PatchSiren

Microsoft CVE debriefs · Page 70

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Microsoft CVE published 2022-03-03

CVE-2017-11826

CVE-2017-11826 is identified by CISA as a Microsoft Office remote code execution vulnerability and is included in the Known Exploited Vulnerabilities catalog. The KEV entry calls for applying updates per vendor instructions, with a CISA remediation due date of 2022-03-24 in the supplied feed. No exploit details are included in this debrief.

Known exploited Microsoft CVE published 2022-03-03

CVE-2017-0261

CVE-2017-0261 is a Microsoft Office use-after-free vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. That means defenders should treat it as a real-world threat, not just a theoretical flaw. The supplied source corpus only confirms the vulnerability name, vendor/product, and that remediation should follow vendor update guidance.

Known exploited Microsoft CVE published 2022-03-03

CVE-2017-0001

CVE-2017-0001 is a Microsoft Graphics Device Interface (GDI) privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-03, with remediation due by 2022-03-24. Because CISA tracks this CVE as known exploited, it should be treated as a high-priority patching item even though the supplied corpus does not include deeper technical details from a vendor advisor [truncated]

Known exploited Microsoft CVE published 2022-03-03

CVE-2016-7262

CVE-2016-7262 is a Microsoft Excel/Microsoft Office security feature bypass that CISA classifies as known exploited. The supplied corpus does not provide root-cause or affected-version details, so the safest response is to treat it as a high-priority patching item and follow Microsoft’s update guidance immediately.

Known exploited Microsoft CVE published 2022-03-03

CVE-2016-7193

CVE-2016-7193 is a Microsoft Office memory corruption vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-03. Because it is listed in KEV, defenders should treat it as a high-priority patching item and confirm affected Microsoft Office systems are updated according to vendor guidance.

Known exploited Microsoft CVE published 2022-03-03

CVE-2016-0099

CVE-2016-0099 is a Microsoft Windows Secondary Logon Service privilege escalation vulnerability. CISA lists it in the Known Exploited Vulnerabilities catalog, notes known ransomware campaign use, and directs defenders to apply vendor updates promptly.

Known exploited Microsoft CVE published 2022-03-03

CVE-2015-2545

CVE-2015-2545 is a Microsoft Office vulnerability described by CISA as a malformed EPS file issue. CISA added it to the Known Exploited Vulnerabilities catalog, which means it is treated as actively exploited in the wild and should be prioritized for remediation by affected organizations.

Known exploited Microsoft CVE published 2022-03-03

CVE-2015-2424

CVE-2015-2424 is a Microsoft PowerPoint memory corruption vulnerability that appears in CISA’s Known Exploited Vulnerabilities (KEV) catalog. In the supplied corpus, CISA lists the issue as requiring updates per vendor instructions, with the KEV entry dated 2022-03-03 and a remediation due date of 2022-03-24. Because this is a known-exploited item, defenders should treat it as a priority patching and expo [truncated]

Known exploited Microsoft CVE published 2022-03-03

CVE-2015-2387

CVE-2015-2387 is a Microsoft ATM Font Driver privilege escalation vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because CISA marks it as known exploited, organizations should treat remediation as urgent and follow vendor update guidance without delay.

Known exploited Microsoft CVE published 2022-03-03

CVE-2015-1701

CVE-2015-1701 is a Microsoft Win32k privilege escalation vulnerability that CISA has placed in the Known Exploited Vulnerabilities catalog. The supplied CISA record indicates known exploitation and known ransomware campaign use, so this should be treated as a high-priority defensive item. Use the official Microsoft and CISA guidance in the linked records to validate remediation and confirm affected system [truncated]

Known exploited Microsoft CVE published 2022-03-03

CVE-2015-1642

CVE-2015-1642 is a Microsoft Office memory corruption vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. The supplied record shows it was added on 2022-03-03 with a remediation due date of 2022-03-24, which makes timely patching important for any environment that still runs affected Office versions.

Known exploited Microsoft CVE published 2022-03-03

CVE-2014-4114

CVE-2014-4114 is a Microsoft Windows Object Linking & Embedding (OLE) remote code execution vulnerability that CISA lists in the Known Exploited Vulnerabilities catalog. Because it is on the KEV list, defenders should treat it as a priority remediation item and apply Microsoft updates per vendor instructions.

Known exploited Microsoft CVE published 2022-03-03

CVE-2013-5065

CVE-2013-5065 is listed by CISA in the Known Exploited Vulnerabilities catalog as a Microsoft Windows kernel privilege escalation vulnerability. The KEV listing indicates known exploitation and makes this a defensive patching priority. CISA’s stated action is to apply updates per vendor instructions.

Known exploited Microsoft CVE published 2022-03-03

CVE-2013-3897

CVE-2013-3897 is a Microsoft Internet Explorer use-after-free vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. Because CISA identifies it as known exploited, defenders should treat it as a priority patching item and follow Microsoft’s update guidance.

Known exploited Microsoft CVE published 2022-03-03

CVE-2013-1347

CVE-2013-1347 is a Microsoft Internet Explorer remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key point is not the underlying exploit technique, but that this issue has been treated as actively exploited and should be remediated using vendor guidance.

