Snapshot
Oct. 21, 2022 - Oct. 28, 2022
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2022-3723 | Google Chromium V8 contains a type confusion vulnerability. Specific impacts from exploitation are not available at this time. | HIGH | Oct. 28, 2022 | |
CVE-2022-42827 | Apple iOS and iPadOS kernel contain an out-of-bounds write vulnerability which can allow an application to perform code execution with kernel privileges. | HIGH | Apple | Oct. 25, 2022 |
CVE-2020-3433 | Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges. | HIGH | Cisco | Oct. 24, 2022 |
CVE-2020-3153 | Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. | MEDIUM | Cisco | Oct. 24, 2022 |
CVE-2018-19323 | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. | HIGH | GIGABYTE | Oct. 24, 2022 |
CVE-2018-19321 | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. | HIGH | GIGABYTE | Oct. 24, 2022 |
CVE-2018-19320 | The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. | HIGH | GIGABYTE | Oct. 24, 2022 |
CVE-2018-19322 | The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. | MEDIUM | GIGABYTE | Oct. 24, 2022 |
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2022-3723 | Type confusion in V8 in Google Chrome prior to 107.0.5304.87 allowed a remote attacker to potentially exploit heap corruption... | HIGH |
CISA Known Exploited Actively Exploited |
|
CVE-2022-42827 | An out-of-bounds write issue was addressed with improved bounds checking. | HIGH | Apple |
CISA Known Exploited Actively Exploited |
CVE-2022-32946 | This issue was addressed with improved entitlements. | MEDIUM | Apple | Risk Context N/A |
CVE-2022-31678 | VMware Cloud Foundation contains an XML External Entity vulnerability. | CRITICAL | Vmware | Risk Context N/A |
CVE-2022-32917 | The issue was addressed with improved bounds checks. | HIGH | Apple |
CISA Known Exploited Actively Exploited |
CVE-2022-32894 | An out-of-bounds write issue was addressed with improved bounds checking. | HIGH | Apple |
CISA Known Exploited Actively Exploited |
CVE-2022-35737 | SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a strin... | HIGH | Sqlite |
Public Exploits Available |
CVE-2021-39144 | XStream is a simple library to serialize objects to XML and back again. | HIGH | Debian, Netapp, Oracle, Fedoraproject |
Public Exploits Available |
CVE-2020-3433 | A vulnerability in the interprocess communication channel of Cisco AnyConnect Secure Mobility Client for Windows could allow... | HIGH | Cisco |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
CVE-2020-3153 | A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticate... | MEDIUM | Cisco |
CISA Known Exploited Actively Exploited Used In Ransomware Public Exploits Available |
CISA Known Exploited Vulnerabilities
CISA added 8 vulnerabilities to the known exploited vulnerabilities list.
Cisco — AnyConnect Secure |
CVE-2020-3433 / Added: Oct. 24, 2022 |
HIGH CVSS 7.80 |
Cisco AnyConnect Secure Mobility Client for Windows interprocess communication (IPC) channel allows for insufficient validation of resources that are loaded by the application at run time. An attacker with valid credentials on Windows could execute code on the affected machine with SYSTEM privileges. |
Headlines
|
Cisco — AnyConnect Secure |
CVE-2020-3153 / Added: Oct. 24, 2022 |
MEDIUM CVSS 6.50 |
Cisco AnyConnect Secure Mobility Client for Windows allows for incorrect handling of directory paths. An attacker with valid credentials on Windows would be able to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. |
Headlines
|
GIGABYTE — Multiple Products |
CVE-2018-19323 / Added: Oct. 24, 2022 |
HIGH CVSS 9.00 |
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. |
GIGABYTE — Multiple Products |
CVE-2018-19321 / Added: Oct. 24, 2022 |
HIGH CVSS 7.20 |
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges. |
GIGABYTE — Multiple Products |
CVE-2018-19320 / Added: Oct. 24, 2022 |
HIGH CVSS 7.20 |
The GDrv low-level driver in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system. |
Headlines |
GIGABYTE — Multiple Products |
CVE-2018-19322 / Added: Oct. 24, 2022 |
MEDIUM CVSS 4.60 |
The GPCIDrv and GDrv low-level drivers in GIGABYTE App Center, AORUS Graphics Engine, XTREME Gaming Engine, and OC GURU II expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges. |
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2022-32946 |
MEDIUM CVSS 5.50 |
Risk Context N/A |
