Snapshot
Nov. 4, 2022 - Nov. 11, 2022
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2022-41128 | Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution. | HIGH | Microsoft | Nov. 8, 2022 |
CVE-2022-41073 | Microsoft Windows Print Spooler contains an unspecified vulnerability which allows an attacker to gain SYSTEM-level privileges. | HIGH | Microsoft | Nov. 8, 2022 |
CVE-2022-41125 | Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability which allows an attacker to gain SYSTEM-level privileges. | HIGH | Microsoft | Nov. 8, 2022 |
CVE-2022-41091 | Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. | MEDIUM | Microsoft | Nov. 8, 2022 |
CVE-2021-25337 | Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. | HIGH | Samsung | Nov. 8, 2022 |
CVE-2021-25369 | Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. | MEDIUM | Samsung | Nov. 8, 2022 |
CVE-2021-25370 | Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. | MEDIUM | Samsung | Nov. 8, 2022 |
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2022-40304 | An issue was discovered in libxml2 before 2.10.3. | N/A | Risk Context N/A | |
CVE-2022-40303 | An issue was discovered in libxml2 before 2.10.3. | HIGH | Risk Context N/A | |
CVE-2022-41128 | Windows Scripting Languages Remote Code Execution Vulnerability. | HIGH | Microsoft |
CISA Known Exploited Actively Exploited Remote Code Execution |
CVE-2022-41125 | Windows CNG Key Isolation Service Elevation of Privilege Vulnerability. | HIGH | Microsoft |
CISA Known Exploited |
CVE-2022-41091 | Windows Mark of the Web Security Feature Bypass Vulnerability. | MEDIUM | Microsoft |
CISA Known Exploited |
CVE-2022-41073 | Windows Print Spooler Elevation of Privilege Vulnerability. | HIGH | Microsoft |
CISA Known Exploited |
CVE-2022-20465 | In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass ... | MEDIUM | Risk Context N/A | |
CVE-2022-41082 | Microsoft Exchange Server Remote Code Execution Vulnerability. | HIGH | Microsoft |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2022-41040 | Microsoft Exchange Server Elevation of Privilege Vulnerability. | HIGH | Microsoft |
CISA Known Exploited Actively Exploited Used In Ransomware Public Exploits Available |
CISA Known Exploited Vulnerabilities
CISA added 7 vulnerabilities to the known exploited vulnerabilities list.
Microsoft — Windows |
CVE-2022-41128 / Added: Nov. 8, 2022 |
HIGH CVSS 8.80 |
Microsoft Windows contains an unspecified vulnerability in the JScript9 scripting language which allows for remote code execution. |
Headlines |
Microsoft — Windows |
CVE-2022-41073 / Added: Nov. 8, 2022 |
HIGH CVSS 7.80 |
Microsoft Windows Print Spooler contains an unspecified vulnerability which allows an attacker to gain SYSTEM-level privileges. |
Headlines |
Microsoft — Windows |
CVE-2022-41125 / Added: Nov. 8, 2022 |
HIGH CVSS 7.80 |
Microsoft Windows Cryptographic Next Generation (CNG) Key Isolation Service contains an unspecified vulnerability which allows an attacker to gain SYSTEM-level privileges. |
Headlines |
Microsoft — Windows |
CVE-2022-41091 / Added: Nov. 8, 2022 |
MEDIUM CVSS 5.40 |
Microsoft Windows Mark of the Web (MOTW) contains a security feature bypass vulnerability resulting in a limited loss of integrity and availability of security features. |
Headlines |
Samsung — Mobile Devices |
CVE-2021-25337 / Added: Nov. 8, 2022 |
HIGH CVSS 7.10 |
Samsung mobile devices contain an improper access control vulnerability in clipboard service which allows untrusted applications to read or write arbitrary files. This vulnerability was chained with CVE-2021-25369 and CVE-2021-25370. |
Headlines |
Samsung — Mobile Devices |
CVE-2021-25369 / Added: Nov. 8, 2022 |
MEDIUM CVSS 5.50 |
Samsung mobile devices using Mali GPU contains an improper access control vulnerability in sec_log file. Exploitation of the vulnerability exposes sensitive kernel information to the userspace. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25370. |
Samsung — Mobile Devices |
CVE-2021-25370 / Added: Nov. 8, 2022 |
MEDIUM CVSS 4.40 |
Samsung mobile devices using Mali GPU contain an incorrect implementation handling file descriptor in dpu driver. This incorrect implementation results in memory corruption, leading to kernel panic. This vulnerability was chained with CVE-2021-25337 and CVE-2021-25369. |
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2022-41128 |
HIGH CVSS 8.80 |
CISA Known Exploited Actively Exploited Remote Code Execution |
Published: Nov. 9, 2022 |
Windows Scripting Languages Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41118. |
Vendor Impacted: Microsoft |
Products Impacted: Windows Server 2012, Windows 7, Windows Server 2022, Windows 8.1, Windows, Windows Server 2019, Windows Server 2016, Windows 11, Windows 10, Windows Server 2008 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-41125 |
HIGH CVSS 7.80 |
CISA Known Exploited |
Published: Nov. 9, 2022 |
Windows CNG Key Isolation Service Elevation of Privilege Vulnerability. |
Vendor Impacted: Microsoft |
Products Impacted: Windows Server 2012, Windows 7, Windows Server 2022, Windows 8.1, Windows, Windows Server 2019, Windows Server 2016, Windows 11, Windows 10 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-41091 |
MEDIUM CVSS 5.40 |
CISA Known Exploited |
Published: Nov. 9, 2022 |
Windows Mark of the Web Security Feature Bypass Vulnerability. This CVE ID is unique from CVE-2022-41049. |
Vendor Impacted: Microsoft |
Products Impacted: Windows Server 2022, Windows, Windows Server 2019, Windows Server 2016, Windows 11, Windows 10 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-41073 |
HIGH CVSS 7.80 |
CISA Known Exploited |
Published: Nov. 9, 2022 |
Windows Print Spooler Elevation of Privilege Vulnerability. |
Vendor Impacted: Microsoft |
Products Impacted: Windows Server 2012, Windows 7, Windows Server 2022, Windows 8.1, Windows, Windows Server 2019, Windows Server 2016, Windows 11, Windows 10, Windows Server 2008 |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-20465 |
MEDIUM CVSS 4.60 |
Risk Context N/A |
Published: Nov. 8, 2022 |
In dismiss and related functions of KeyguardHostViewController.java and related files, there is a possible lockscreen bypass due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-10 Android-11 Android-12 Android-12L Android-13Android ID: A-218500036 |
Vendor Impacted: Google |
Product Impacted: Android |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-41082 |
HIGH CVSS 8.80 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Oct. 3, 2022 |
Microsoft Exchange Server Remote Code Execution Vulnerability. |
Vendor Impacted: Microsoft |
Product Impacted: Exchange Server |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-41040 |
HIGH CVSS 8.80 |
CISA Known Exploited Actively Exploited Used In Ransomware Public Exploits Available |
Published: Oct. 3, 2022 |
Microsoft Exchange Server Elevation of Privilege Vulnerability. |
Vendor Impacted: Microsoft |
Product Impacted: Exchange Server |
Quotes
|
Headlines
|
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.