Known exploited Microsoft CVE published 2022-03-03

CVE-2012-1856

CVE-2012-1856 is a Microsoft Office remote code execution vulnerability associated with MSCOMCTL.OCX and included in CISA’s Known Exploited Vulnerabilities catalog. That KEV listing means defenders should treat it as actively exploited and prioritize remediation using Microsoft’s guidance.

Known exploited Microsoft CVE published 2022-03-03

CVE-2011-1889

CVE-2011-1889 is a Microsoft Forefront Threat Management Gateway (TMG) remote code execution vulnerability that CISA has placed in its Known Exploited Vulnerabilities catalog. That KEV designation means CISA has identified it as actively exploited and expects organizations to remediate it promptly using vendor guidance.

Known exploited Microsoft CVE published 2022-03-03

CVE-2010-3333

CISA added CVE-2010-3333 to the Known Exploited Vulnerabilities catalog on 2022-03-03 and set a remediation due date of 2022-03-24. In the supplied corpus, the vulnerability is described as a Microsoft Office stack-based buffer overflow. Because the source set is limited, the safest operational response is to treat this as a prioritized remediation item and verify affected versions and vendor guidance thr [truncated]

Known exploited Microsoft CVE published 2022-03-03

CVE-2010-0232

CVE-2010-0232 is a Microsoft Windows kernel exception handler vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2022-03-03, with a remediation due date of 2022-03-24. Its KEV status means defenders should treat it as a priority patching item and confirm that affected Windows systems are updated according to vendor instructions.

Known exploited Microsoft CVE published 2022-03-03

CVE-2009-3129

CVE-2009-3129 is a Microsoft Excel vulnerability described as a Featheader record memory corruption issue. CISA added it to the Known Exploited Vulnerabilities (KEV) catalog on 2022-03-03, indicating it is treated as actively exploited in the wild. The KEV record sets a remediation due date of 2022-03-24 and directs organizations to apply updates per vendor instructions.

Known exploited Microsoft CVE published 2022-03-03

CVE-2009-1123

CVE-2009-1123 is a Microsoft Windows improper input validation vulnerability that CISA lists in its Known Exploited Vulnerabilities (KEV) catalog. The supplied corpus does not provide a CVSS score or deeper technical detail, but it does confirm that the issue is considered actively exploited enough to require prompt remediation. CISA’s KEV metadata says to apply updates per vendor instructions.

Known exploited Microsoft CVE published 2022-03-03

CVE-2004-0210

CVE-2004-0210 is a Microsoft Windows privilege escalation vulnerability that CISA has included in its Known Exploited Vulnerabilities catalog. The KEV entry indicates organizations should apply updates per vendor instructions and prioritize affected Windows systems, especially where local privilege escalation would materially increase the impact of a compromise.

Known exploited Microsoft CVE published 2022-03-03

CVE-2002-0367

CVE-2002-0367 is a Microsoft Windows privilege escalation vulnerability that CISA included in its Known Exploited Vulnerabilities catalog. The KEV listing means CISA has identified it as being actively or historically exploited in the wild, so it should be treated as a real-world defensive priority even though the corpus does not provide deeper technical detail or a CVSS score.

Known exploited Microsoft CVE published 2022-02-25

CVE-2017-8570

CVE-2017-8570 is a Microsoft Office remote code execution vulnerability that CISA listed in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is not the absence of a CVSS score in the supplied corpus, but the KEV status: CISA’s inclusion indicates known exploitation and a need to prioritize remediation using Microsoft’s update guidance. The source corpus does not provide deeper [truncated]

Known exploited Microsoft CVE published 2022-02-25

CVE-2017-0222

CVE-2017-0222 is a Microsoft Internet Explorer remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. That KEV listing indicates known exploitation and makes this a high-priority remediation item for defenders. The supplied CISA record directs organizations to apply updates per vendor instructions.

Known exploited Microsoft CVE published 2022-02-25

CVE-2014-6352

CVE-2014-6352 is a Microsoft Windows code injection vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. Because CISA identifies it as known exploited, defenders should treat remediation as a priority and apply Microsoft-recommended updates as soon as possible.

Known exploited Microsoft CVE published 2022-02-15

CVE-2019-0752

CVE-2019-0752 is a Microsoft Internet Explorer type confusion vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry marks it as known exploited and notes known ransomware campaign use, so defenders should treat it as a prioritized patching issue.

Known exploited Microsoft CVE published 2022-02-15

CVE-2018-8174

CVE-2018-8174 is a Microsoft Windows VBScript Engine out-of-bounds write vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry also marks it as having known ransomware campaign use. The practical takeaway is straightforward: affected systems should be patched according to Microsoft’s guidance, with priority given to exposed Windows endpoints and systems that may encou [truncated]

Known exploited Microsoft CVE published 2022-02-15

CVE-2014-1761

CVE-2014-1761 is a Microsoft Word memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. For defenders, the key point is not the absence of a CVSS score in the supplied record, but the fact that CISA treats it as actively exploited and directs organizations to apply vendor updates.

Known exploited Microsoft CVE published 2022-02-15

CVE-2013-3906

CVE-2013-3906 is a Microsoft Graphics Component memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. That KEV listing indicates the issue was known to be exploited in the wild, so organizations should treat it as a high-priority remediation item and apply vendor-recommended updates as soon as practical.