Published: Nov. 1, 2022 |
This issue was addressed with improved entitlements. This issue is fixed in iOS 16.1 and iPadOS 16. An app may be able to record audio using a pair of connected AirPods. |
Vendor Impacted: Apple |
Products Impacted: Ipad Os, Iphone Os |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-31678 |
CRITICAL CVSS 9.10 |
Risk Context N/A |
Published: Oct. 28, 2022 |
VMware Cloud Foundation (NSX-V) contains an XML External Entity (XXE) vulnerability. On VCF 3.x instances with NSX-V deployed, this may allow a user to exploit this issue leading to a denial-of-service condition or unintended information disclosure. |
Vendor Impacted: Vmware |
Products Impacted: Cloud Foundation, Nsx Data Center |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-32917 |
HIGH CVSS 7.80 |
CISA Known Exploited Actively Exploited |
Published: Sept. 20, 2022 |
The issue was addressed with improved bounds checks. This issue is fixed in macOS Monterey 12.6, iOS 15.7 and iPadOS 15.7, iOS 16, macOS Big Sur 11.7. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited.. |
Vendor Impacted: Apple |
Products Impacted: Ios, Ipados, And Macos, Iphone Os, Macos, Ipados |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-32894 |
HIGH CVSS 7.80 |
CISA Known Exploited Actively Exploited |
Published: Aug. 24, 2022 |
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 15.6.1 and iPadOS 15.6.1, macOS Monterey 12.5.1. An application may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited. |
Vendor Impacted: Apple |
Products Impacted: Ios And Macos, Macos, Iphone Os, Ipados, Watchos |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-35737 |
HIGH CVSS 7.50 |
Public Exploits Available |
Published: Aug. 3, 2022 |
SQLite 1.0.12 through 3.39.x before 3.39.2 sometimes allows an array-bounds overflow if billions of bytes are used in a string argument to a C API. |
Vendor Impacted: Sqlite |
Product Impacted: Sqlite |
Quotes
|
Headlines |
Back to top ↑ |
CVE-2021-39144 |
HIGH CVSS 8.50 |
Public Exploits Available |
Published: Aug. 23, 2021 |
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stream. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. XStream 1.4.18 uses no longer a blacklist by default, since it cannot be secured for general purpose. |
Vendors Impacted: Debian, Netapp, Oracle, Fedoraproject |
Products Impacted: Debian Linux, Snapmanager, Retail Xstore Point Of Service, Utilities Framework, Communications Cloud Native Core Bin, Communications Unified Inventory Man, Webcenter Portal, Fedora, Communications Cloud Native Core Pol, Communications Billing And Revenue M, Business Activity Monitoring, Utilities Testing Accelerator, Communications Cloud Native Core Aut, Commerce Guided Search |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2020-3433 |
HIGH CVSS 7.80 |
CISA Known Exploited Actively Exploited Remote Code Execution Public Exploits Available |
Published: Aug. 17, 2020 |
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The vulnerability is due to insufficient validation of resources that are loaded by the application at run time. An attacker could exploit this vulnerability by sending a crafted IPC message to the AnyConnect process. A successful exploit could allow the attacker to execute arbitrary code on the affected machine with SYSTEM privileges. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. |
Vendor Impacted: Cisco |
Product Impacted: Anyconnect Secure |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2020-3153 |
MEDIUM CVSS 6.50 |
CISA Known Exploited Actively Exploited Used In Ransomware Public Exploits Available |
Published: Feb. 19, 2020 |
A vulnerability in the installer component of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated local attacker to copy user-supplied files to system level directories with system level privileges. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by creating a malicious file and copying the file to a system directory. An exploit could allow the attacker to copy malicious files to arbitrary locations with system level privileges. This could include DLL pre-loading, DLL hijacking, and other related attacks. To exploit this vulnerability, the attacker needs valid credentials on the Windows system. |
Vendor Impacted: Cisco |
Product Impacted: Anyconnect Secure |
Quotes
|
Headlines
|
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.