PatchSiren

Microsoft CVE debriefs · Page 74

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Microsoft CVE published 2021-11-03

CVE-2018-0802

CISA lists CVE-2018-0802 as a Known Exploited Vulnerability affecting Microsoft Office. The provided corpus identifies it as a memory corruption issue and directs defenders to apply updates per vendor instructions. Because the source set does not include affected versions, exploit mechanics, or campaign attribution, defenders should treat this as a high-priority patching item and verify remediation throug [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2018-0798

CVE-2018-0798 is listed by CISA in the Known Exploited Vulnerabilities catalog as a Microsoft Office memory corruption vulnerability. That designation means the issue is treated as actively exploited and should be handled as a high-priority remediation item. The supplied public sources do not include a CVSS score, affected versions, specific component details, or attack mechanics, so this debrief stays at [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2017-8759

CVE-2017-8759 is a Microsoft .NET Framework remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is prioritization: CISA’s KEV entry indicates this issue has been observed as exploited and should be addressed with vendor updates as soon as possible. The supplied corpus does not include exploit mechanics, affected versions, [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2017-7269

CVE-2017-7269 is a Microsoft Internet Information Services (IIS) / Windows Server buffer overflow vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is on the KEV list, defenders should treat it as a high-priority patching issue and verify that vendor-recommended updates have been applied.

Known exploited Microsoft CVE published 2021-11-03

CVE-2017-11882

CVE-2017-11882 is a Microsoft Office memory corruption vulnerability that CISA has placed in its Known Exploited Vulnerabilities catalog, indicating confirmed real-world exploitation. The KEV entry also marks known ransomware campaign use, so defenders should treat this as a high-priority patching and exposure-reduction item for Microsoft Office environments.

Known exploited Microsoft CVE published 2021-11-03

CVE-2017-11774

CVE-2017-11774 is a Microsoft Office Outlook security feature bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is not exploit mechanics but urgency: systems running affected Microsoft Office/Outlook installations should be updated according to Microsoft’s guidance as soon as possible.

Known exploited Microsoft CVE published 2021-11-03

CVE-2017-0199

CVE-2017-0199 is a Microsoft Office and WordPad remote code execution vulnerability that CISA has placed in the Known Exploited Vulnerabilities catalog. CISA also flags it as having known ransomware campaign use, which makes remaining exposure especially important to find and remediate. The defensive takeaway is straightforward: verify whether any affected Microsoft Office or WordPad installations remain [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2017-0143

CVE-2017-0143 is a Microsoft Windows Server Message Block (SMBv1) remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry also marks it as having known ransomware campaign use. For defenders, this is a high-priority patching and exposure-reduction item for any environment that still has SMBv1 enabled or reachable.

Known exploited Microsoft CVE published 2021-11-03

CVE-2016-7255

CVE-2016-7255 is a Microsoft Win32k privilege escalation vulnerability that CISA has included in its Known Exploited Vulnerabilities catalog. That KEV listing means defenders should treat it as an actively exploited issue and prioritize remediation on affected Microsoft systems.

Known exploited Microsoft CVE published 2021-11-03

CVE-2016-3235

CVE-2016-3235 is a Microsoft Office vulnerability described as an OLE DLL side loading issue and listed by CISA in the Known Exploited Vulnerabilities catalog. That KEV listing means it is considered known exploited and should be treated as a patching priority for environments that use Microsoft Office.

Known exploited Microsoft CVE published 2021-11-03

CVE-2016-0185

CVE-2016-0185 is a Microsoft Windows Media Center remote code execution vulnerability. In the supplied records, CISA lists it in the Known Exploited Vulnerabilities (KEV) catalog, which means it is treated as actively exploited and should be prioritized for remediation. The available source corpus does not provide exploit mechanics or a vendor advisory, so defensive handling should focus on patching, expo [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2016-0167

CISA lists CVE-2016-0167 as a known exploited Microsoft Win32k privilege escalation vulnerability and marks it with known ransomware campaign use. The KEV entry directs defenders to apply updates per vendor instructions. Based on the supplied corpus, the safest response is to prioritize remediation using Microsoft’s official guidance and validate exposure against the official CVE and NVD records.

Known exploited Microsoft CVE published 2021-11-03

CVE-2015-1641

CVE-2015-1641 is a Microsoft Office memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is marked as known exploited, defenders should treat it as a patch-priority issue and apply Microsoft-recommended updates as soon as practical.

Known exploited Microsoft CVE published 2021-11-03

CVE-2014-1812

CVE-2014-1812 is a Microsoft Windows Group Policy Preferences password privilege escalation issue that CISA has added to its Known Exploited Vulnerabilities catalog. The KEV entry also marks it as having known ransomware campaign use, which makes this a high-priority item for Windows environments that still rely on Group Policy Preferences. The source corpus does not provide exploit mechanics, but it does [truncated]

Known exploited Microsoft CVE published 2021-11-03

CVE-2012-0158

CVE-2012-0158 is a Microsoft MSCOMCTL.OCX remote code execution vulnerability that CISA lists in the Known Exploited Vulnerabilities catalog. That KEV listing means the issue is confirmed to have been exploited in the wild and should be treated as a high-priority remediation item using vendor guidance.

HIGH Microsoft CVE published 2020-12-10

CVE-2020-17103

CVE-2020-17103 is a Microsoft Windows elevation of privilege vulnerability affecting the Windows Cloud Files Mini Filter Driver. NVD rates it CVSS 3.1 7.0 High with a local attack vector, low privileges required, no user interaction, and high impacts to confidentiality, integrity, and availability. Microsoft’s update guide and advisory are referenced by NVD for remediation guidance.

