These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CVE-2021-36934 is a Microsoft Windows SAM local privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. Because it is listed as known exploited, defenders should treat it as a high-priority patching and exposure-check item, even though the supplied corpus does not include CVSS details or broader technical impact data.
CVE-2020-0796 is a Microsoft SMBv3 remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied KEV record marks it as known to be used in ransomware campaigns, so defenders should treat exposed or unpatched SMBv3 systems as a high-priority risk. The official guidance in the supplied source is to apply updates per vendor instructions.
CVE-2017-8464 is a Microsoft Windows Shell (.lnk) remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. In the supplied corpus, CISA added the entry on 2022-02-10 and set a remediation due date of 2022-08-10. Because the vulnerability is in the KEV catalog, defenders should treat it as actively exploited or otherwise confirmed for real-world abuse and prioriti [truncated]
CVE-2017-0263 is listed by CISA in the Known Exploited Vulnerabilities catalog as a Microsoft Win32k privilege escalation vulnerability. Because it is in KEV, defenders should treat it as a high-priority patching and verification item and follow vendor update guidance as soon as possible.
CVE-2017-0262 is a Microsoft Office remote code execution vulnerability that CISA lists in the Known Exploited Vulnerabilities catalog. That KEV listing means the issue has been identified as known to be exploited, so it should be treated as a high-priority remediation item. CISA’s required action is to apply updates per vendor instructions.
CVE-2017-0145 is listed by CISA in the Known Exploited Vulnerabilities catalog for Microsoft SMBv1 and is marked as having known ransomware campaign use. In the supplied record, CISA added the entry on 2022-02-10 and set a remediation due date of 2022-08-10. Defenders should treat any environment that still relies on SMBv1 as urgent patch-and-mitigate territory and follow vendor guidance to remove or upda [truncated]
CVE-2017-0144 is a Microsoft SMBv1 remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The supplied KEV metadata marks it as known exploited and notes known ransomware campaign use, which makes this a high-priority remediation item for any environment that still depends on SMBv1. CISA added the entry on 2022-02-10 and set a remediation due date of 2022-08-10 [truncated]
CVE-2015-1635 is a Microsoft HTTP.sys remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because CISA flags it as known exploited, defenders should treat remediation as urgent and follow vendor update guidance. The supplied corpus does not include version-specific technical detail, so this debrief stays focused on defensive response rather than exploit mechanics.
CVE-2022-22709 is a Microsoft VP9 Video Extensions vulnerability disclosed on 2022-02-09 and scored 7.8 (High) by NVD. The official records indicate affected versions before 1.0.42791.0 and a user-interaction-dependent code execution impact. Administrators should treat it as a patch-priority issue on systems where the extension is installed, especially endpoints that process untrusted media or content.
CVE-2022-21882 is a Microsoft Win32k privilege escalation vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2022-02-04. Because it is flagged as known exploited, defenders should treat it as urgent and apply vendor updates without delay.
CVE-2020-0787 affects Microsoft Windows Background Intelligent Transfer Service (BITS) and is listed by CISA in the Known Exploited Vulnerabilities catalog. The supplied CISA record also marks it as having known ransomware campaign use, which makes it a defensive priority for patching and verification. Use Microsoft’s update guidance and treat any unpatched Windows host as urgent remediation work.
CVE-2014-1776 is a Microsoft Internet Explorer memory corruption vulnerability that CISA added to the Known Exploited Vulnerabilities catalog on 2022-01-28. The KEV entry directs organizations to apply vendor updates, and CISA’s notes point to Microsoft security bulletin MS14-021 and the NVD record for additional reference. Because CISA lists it as known exploited, this should be treated as a high-priorit [truncated]
CVE-2018-8453 is a Microsoft Win32k privilege escalation vulnerability that CISA has added to its Known Exploited Vulnerabilities catalog. Because CISA lists it as known exploited and notes known ransomware campaign use, it should be treated as a high-priority patching item. The available official guidance is to apply updates per vendor instructions.
CVE-2021-33766 is a Microsoft Exchange Server information disclosure vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is in KEV, defenders should treat it as an urgent remediation item and follow Microsoft’s update guidance without delay.
