These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
CISA lists CVE-2018-0802 as a Known Exploited Vulnerability affecting Microsoft Office. The provided corpus identifies it as a memory corruption issue and directs defenders to apply updates per vendor instructions. Because the source set does not include affected versions, exploit mechanics, or campaign attribution, defenders should treat this as a high-priority patching item and verify remediation throug [truncated]
CVE-2018-0798 is listed by CISA in the Known Exploited Vulnerabilities catalog as a Microsoft Office memory corruption vulnerability. That designation means the issue is treated as actively exploited and should be handled as a high-priority remediation item. The supplied public sources do not include a CVSS score, affected versions, specific component details, or attack mechanics, so this debrief stays at [truncated]
CVE-2017-8759 is a Microsoft .NET Framework remote code execution vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is prioritization: CISA’s KEV entry indicates this issue has been observed as exploited and should be addressed with vendor updates as soon as possible. The supplied corpus does not include exploit mechanics, affected versions, [truncated]
CVE-2017-7269 is a Microsoft Internet Information Services (IIS) / Windows Server buffer overflow vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is on the KEV list, defenders should treat it as a high-priority patching issue and verify that vendor-recommended updates have been applied.
CVE-2017-11882 is a Microsoft Office memory corruption vulnerability that CISA has placed in its Known Exploited Vulnerabilities catalog, indicating confirmed real-world exploitation. The KEV entry also marks known ransomware campaign use, so defenders should treat this as a high-priority patching and exposure-reduction item for Microsoft Office environments.
CVE-2017-11774 is a Microsoft Office Outlook security feature bypass vulnerability that CISA added to its Known Exploited Vulnerabilities catalog. For defenders, the key takeaway is not exploit mechanics but urgency: systems running affected Microsoft Office/Outlook installations should be updated according to Microsoft’s guidance as soon as possible.
CVE-2017-0199 is a Microsoft Office and WordPad remote code execution vulnerability that CISA has placed in the Known Exploited Vulnerabilities catalog. CISA also flags it as having known ransomware campaign use, which makes remaining exposure especially important to find and remediate. The defensive takeaway is straightforward: verify whether any affected Microsoft Office or WordPad installations remain [truncated]
CVE-2017-0143 is a Microsoft Windows Server Message Block (SMBv1) remote code execution vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. The KEV entry also marks it as having known ransomware campaign use. For defenders, this is a high-priority patching and exposure-reduction item for any environment that still has SMBv1 enabled or reachable.
CVE-2016-7255 is a Microsoft Win32k privilege escalation vulnerability that CISA has included in its Known Exploited Vulnerabilities catalog. That KEV listing means defenders should treat it as an actively exploited issue and prioritize remediation on affected Microsoft systems.
CVE-2016-3235 is a Microsoft Office vulnerability described as an OLE DLL side loading issue and listed by CISA in the Known Exploited Vulnerabilities catalog. That KEV listing means it is considered known exploited and should be treated as a patching priority for environments that use Microsoft Office.
CVE-2016-0185 is a Microsoft Windows Media Center remote code execution vulnerability. In the supplied records, CISA lists it in the Known Exploited Vulnerabilities (KEV) catalog, which means it is treated as actively exploited and should be prioritized for remediation. The available source corpus does not provide exploit mechanics or a vendor advisory, so defensive handling should focus on patching, expo [truncated]
CISA lists CVE-2016-0167 as a known exploited Microsoft Win32k privilege escalation vulnerability and marks it with known ransomware campaign use. The KEV entry directs defenders to apply updates per vendor instructions. Based on the supplied corpus, the safest response is to prioritize remediation using Microsoft’s official guidance and validate exposure against the official CVE and NVD records.
CVE-2015-1641 is a Microsoft Office memory corruption vulnerability that CISA lists in its Known Exploited Vulnerabilities catalog. Because it is marked as known exploited, defenders should treat it as a patch-priority issue and apply Microsoft-recommended updates as soon as practical.
CVE-2014-1812 is a Microsoft Windows Group Policy Preferences password privilege escalation issue that CISA has added to its Known Exploited Vulnerabilities catalog. The KEV entry also marks it as having known ransomware campaign use, which makes this a high-priority item for Windows environments that still rely on Group Policy Preferences. The source corpus does not provide exploit mechanics, but it does [truncated]
CVE-2012-0158 is a Microsoft MSCOMCTL.OCX remote code execution vulnerability that CISA lists in the Known Exploited Vulnerabilities catalog. That KEV listing means the issue is confirmed to have been exploited in the wild and should be treated as a high-priority remediation item using vendor guidance.
CVE-2020-17103 is a Microsoft Windows elevation of privilege vulnerability affecting the Windows Cloud Files Mini Filter Driver. NVD rates it CVSS 3.1 7.0 High with a local attack vector, low privileges required, no user interaction, and high impacts to confidentiality, integrity, and availability. Microsoft’s update guide and advisory are referenced by NVD for remediation guidance.
