PatchSiren

Microsoft CVE debriefs · Page 68

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Microsoft CVE published 2022-04-13

CVE-2022-24521

CVE-2022-24521 is a Microsoft Windows privilege escalation vulnerability affecting the CLFS driver. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-13 and marked it as having known ransomware campaign use. That combination makes it a high-priority patching item for Windows environments, especially where local users or attackers with an initial foothold could attempt to elevate privileges.

Known exploited Microsoft CVE published 2022-04-13

CVE-2015-2502

CVE-2015-2502 is a Microsoft Internet Explorer memory corruption vulnerability that CISA has included in its Known Exploited Vulnerabilities catalog. The supplied sources indicate known exploitation and recommend applying vendor updates. The corpus does not provide exploit mechanics or affected-version detail beyond the Internet Explorer product identification.

Known exploited Microsoft CVE published 2022-04-11

CVE-2021-42287

CVE-2021-42287 is a Microsoft Active Directory Domain Services privilege escalation vulnerability. In the supplied official records, CISA added it to the Known Exploited Vulnerabilities catalog on 2022-04-11, set a remediation due date of 2022-05-02, and marked known ransomware campaign use as Known. The practical takeaway is straightforward: treat this as a high-priority Active Directory patching issue a [truncated]

Known exploited Microsoft CVE published 2022-04-11

CVE-2021-42278

CVE-2021-42278 is a Microsoft Active Directory Domain Services privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-04-11. Because it is listed in KEV and marked as having known ransomware campaign use, defenders should treat it as a high-priority patching item for Active Directory environments.

Known exploited Microsoft CVE published 2022-04-06

CVE-2021-31166

CVE-2021-31166 is a Microsoft HTTP Protocol Stack remote code execution vulnerability that CISA listed in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is prioritization: CISA marked it for remediation with a due date of 2022-04-27, so affected systems should be updated using vendor guidance as soon as possible.

Known exploited Microsoft CVE published 2022-04-06

CVE-2017-0148

CVE-2017-0148 is a Microsoft SMBv1 server remote code execution vulnerability that CISA includes in its Known Exploited Vulnerabilities catalog. The KEV entry indicates known exploitation and notes known ransomware campaign use, so this should be treated as an urgent patching and exposure-reduction item. CISA’s required action is to apply updates per vendor instructions.

Known exploited Microsoft CVE published 2022-03-31

CVE-2021-34484

CVE-2021-34484 is a Microsoft Windows privilege escalation vulnerability involving the User Profile Service. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-31, which means it should be treated as actively exploited or a strong exploitation concern in the wild. The immediate defensive action is to apply Microsoft’s updates per vendor instructions and confirm affected systems are re [truncated]

Known exploited Microsoft CVE published 2022-03-28

CVE-2021-38646

CVE-2021-38646 is a Microsoft Office Access Connectivity Engine remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-28. CISA also marked it as having known ransomware campaign use, which makes it a high-priority patching item for organizations that use Microsoft Office.

Known exploited Microsoft CVE published 2022-03-28

CVE-2021-34486

CVE-2021-34486 is a Microsoft Windows privilege escalation vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is urgency: treat this as a known-exploited issue and apply Microsoft’s guidance and updates as soon as possible across the Windows fleet.

Known exploited Microsoft CVE published 2022-03-28

CVE-2018-8440

CVE-2018-8440 is a Microsoft Windows privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. CISA’s listing indicates known exploitation and known ransomware campaign use, so Windows environments should treat it as an urgent patching priority.

Known exploited Microsoft CVE published 2022-03-28

CVE-2018-8406

CVE-2018-8406 is a Microsoft DirectX Graphics Kernel (DXGKRNL) privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-28. Because it is a KEV entry and is marked as known ransomware campaign use, defenders should treat it as an active-risk issue and prioritize vendor-guided patching.

Known exploited Microsoft CVE published 2022-03-28

CVE-2018-8405

CVE-2018-8405 is a Microsoft DirectX Graphics Kernel (DXGKRNL) privilege escalation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. In the supplied corpus, CISA also marks it as having known ransomware campaign use, which makes this a high-priority remediation item. The practical takeaway is straightforward: follow vendor update guidance and treat this as an active exposure u [truncated]

Known exploited Microsoft CVE published 2022-03-28

CVE-2017-0213

CVE-2017-0213 is a Microsoft Windows privilege escalation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry marks it as known to be used in ransomware campaigns, which makes it a higher-priority patching item than an ordinary non-exploited bulletin. Based on the supplied timeline, CISA added the vulnerability to KEV on 2022-03-28 and set a remediation due date of [truncated]

Known exploited Microsoft CVE published 2022-03-28

CVE-2017-0059

CVE-2017-0059 is a Microsoft Internet Explorer information disclosure vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. The official CISA entry directs organizations to apply updates per vendor instructions. Because it is in KEV, this issue should be treated as a high-priority patching item rather than a routine bulletin.

