019-1458 · Microsoft Win32kPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 10, 2022
Microsoft Win32k Privilege Escalation Vulnerability
Affects anyone running Microsoft Win32k. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
A privilege escalation vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka 'Win32k EoP.
- KB4530681
- KB4530689
- KB4530734
- KB4530692
- +6 more
CVE-2019-1579 · Palo Alto Networks PAN-OSRemote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Jan 10, 2022
Palo Alto Networks PAN-OS Remote Code Execution Vulnerability
Affects anyone behind a Palo Alto firewall or using GlobalProtect VPN. The firewall is the network edge; the VPN is how remote workers reach inside the perimeter — exploitation puts an attacker on the internal network without touching a workstation.
Remote Code Execution in PAN-OS with GlobalProtect Portal or GlobalProtect Gateway Interface enabled.
CVE-2021-43890 · Microsoft WindowsAppX Installer Spoofing VulnerabilityKnown ransomware usePatch nowAdded to KEV Dec 15, 2021
Microsoft Windows AppX Installer Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows AppX Installer contains a spoofing vulnerability which has a high impacts to confidentiality, integrity, and availability.
CVE-2021-42321 · Microsoft ExchangeServer Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 17, 2021
Microsoft Exchange Server Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
An authenticated attacker could leverage improper validation in cmdlet arguments within Microsoft Exchange and perform remote code execution.
CVE-2021-40449 · Microsoft WindowsWin32k Privilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 17, 2021
Microsoft Windows Win32k Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Unspecified vulnerability allows for an authenticated user to escalate privileges.
- KB5006672
- KB5006667
- KB5006670
- KB5006699
- +11 more
Ivanti Pulse Connect Secure: 2 CVEsPatch nowadded Nov 3, 2021
- CVE-2021-22893Known ransomware use
Ivanti Pulse Connect Secure Use-After-Free Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Pulse Connect Secure contains a use-after-free vulnerability that allow a remote, unauthenticated attacker to execute code via license services.
- CVE-2019-11510Known ransomware use
Ivanti Pulse Connect Secure Arbitrary File Read Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Pulse Connect Secure contains an arbitrary file read vulnerability that allows an unauthenticated remote attacker with network access via HTTPS to send a specially crafted URI.
SonicWall Email Security: 3 CVEsPatch nowadded Nov 3, 2021
- CVE-2021-20023Known ransomware use
SonicWall Email Security Path Traversal Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall Email Security contains a path traversal vulnerability that allows a post-authenticated attacker to read files on the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20022 to achieve privilege escalation.
- CVE-2021-20021Known ransomware use
SonicWall Email Security Improper Privilege Management Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall Email Security contains an improper privilege management vulnerability that allows an attacker to create an administrative account by sending a crafted HTTP request to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20022 and CVE-2021-20023 to achieve privilege escalation.
- CVE-2021-20022Known ransomware use
SonicWall Email Security Unrestricted Upload of File Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall Email Security contains an unrestricted upload of file with dangerous type vulnerability that allows a post-authenticated attacker to upload a file to the remote host. This vulnerability has known usage in a SonicWall Email Security exploit chain along with CVE-2021-20021 and CVE-2021-20023 to achieve privilege escalation.
CVE-2017-0199 · Microsoft Office and WordPadRemote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft Office and WordPad Remote Code Execution Vulnerability
Affects anyone using Microsoft 365 or Office to compose, store, or send email, documents, or spreadsheets. In a small practice, that's typically where client communications, engagement letters, and case notes live — credential compromise here means an attacker reads everything that platform stores.
Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution.
CVE-2019-7481 · SonicWall SMA100SQL Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
SonicWall SMA100 SQL Injection Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SMA100 contains a SQL injection vulnerability allowing an unauthenticated user to gain read-only access to unauthorized resources.
CVE-2020-1472 · Microsoft NetlogonPrivilege Escalation VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft Netlogon Privilege Escalation Vulnerability
Affects anyone running Microsoft Netlogon. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon.
- KB4601319
- KB4601345
- KB4601315
- KB4565351
- +7 more
Microsoft Windows: 7 CVEsPatch nowadded Nov 3, 2021
- CVE-2014-1812Known ransomware use
Microsoft Windows Group Policy Preferences Password Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Active Directory contains a privilege escalation vulnerability due to the way it distributes passwords that are configured using Group Policy preferences. An authenticated attacker who successfully exploits the vulnerability could decrypt the passwords and use them to elevate privileges on the domain.
- CVE-2019-1215Known ransomware use
Microsoft Windows Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows contains an unspecified vulnerability due to the way ws2ifsl.sys (Winsock) handles objects in memory, allowing for privilege escalation. Successful exploitation allows an attacker to execute code with elevated privileges.