CVE-2005-1794 is a legacy Microsoft Remote Desktop Protocol (RDP) issue in which RDP 5.2 stored an RSA private key in mstlsapi.dll and used it to sign a certificate. That design flaw could let a remote attacker spoof the public key of a legitimate server and conduct man-in-the-middle interception of RDP sessions. The issue is historical, but it remains relevant anywhere older Terminal Services or RDP 5.2 [truncated]
CVE-2017-2290 is a privilege-escalation issue in Puppet's mcollective-puppet-agent on Windows. In version 1.12.0, a non-administrator user can place an executable that is later run with administrator privileges when "mco puppet" is executed. The issue is fixed in mcollective-puppet-agent 1.12.1, and Puppet Enterprise users are stated to be unaffected.
CVE-2017-0038 is a Microsoft Windows information disclosure issue in gdi32.dll/GDI. A crafted EMF file can expose process heap memory when the EMR_SETDIBITSTODEVICE record uses modified Device Independent Bitmap dimensions. The CVE record notes that this vulnerability exists because of an incomplete fix for CVE-2016-3216, CVE-2016-3219, and/or CVE-2016-3220. The official CVE was published on 2017-02-20; t [truncated]
CVE-2017-0324 is a high-severity memory-safety issue in NVIDIA's Windows GPU Display Driver kernel component (nvlddmkm.sys). The flaw stems from missing validation of an input buffer size in the DxgkDdiEscape handler, which can lead to a crash and may allow privilege escalation on affected systems.
CVE-2017-0323 is a high-severity vulnerability in NVIDIA Windows GPU Display Driver kernel-mode handling. According to the CVE record and NVIDIA’s advisory reference, invalid user input may trigger a NULL pointer dereference, which can result in denial of service and may also create conditions for privilege escalation on affected systems.
CVE-2017-0322 affects NVIDIA Windows GPU Display Driver versions described by NVD as vulnerable across the gpu_driver product line. The issue is in the kernel-mode layer (nvlddmkm.sys) handler, where a user-controlled value is not correctly validated before being used as an array index. NVD rates the weakness as CVE-3.0 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H and maps it to CWE-129 (improper validation of arr [truncated]
CVE-2017-0320 is a medium-severity denial-of-service issue in NVIDIA Windows GPU Display Driver. NVD states that the vulnerability is in a kernel mode layer handler and that improper handling of values may cause a system denial of service. The published CVSS vector indicates local access, low privileges, and no user interaction, with high availability impact.
CVE-2017-0319 is a medium-severity denial-of-service issue in the NVIDIA Windows GPU Display Driver. NVD describes improper handling of values in a kernel-mode layer handler that may crash or otherwise disrupt the system. The published CVSS vector indicates local access, low privileges, no user interaction, and high availability impact.
CVE-2017-0317 is a local privilege-escalation issue in NVIDIA GPU and GeForce Experience installer workflows. The installer fails to set proper permissions on the package extraction path, which can let a non-privileged user modify extracted files and potentially influence what code is executed during installation. NVD rates the issue 7.5 HIGH, with local attack requirements and a changed scope impact.
CVE-2017-0315 affects NVIDIA Windows GPU Display Driver components in kernel mode. The issue is in the nvlddmkm.sys handler for DxgkDdiEscape, where an attempt to access an invalid object pointer may trigger a crash or potentially allow escalation of privileges. NVD rates the issue 7.8 High with a local, low-privilege attack path and no user interaction.
CVE-2017-0314 is a high-severity vulnerability in the NVIDIA Windows GPU Display Driver kernel-mode layer. According to NVD and the referenced NVIDIA advisory, untrusted input in DxgkDdiSubmitCommandVirtual can reference memory outside the intended buffer boundary, creating a path to denial of service or privilege escalation.
CVE-2017-0313 affects NVIDIA Windows GPU Display Driver kernel-mode code in nvlddmkm.sys. The issue is in the SubmitCommandVirtual DDI (DxgkDdiSubmitCommandVirtual), where untrusted input can be used to reference memory outside the intended buffer boundary. NVD classifies the weakness as CWE-119 and rates the issue HIGH with a CVSS v3.0 score of 7.8. The practical impact is local: an attacker with limited [truncated]
CVE-2017-0312 affects the NVIDIA Windows GPU Display Driver in the kernel-mode component nvlddmkm.sys. NVD describes a flaw in the DxgkDdiEscapeID 0x100008b handler where user-supplied input is used as a loop limit, creating a path to denial of service or potential privilege escalation. The issue is rated HIGH in NVD with a local attack vector and no user interaction required.
CVE-2017-0308 is a high-severity vulnerability in NVIDIA's Windows GPU Display Driver kernel-mode component. According to NVD, untrusted input is used in a buffer size calculation in the nvlddmkm.sys DxgkDdiEscape handler, which can result in denial of service or escalation of privileges. The issue is local, requires low privileges, and is classified by NVD as CWE-119. From a defensive perspective, this i [truncated]