CVE-2022-21840 is a remote code execution vulnerability in Microsoft Office, published by NVD on 2022-01-11 and last modified on 2026-05-19. The vulnerability carries a CVSS 3.1 score of 8.8 (HIGH severity) with an attack vector of network-based, low complexity, requiring no privileges but user interaction, and can result in high impact to confidentiality, integrity, and availability. Affected products in [truncated]
CVE-2019-1458 is a Microsoft Win32k privilege escalation vulnerability that CISA lists in its Known Exploited Vulnerabilities (KEV) catalog. The KEV listing indicates the issue has been observed as exploited in the wild and should be treated as a high-priority patching item. CISA’s entry also marks it as associated with known ransomware campaign use and directs organizations to apply vendor updates.
CVE-2013-3900 is a Microsoft WinVerifyTrust function remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because CISA marks it as known exploited, organizations should treat remediation as urgent and follow Microsoft’s update guidance without delay.
CVE-2021-43875 is a remote code execution vulnerability in Microsoft Office Graphics, published by Microsoft on December 15, 2021. The vulnerability carries a CVSS 3.1 score of 7.8 (HIGH severity) with an attack vector of local (AV:L), low attack complexity (AC:L), no privileges required (PR:N), and requires user interaction (UI:R). The vulnerability affects multiple Microsoft Office product lines includi [truncated]
A spoofing vulnerability in Microsoft Office Trust Center could allow an attacker to bypass security warnings and present malicious content as trusted. The vulnerability affects multiple Office versions including Microsoft 365 Apps for Enterprise, Office 2013 SP1, Office 2016, Office 2019, and Office LTSC 2021 across both x86 and x64 architectures. Microsoft has released security updates to address this issue.
CVE-2021-42295 is a Visual Basic for Applications (VBA) information disclosure vulnerability affecting multiple Microsoft Office products. Published on December 15, 2021, this vulnerability carries a CVSS 3.1 score of 5.5 (MEDIUM severity) with the vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N. The vulnerability requires local attack vector and user interaction, but can result in high confidentiality impact. [truncated]
Microsoft Jet Red Database Engine and Access Connectivity Engine Elevation of Privilege Vulnerability
CVE-2021-43890 is a Microsoft Windows AppX Installer spoofing vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-12-15. CISA marks it as known exploited and notes known ransomware campaign use, so Windows patching teams should treat remediation as urgent and follow vendor update guidance.
CVE-2021-42321 is a Microsoft Exchange Server remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry marks it as known exploited and notes known ransomware campaign use, so this should be treated as an active risk rather than a routine patch item. The supplied corpus does not include exploit mechanics or affected-version detail, so the safest resp [truncated]
CVE-2021-42292 is a Microsoft Excel security feature bypass affecting Microsoft Office. It was added to CISA’s Known Exploited Vulnerabilities catalog on 2021-11-17, which means defenders should treat it as actively exploited and prioritize remediation. CISA’s listed required action is to apply updates per vendor instructions.
CVE-2021-40449 is a Microsoft Windows Win32k privilege escalation vulnerability that CISA placed in its Known Exploited Vulnerabilities catalog on 2021-11-17. CISA also marked it as having known ransomware campaign use and set a remediation due date of 2021-12-01. The defensive takeaway is straightforward: affected Windows systems should be updated according to Microsoft’s guidance as soon as possible.
A remote code execution vulnerability in Microsoft Word, rated HIGH severity (CVSS 7.8), was disclosed on November 10, 2021. The vulnerability requires local attack vector with user interaction—an attacker must convince a victim to open a maliciously crafted document. Successful exploitation yields high impact across confidentiality, integrity, and availability. Microsoft released patches and security gui [truncated]
CVE-2021-40444 is a Microsoft MSHTML remote code execution vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is listed as actively exploited and marked as known ransomware campaign use, it should be treated as an urgent remediation item. Follow vendor guidance and prioritize affected Microsoft systems immediately.
CVE-2021-38649 is a Microsoft Open Management Infrastructure (OMI) privilege escalation vulnerability that CISA added to its Known Exploited Vulnerabilities catalog on 2021-11-03. Because it is on the KEV list, defenders should treat it as a high-priority remediation item and follow vendor update guidance promptly. The supplied source corpus does not include a CVSS score or deeper technical advisory detai [truncated]
CVE-2021-38648 affects Microsoft Open Management Infrastructure (OMI) and is identified as a privilege escalation vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, which makes it a high-priority item for remediation even though the supplied corpus does not include a CVSS score or deeper technical details.
CVE-2021-38647 is a Microsoft Open Management Infrastructure (OMI) remote code execution vulnerability. CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03 and marked it as having known ransomware campaign use, which makes it an urgent patching priority. CISA’s required action is to apply updates per vendor instructions.