- KB4516068
- KB4516058
- KB4512578
- KB4516066
- +11 more
- CVE-2017-0143Known ransomware use
Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Server Message Block 1.0 (SMBv1) contains an unspecified vulnerability that allows for remote code execution.
- KB4012606
- KB4013198
- KB4013429
- KB4012215
- +6 more
- CVE-2021-36955Known ransomware use
Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Common Log File System (CLFS) driver contains an unspecified vulnerability that allows for privilege escalation.
- KB5005568
- KB5005566
- KB5005565
- KB5005575
- +10 more
- CVE-2021-34527Known ransomware use
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler contains an unspecified vulnerability due to the Windows Print Spooler service improperly performing privileged file operations. Successful exploitation allows an attacker to perform remote code execution with SYSTEM privileges. The vulnerability is also known under the moniker of PrintNightmare.
- KB5004947
- KB5005575
- KB5004945
- KB5007215
- +13 more
- CVE-2021-36942Known ransomware use
Microsoft Windows Local Security Authority (LSA) Spoofing Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Local Security Authority (LSA) contains a spoofing vulnerability allowing an unauthenticated attacker to call a method on the LSARPC interface and coerce the domain controller to authenticate against another server using NTLM.
- KB5005030
- KB5005033
- KB5005043
- KB5005090
- +7 more
- CVE-2021-1675Known ransomware use
Microsoft Windows Print Spooler Remote Code Execution Vulnerability
Affects anyone running Windows workstations or servers. In a small CPA, legal, or dental practice, Windows is typically the platform your accounting, document management, or practice management software runs on — exploitation gives an attacker access to whatever client files and credentials live on those machines.
Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution.
- KB5003646
- KB5003635
- KB5003637
- KB5003687
- +9 more
CVE-2020-3580 · Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD)ASA and FTD Cross-Site Scripting (XSS) VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Cisco ASA and FTD Cross-Site Scripting (XSS) Vulnerability
Affects anyone with Cisco networking or security appliances on their network — typically a firewall, switch, or remote-access VPN. That device controls traffic to and from every workstation; exploitation can mean an attacker pivots inside the network without touching any user device.
Cisco Adaptive Security Appliance (ASA) and Firepower Threat Defense (FTD) contain an insufficient input validation vulnerability for user-supplied input by the web services interface. Successful exploitation could allow an attacker to perform cross-site scripting (XSS) in the context of the interface or access sensitive browser-based information.
CVE-2021-38647 · Microsoft Open Management Infrastructure (OMI)Remote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
Affects anyone running Microsoft Open Management Infrastructure (OMI). Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Open Management Infrastructure (OMI) within Azure VM Management Extensions contains an unspecified vulnerability allowing remote code execution.
Microsoft Exchange Server: 8 CVEsPatch nowadded Nov 3, 2021
- CVE-2021-26855Known ransomware use
Microsoft Exchange Server Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- CVE-2020-0688Known ransomware use
Microsoft Exchange Server Validation Key Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server Validation Key fails to properly create unique keys at install time, allowing for remote code execution.
- CVE-2021-34523Known ransomware use
Microsoft Exchange Server Privilege Escalation Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
- CVE-2021-34473Known ransomware use
Microsoft Exchange Server Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
- CVE-2021-31207Known ransomware use
Microsoft Exchange Server Security Feature Bypass Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
- CVE-2021-26858Known ransomware use
Microsoft Exchange Server Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- CVE-2021-27065Known ransomware use
Microsoft Exchange Server Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- CVE-2021-26857Known ransomware use
Microsoft Exchange Server Remote Code Execution Vulnerability
Affects anyone running on-premises Microsoft Exchange Server. If you have Exchange in your office (as opposed to Microsoft 365 hosted email), it's the mail server holding all internal email — full compromise reads every conversation it stores.
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
CVE-2017-11882 · Microsoft OfficeMemory Corruption VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft Office Memory Corruption Vulnerability
Affects anyone using Microsoft 365 or Office to compose, store, or send email, documents, or spreadsheets. In a small practice, that's typically where client communications, engagement letters, and case notes live — credential compromise here means an attacker reads everything that platform stores.
Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user.
CVE-2020-0878 · Microsoft Edge and Internet ExplorerMemory Corruption VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft Edge and Internet Explorer Memory Corruption Vulnerability
Affects anyone using Microsoft Edge as their browser. The browser is the entry point for cloud apps (accounting SaaS, client portals, banking) — exploitation can lead to session theft or stored-credential exposure for everything you log into through it.
Microsoft Edge and Internet Explorer contain a memory corruption vulnerability that allows attackers to execute code in the context of the current user.