MEDIUM Microsoft CVE published 2018-02-27

CVE-2005-1794

CVE-2005-1794 is a legacy Microsoft Remote Desktop Protocol (RDP) issue in which RDP 5.2 stored an RSA private key in mstlsapi.dll and used it to sign a certificate. That design flaw could let a remote attacker spoof the public key of a legitimate server and conduct man-in-the-middle interception of RDP sessions. The issue is historical, but it remains relevant anywhere older Terminal Services or RDP 5.2 [truncated]

HIGH Microsoft CVE published 2017-03-03

CVE-2017-2290

CVE-2017-2290 is a privilege-escalation issue in Puppet's mcollective-puppet-agent on Windows. In version 1.12.0, a non-administrator user can place an executable that is later run with administrator privileges when "mco puppet" is executed. The issue is fixed in mcollective-puppet-agent 1.12.1, and Puppet Enterprise users are stated to be unaffected.

MEDIUM Microsoft CVE published 2017-02-20

CVE-2017-0038

CVE-2017-0038 is a Microsoft Windows information disclosure issue in gdi32.dll/GDI. A crafted EMF file can expose process heap memory when the EMR_SETDIBITSTODEVICE record uses modified Device Independent Bitmap dimensions. The CVE record notes that this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220. The official CVE was published on 2017-02-20; t [truncated]

HIGH Microsoft CVE published 2017-02-15

CVE-2017-0324

CVE-2017-0324 is a high-severity memory-safety issue in NVIDIA's Windows GPU Display Driver kernel component (nvlddmkm.sys). The flaw stems from missing validation of an input buffer size in the DxgkDdiEscape handler, which can lead to a crash and may allow privilege escalation on affected systems.

HIGH Microsoft CVE published 2017-02-15

CVE-2017-0323

CVE-2017-0323 is a high-severity vulnerability in NVIDIA Windows GPU Display Driver kernel-mode handling. According to the CVE record and NVIDIA’s advisory reference, invalid user input may trigger a NULL pointer dereference, which can result in denial of service and may also create conditions for privilege escalation on affected systems.

HIGH Microsoft CVE published 2017-02-15

CVE-2017-0322

CVE-2017-0322 affects NVIDIA Windows GPU Display Driver versions described by NVD as vulnerable across the gpu_driver product line. The issue is in the kernel-mode layer (nvlddmkm.sys) handler, where a user-controlled value is not correctly validated before being used as an array index. NVD rates the weakness as CVE-3.0 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and maps it to CWE-129 (improper validation of arr [truncated]

MEDIUM Microsoft CVE published 2017-02-15

CVE-2017-0320

CVE-2017-0320 is a medium-severity denial-of-service issue in NVIDIA Windows GPU Display Driver. NVD states that the vulnerability is in a kernel mode layer handler and that improper handling of values may cause a system denial of service. The published CVSS vector indicates local access, low privileges, and no user interaction, with high availability impact.

MEDIUM Microsoft CVE published 2017-02-15

CVE-2017-0319

CVE-2017-0319 is a medium-severity denial-of-service issue in the NVIDIA Windows GPU Display Driver. NVD describes improper handling of values in a kernel-mode layer handler that may crash or otherwise disrupt the system. The published CVSS vector indicates local access, low privileges, no user interaction, and high availability impact.

HIGH Microsoft CVE published 2017-02-15

CVE-2017-0317

CVE-2017-0317 is a local privilege-escalation issue in NVIDIA GPU and GeForce Experience installer workflows. The installer fails to set proper permissions on the package extraction path, which can let a non-privileged user modify extracted files and potentially influence what code is executed during installation. NVD rates the issue 7.5 HIGH, with local attack requirements and a changed scope impact.

HIGH Microsoft CVE published 2017-02-15

CVE-2017-0315

CVE-2017-0315 affects NVIDIA Windows GPU Display Driver components in kernel mode. The issue is in the nvlddmkm.sys handler for DxgkDdiEscape, where an attempt to access an invalid object pointer may trigger a crash or potentially allow escalation of privileges. NVD rates the issue 7.8 High with a local, low-privilege attack path and no user interaction.

HIGH Microsoft CVE published 2017-02-15

CVE-2017-0314

CVE-2017-0314 is a high-severity vulnerability in the NVIDIA Windows GPU Display Driver kernel-mode layer. According to NVD and the referenced NVIDIA advisory, untrusted input in DxgkDdiSubmitCommandVirtual can reference memory outside the intended buffer boundary, creating a path to denial of service or privilege escalation.

HIGH Microsoft CVE published 2017-02-15

CVE-2017-0313

CVE-2017-0313 affects NVIDIA Windows GPU Display Driver kernel-mode code in nvlddmkm.sys. The issue is in the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual), where untrusted input can be used to reference memory outside the intended buffer boundary. NVD classifies the weakness as CWE-119 and rates the issue HIGH with a CVSS v3.0 score of 7.8. The practical impact is local: an attacker with limited [truncated]

HIGH Microsoft CVE published 2017-02-15

CVE-2017-0312

CVE-2017-0312 affects the NVIDIA Windows GPU Display Driver in the kernel-mode component nvlddmkm.sys. NVD describes a flaw in the DxgkDdiEscapeID 0x100008b handler where user-supplied input is used as a loop limit, creating a path to denial of service or potential privilege escalation. The issue is rated HIGH in NVD with a local attack vector and no user interaction required.

HIGH Microsoft CVE published 2017-02-15

CVE-2017-0308

CVE-2017-0308 is a high-severity vulnerability in NVIDIA's Windows GPU Display Driver kernel-mode component. According to NVD, untrusted input is used in a buffer size calculation in the nvlddmkm.sys DxgkDdiEscape handler, which can result in denial of service or escalation of privileges. The issue is local, requires low privileges, and is classified by NVD as CWE-119. From a defensive perspective, this i [truncated]