Snapshot
Jan. 6, 2023 - Jan. 13, 2023
CISA Known Exploited Vulnerabilities |
||||
---|---|---|---|---|
CVE | Summary | Severity | Vendor | Date Added |
CVE-2022-41080 | Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation. This vulnerability is chainable with CVE-2022-41082, which allows for remote code execution. | CRITICAL | Microsoft | Jan. 10, 2023 |
CVE-2023-21674 | Microsoft Windows Advanced Local Procedure Call (ALPC) contains an unspecified vulnerability that allows for privilege escalation. | HIGH | Microsoft | Jan. 10, 2023 |
Vulnerabilities In The News |
||||
CVE | Summary | Severity | Vendor | Risk Context |
CVE-2022-23529 (7) | node-jsonwebtoken is a JsonWebToken implementation for node.js. | CRITICAL |
Actively Exploited Remote Code Execution Public Exploits Available |
|
CVE-2022-41080 (4) | Microsoft Exchange Server Elevation of Privilege Vulnerability. | CRITICAL | Microsoft |
CISA Known Exploited Used In Ransomware Public Exploits Available |
CVE-2023-21674 (22) | Windows Advanced Local Procedure Call Elevation of Privilege Vulnerability. | HIGH | Microsoft |
CISA Known Exploited Actively Exploited |
CVE-2023-21549 (14) | Windows SMB Witness Service Elevation of Privilege Vulnerability. | HIGH | Risk Context N/A | |
CVE-2023-21762 (5) | Microsoft Exchange Server Spoofing Vulnerability. | HIGH | Risk Context N/A | |
CVE-2023-21745 (5) | Microsoft Exchange Server Spoofing Vulnerability. | HIGH | Risk Context N/A | |
CVE-2023-21764 (8) | Microsoft Exchange Server Elevation of Privilege Vulnerability. | HIGH | Risk Context N/A | |
CVE-2023-21763 (8) | Microsoft Exchange Server Elevation of Privilege Vulnerability. | HIGH | Risk Context N/A | |
CVE-2022-41123 (6) | Microsoft Exchange Server Elevation of Privilege Vulnerability. | HIGH | Microsoft | Risk Context N/A |
CVE-2023-21743 (10) | Microsoft SharePoint Server Security Feature Bypass Vulnerability. | MEDIUM |
Actively Exploited |
CISA Known Exploited Vulnerabilities
CISA added 2 vulnerabilities to the known exploited vulnerabilities list.
In The News
Vulnerabilities receiving the most attention in traditional news media.
CVE-2022-23529 |
CRITICAL CVSS 9.80 |
Actively Exploited Remote Code Execution Public Exploits Available |
Published: Dec. 21, 2022 |
node-jsonwebtoken is a JsonWebToken implementation for node.js. For versions `<= 8.5.1` of `jsonwebtoken` library, if a malicious actor has the ability to modify the key retrieval parameter (referring to the `secretOrPublicKey` argument from the readme link of the `jwt.verify()` function, they can write arbitrary files on the host machine. Users are affected only if untrusted entities are allowed to modify the key retrieval parameter of the `jwt.verify()` on a host that you control. This issue has been fixed, please update to version 9.0.0. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-41080 |
CRITICAL CVSS 9.80 |
CISA Known Exploited Used In Ransomware Public Exploits Available |
Published: Nov. 9, 2022 |
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41123. |
Vendor Impacted: Microsoft |
Product Impacted: Exchange Server |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-21674 |
HIGH CVSS 8.80 |
CISA Known Exploited Actively Exploited |
Published: Jan. 10, 2023 |
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability. |
Vendor Impacted: Microsoft |
Product Impacted: Windows |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-21549 |
HIGH CVSS 8.80 |
Risk Context N/A |
Published: Jan. 10, 2023 |
Windows SMB Witness Service Elevation of Privilege Vulnerability. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-21762 |
HIGH CVSS 8.00 |
Risk Context N/A |
Published: Jan. 10, 2023 |
Microsoft Exchange Server Spoofing Vulnerability. This CVE ID is unique from CVE-2023-21745. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-21745 |
HIGH CVSS 8.00 |
Risk Context N/A |
Published: Jan. 10, 2023 |
Microsoft Exchange Server Spoofing Vulnerability. This CVE ID is unique from CVE-2023-21762. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-21764 |
HIGH CVSS 7.80 |
Risk Context N/A |
Published: Jan. 10, 2023 |
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21763. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-21763 |
HIGH CVSS 7.80 |
Risk Context N/A |
Published: Jan. 10, 2023 |
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21764. |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2022-41123 |
HIGH CVSS 7.80 |
Risk Context N/A |
Published: Nov. 9, 2022 |
Microsoft Exchange Server Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41080. |
Vendor Impacted: Microsoft |
Product Impacted: Exchange Server |
Quotes
|
Headlines
|
Back to top ↑ |
CVE-2023-21743 |
MEDIUM CVSS 5.30 |
Actively Exploited |
Published: Jan. 10, 2023 |
Microsoft SharePoint Server Security Feature Bypass Vulnerability. |
Quotes
|
Headlines
|
Back to top ↑ |
Accelerate Security Teams
Schedule a free consultation with a vulnerability expert to discuss your use cases and to see a demo.