- KB4577032
- KB4570333
- KB4574727
- KB4577041
- +8 more
Microsoft Internet Explorer: 2 CVEsPatch nowadded Nov 3, 2021
- CVE-2021-26411Known ransomware use
Microsoft Internet Explorer Memory Corruption Vulnerability
Affects anyone running Microsoft Internet Explorer. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Internet Explorer contains an unspecified vulnerability that allows for memory corruption.
- KB5000844
- KB5000800
- KB5000809
- KB5000822
- +7 more
- CVE-2019-1367Known ransomware use
Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability
Affects anyone running Microsoft Internet Explorer. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user.
- KB4520007
- KB4519974
- KB4520002
- KB4520010
- +8 more
CVE-2018-4878 · Adobe Flash PlayerUse-After-Free VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Adobe Flash Player Use-After-Free Vulnerability
Affects anyone running Adobe Flash Player. If it's part of your document workflow, exploitation can lead to code execution when a user opens an attacker-controlled file.
Adobe Flash Player contains a use-after-free vulnerability that could allow for code execution.
CVE-2019-0708 · Microsoft Remote Desktop ServicesRemote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft Remote Desktop Services Remote Code Execution Vulnerability
Affects anyone running Microsoft Remote Desktop Services. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Remote Desktop Services, formerly known as Terminal Service, contains an unspecified vulnerability that allows an unauthenticated attacker to connect to the target system using RDP and send specially crafted requests. Successful exploitation allows for remote code execution. The vulnerability is also known under the moniker of BlueKeep.
- KB4499164
- KB4499175
- KB4499149
- KB4499180
Fortinet FortiOS: 2 CVEsPatch nowadded Nov 3, 2021
- CVE-2020-12812Known ransomware use
Fortinet FortiOS SSL VPN Improper Authentication Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS SSL VPN contains an improper authentication vulnerability that may allow a user to login successfully without being prompted for the second factor of authentication (FortiToken) if they change the case in their username.
- CVE-2018-13379Known ransomware use
Fortinet FortiOS SSL VPN Path Traversal Vulnerability
Affects anyone whose internet connection goes through a Fortinet appliance — typically a FortiGate firewall or FortiClient VPN. The firewall sits between every device in the office and the internet; exploitation can mean an attacker gets inside the network perimeter without touching a workstation.
Fortinet FortiOS SSL VPN web portal contains a path traversal vulnerability that may allow an unauthenticated attacker to download FortiOS system files through specially crafted HTTP resource requests.
Microsoft Win32k: 2 CVEsPatch nowadded Nov 3, 2021
- CVE-2021-1732Known ransomware use
Microsoft Win32k Privilege Escalation Vulnerability
Affects anyone running Microsoft Win32k. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation.
- KB4601354
- KB4601345
- KB4601315
- KB4601319
- CVE-2016-0167Known ransomware use
Microsoft Win32k Privilege Escalation Vulnerability
Affects anyone running Microsoft Win32k. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft Win32k contains an unspecified vulnerability that allows for privilege escalation via a crafted application
- KB3145739
- KB3147461
- KB3147458
CVE-2021-40444 · Microsoft MSHTMLRemote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft MSHTML Remote Code Execution Vulnerability
Affects anyone running Microsoft MSHTML. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft MSHTML contains a unspecified vulnerability that allows for remote code execution.
- KB5005568
- KB5005566
- KB5005565
- KB5005575
- +9 more
CVE-2019-0604 · Microsoft SharePointRemote Code Execution VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Microsoft SharePoint Remote Code Execution Vulnerability
Affects anyone running Microsoft SharePoint. Microsoft products in a small practice typically sit close to credentials, email, or document workflows — treat the patch as in-scope.
Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account.
CVE-2019-11539 · Ivanti Pulse Connect Secure and Pulse Policy SecurePulse Connect Secure and Policy Secure Command Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
Ivanti Pulse Connect Secure and Policy Secure Command Injection Vulnerability
Affects anyone using Ivanti VPN (Connect Secure or Pulse) or Ivanti endpoint management. The VPN is what remote workers use to reach internal systems; the endpoint management tool typically has admin reach into every laptop — exploitation in either is high-impact.
Ivanti Pulse Connect Secure and Policy Secure allows an authenticated attacker from the admin web interface to inject and execute commands.
CVE-2021-20016 · SonicWall SSLVPN SMA100SQL Injection VulnerabilityKnown ransomware usePatch nowAdded to KEV Nov 3, 2021
SonicWall SSLVPN SMA100 SQL Injection Vulnerability
Affects anyone whose network is fronted by a SonicWall firewall or SSL VPN. The device sits at the edge between your office and the internet and authenticates remote workers — exploitation typically means an attacker reaches inside without needing a user credential.
SonicWall SSLVPN SMA100 contains a SQL injection vulnerability that allows remote exploitation for credential access by an unauthenticated attacker.
