Vendor: Microsoft | Product: MSHTML | Microsoft MSHTML engine contains an improper input validation vulnerability that allows for remote code execution vulnerability. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-11882 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office contains a memory corruption vulnerability that allows remote code execution in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0674 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability due to the way the Scripting Engine handles objects in memory. Successful exploitation could allow remote code execution in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-27059 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office contains an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2019-1367 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability in how the scripting engine handles objects in memory. Successful exploitation allows for remote code execution in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-0199 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office and WordPad | Microsoft Office and WordPad contain an unspecified vulnerability due to the way the applications parse specially crafted files. Successful exploitation allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-1380 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-1429 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability which can allow for remote code execution in the context of the current user. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2017-11774 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Office | Microsoft Office Outlook contains a security feature bypass vulnerability due to improperly handling objects in memory. Successful exploitation allows an attacker to execute commands. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0968 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Internet Explorer | Microsoft Internet Explorer contains a memory corruption vulnerability due to how the Scripting Engine handles objects in memory, leading to remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-1472 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Netlogon | Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of…
Read full source summary
Vendor: Microsoft | Product: Netlogon | Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a domain controller. An attacker who successfully exploits the vulnerability could run a specially crafted application on a device on the network. The vulnerability is also known under the moniker of Zerologon. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-26855 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-26858 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-27065 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Exchange Server | Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-1054 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Win32k | Microsoft Win32k contains a privilege escalation vulnerability when the Windows kernel-mode driver fails to properly handle objects in memory. Successful exploitation allows an attacker to execute code in kernel mode. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2021-1675 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Print Spooler contains an unspecified vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2021-34448 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows Scripting Engine contains an unspecified vulnerability that allows for memory corruption. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2021-11-17
CVE-2020-0601 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: Windows | Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the…
Read full source summary
Vendor: Microsoft | Product: Windows | Microsoft Windows CryptoAPI (Crypt32.dll) contains a spoofing vulnerability in the way it validates Elliptic Curve Cryptography (ECC) certificates. An attacker could exploit the vulnerability by using a spoofed code-signing certificate to sign a malicious executable, making it appear the file was from a trusted, legitimate source. A successful exploit could also allow the attacker to conduct man-in-the-middle attacks and decrypt confidential information on user connections to the affected software. The vulnerability is also known under the moniker of CurveBall. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2019-0604 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: SharePoint | Microsoft SharePoint fails to check the source markup of an application package. An attacker who successfully exploits the vulnerability could run remote code in the context of the SharePoint application pool and the SharePoint server farm account. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
CVE-2020-0646 · CISA Known Exploited Vulnerabilities
Vendor: Microsoft | Product: .NET Framework | Microsoft .NET Framework contains an improper input validation vulnerability that allows for remote code execution. | Required action: Apply updates per vendor instructions. | Federal remediation due: 2022-05-03
BioThreat Corporation threat monitoring workflows bring together reports published by the named source institutions. These are public-source reports; publication dates and source links accompany each record.
01 / SOURCE
Read the source
Open a feed to search titles, summaries, or CVE IDs. Follow a record’s title or the Official source link to read the reporting in its original context.
Daily snapshots are collected when a source is visited and successfully refreshed. Archive dates indicate collection dates, and the archive may contain gaps.
JSON links provide machine-readable records with source names, titles, summaries, links, and publication dates. Choose a saved date for the records collected in that snapshot.