Known exploited Microsoft CVE published 2022-03-28

CVE-2017-0037

CVE-2017-0037 is a Microsoft Edge and Internet Explorer type confusion vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is tracked as known exploited, organizations should treat it as an active defensive priority and follow Microsoft’s update guidance. The supplied corpus does not include a CVSS score or exploit details, so the safest response is to patch using vend [truncated]

Known exploited Microsoft CVE published 2022-03-28

CVE-2016-7201

CVE-2016-7201 is a Microsoft Edge memory corruption vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-28, with a remediation due date of 2022-04-18. Because it appears in the KEV catalog, defenders should treat it as a priority patching item for systems running affected Microsoft Edge versions.

Known exploited Microsoft CVE published 2022-03-28

CVE-2016-7200

CVE-2016-7200 is a Microsoft Edge memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The presence of this CVE in KEV means defenders should treat it as actively exploited or at least confirmed to have been exploited in the wild. CISA’s required action is to apply updates per vendor instructions, with a due date of 2022-04-18 in the supplied timeline. Public det [truncated]

Known exploited Microsoft CVE published 2022-03-28

CVE-2016-0189

CVE-2016-0189 is a Microsoft Internet Explorer memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. In the supplied official record, CISA marked it as known exploited and set a remediation due date of 2022-04-18, so this should be treated as a high-priority patching item for any environment that still has Internet Explorer exposure.

Known exploited Microsoft CVE published 2022-03-28

CVE-2016-0151

CVE-2016-0151 is a Microsoft Windows Client-Server Run-time Subsystem (CSRSS) security feature bypass vulnerability. CISA has included it in the Known Exploited Vulnerabilities catalog, which means it is treated as an actively exploited issue and is subject to federal remediation timelines. The supplied KEV record also marks it as having known ransomware campaign use. For defenders, the practical takeaway [truncated]

Known exploited Microsoft CVE published 2022-03-28

CVE-2016-0040

CVE-2016-0040 is a Microsoft Windows kernel privilege escalation vulnerability that CISA has listed in its Known Exploited Vulnerabilities (KEV) catalog. KEV inclusion means CISA considers it known to be exploited in the wild, so the practical response is to apply Microsoft updates according to vendor guidance and verify affected systems are brought into compliance.

Known exploited Microsoft CVE published 2022-03-28

CVE-2015-2426

CVE-2015-2426 is a Microsoft Windows Adobe Type Manager Library remote code execution vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog, which means defenders should treat it as an actively exploited issue and prioritize remediation.

Known exploited Microsoft CVE published 2022-03-28

CVE-2015-2419

CVE-2015-2419 is a Microsoft Internet Explorer memory corruption vulnerability that CISA has placed in its Known Exploited Vulnerabilities catalog, which means it was significant enough to warrant active defensive attention. In the supplied timeline, CISA added it on 2022-03-28 and set a remediation due date of 2022-04-18. For defenders, the practical takeaway is simple: treat this as a high-priority patc [truncated]

Known exploited Microsoft CVE published 2022-03-28

CVE-2015-1770

CVE-2015-1770 is a Microsoft Office uninitialized memory use vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. That makes it a defensive priority for patching and validation, even though the supplied corpus does not include deeper technical or impact details. Follow Microsoft’s update guidance and treat affected Office installations as urgent remediation targets.

Known exploited Microsoft CVE published 2022-03-28

CVE-2013-3660

CVE-2013-3660 is a Microsoft Win32k privilege escalation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. That KEV inclusion means the issue has been identified as known to be exploited in the wild, so defenders should treat remediation as urgent and follow vendor guidance for updates.

Known exploited Microsoft CVE published 2022-03-28

CVE-2013-2551

CVE-2013-2551 is a Microsoft Internet Explorer use-after-free vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. CISA added it on 2022-03-28 and set a 2022-04-18 remediation due date, noting known ransomware campaign use.

Known exploited Microsoft CVE published 2022-03-28

CVE-2012-2539

CVE-2012-2539 is a Microsoft Word remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. Because it is listed as known exploited, defenders should treat it as a high-priority patching item and apply Microsoft’s updates per vendor instructions.

Known exploited Microsoft CVE published 2022-03-28

CVE-2011-2005

CVE-2011-2005 is a Microsoft Ancillary Function Driver (afd.sys) vulnerability described as improper input validation and included in CISA’s Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is that CISA has identified this issue as actively exploited enough to require prompt remediation. The supplied source corpus does not include deeper technical detail, so the safest response is [truncated]

Known exploited Microsoft CVE published 2022-03-28

CVE-2010-4398

CVE-2010-4398 is a Microsoft Windows kernel stack-based buffer overflow vulnerability that CISA listed in its Known Exploited Vulnerabilities catalog on 2022-03-28. A KEV listing means CISA has evidence of known exploitation, so this issue should be treated as a high-priority patching item for Windows environments. The source corpus provided here does not include vendor advisory specifics or technical exp [truncated]

Known exploited Microsoft CVE published 2022-03-25

CVE-2022-21999

CVE-2022-21999 is a Microsoft Windows Print Spooler privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-25. Because it is listed in KEV and marked as having known ransomware campaign use, defenders should treat it as a high-priority remediation item, even though the supplied record does not include a CVSS score.

Known exploited Microsoft CVE published 2022-03-25

CVE-2019-0903

CVE-2019-0903 is a Microsoft Graphics Device Interface (GDI) remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because it appears in the KEV catalog, defenders should treat it as actively relevant to patch management and exposure reduction. The supplied CISA entry says to apply updates per vendor instructions.