漏洞快報
正在遭實際利用的漏洞(CISA KEV)依最新排序。每個 CVE 均附上利用機率(EPSS)與嚴重程度(CVSS),從防禦視角協助你判斷「是否需要立即修復」的資訊流。
A security vulnerability in MICS Admin Portal in Ivanti MobileIron Sentry versions 9.18.0 and below, which may allow an attacker to bypass authentication controls on the administrative interface due to an insufficiently restrictive Apache HTTPD configuration.
KEV 收錄: 2023-08-22官方(NVD) →Vulnerability in Veeam Backup & Replication component allows encrypted credentials stored in the configuration database to be obtained. This may lead to gaining access to the backup infrastructure hosts.
KEV 收錄: 2023-08-22官方(NVD) →Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
KEV 收錄: 2023-08-21官方(NVD) →A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
KEV 收錄: 2023-08-16官方(NVD) →.NET and Visual Studio Denial of Service Vulnerability
KEV 收錄: 2023-08-09官方(NVD) →The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command injection vulnerability in the Remote System Log forwarding function, which is accessible by an unauthenticated user. The vulnerability is in the ViewLog.asp page and can be exploited through the remote_host parameter.
KEV 收錄: 2023-08-07官方(NVD) →A path traversal vulnerability in Ivanti EPMM versions (11.10.x < 11.10.0.3, 11.9.x < 11.9.1.2 and 11.8.x < 11.8.1.2) allows an authenticated administrator to write arbitrary files onto the appliance.
KEV 收錄: 2023-07-31官方(NVD) →Zimbra Collaboration (ZCS) 8 before 8.8.15 Patch 41 allows XSS in the Zimbra Classic Web Client.
KEV 收錄: 2023-07-27官方(NVD) →This issue was addressed with improved state management. This issue is fixed in macOS Monterey 12.6.8, iOS 15.7.8 and iPadOS 15.7.8, iOS 16.6 and iPadOS 16.6, tvOS 16.6, macOS Big Sur 11.7.9, macOS Ventura 13.5, watchOS 9.6. An app may be able to modify sensitive kernel state. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.1.
KEV 收錄: 2023-07-26官方(NVD) →An authentication bypass vulnerability in Ivanti EPMM allows unauthorized users to access restricted functionality or resources of the application without proper authentication.
KEV 收錄: 2023-07-25官方(NVD) →Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
KEV 收錄: 2023-07-20官方(NVD) →Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.
KEV 收錄: 2023-07-20官方(NVD) →Unauthenticated remote code execution
KEV 收錄: 2023-07-19官方(NVD) →Windows Search Remote Code Execution Vulnerability
KEV 收錄: 2023-07-17官方(NVD) →SolarView Compact ver.6.00 was discovered to contain a command injection vulnerability via conf_mail.php.
KEV 收錄: 2023-07-13官方(NVD) →The issue was addressed with improved checks. This issue is fixed in iOS 16.6 and iPadOS 16.6, Safari 16.5.2, tvOS 16.6, macOS Ventura 13.5, watchOS 9.6. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
KEV 收錄: 2023-07-13官方(NVD) →Remote code execution vulnerabilities exist in the Netwrix Auditor User Activity Video Recording component affecting both the Netwrix Auditor server and agents installed on monitored systems. The remote code execution vulnerabilities exist within the underlying protocol used by the component, and potentially allow an unauthenticated remote attacker to execute arbitrary code as the NT AUTHORITY\SYSTEM user on affected systems, including on systems Netwrix Auditor monitors.
KEV 收錄: 2023-07-11官方(NVD) →Windows Error Reporting Service Elevation of Privilege Vulnerability
KEV 收錄: 2023-07-11官方(NVD) →Microsoft Outlook Security Feature Bypass Vulnerability
KEV 收錄: 2023-07-11官方(NVD) →Windows SmartScreen Security Feature Bypass Vulnerability
KEV 收錄: 2023-07-11官方(NVD) →Windows MSHTML Platform Elevation of Privilege Vulnerability
KEV 收錄: 2023-07-11官方(NVD) →. The Arm Mali GPU kernel driver allows an unprivileged user to achieve access to freed memory, leading to information disclosure or root privilege escalation. This affects Bifrost r16p0 through r29p0 before r30p0, Valhall r19p0 through r29p0 before r30p0, and Midgard r28p0 through r30p0.
KEV 收錄: 2023-07-07官方(NVD) →The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
KEV 收錄: 2023-06-29官方(NVD) →D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Save Configuration functionality in the Web interface, using shell metacharacters in the admin.cgi?action=config_save configBackup or downloadServerip parameter.
KEV 收錄: 2023-06-29官方(NVD) →Lack of boundary checking of a buffer in set_skb_priv() of modem interface driver prior to SMR Oct-2021 Release 1 allows OOB read and it results in arbitrary code execution by dereference of invalid function pointer.
KEV 收錄: 2023-06-29官方(NVD) →A vulnerability in DSP driver prior to SMR Mar-2021 Release 1 allows attackers load arbitrary ELF libraries inside DSP.
KEV 收錄: 2023-06-29官方(NVD) →An improper boundary check in DSP driver prior to SMR Mar-2021 Release 1 allows out of bounds memory access.
KEV 收錄: 2023-06-29官方(NVD) →A race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows local attackers to bypass signature check given a radio privilege is compromised.
KEV 收錄: 2023-06-29官方(NVD) →A use after free vulnerability via race condition in MFC charger driver prior to SMR MAY-2021 Release 1 allows arbitrary write given a radio privilege is compromised.
KEV 收錄: 2023-06-29官方(NVD) →Assuming radio permission is gained, missing input validation in modem interface driver prior to SMR Oct-2021 Release 1 results in format string bug leading to kernel panic.
KEV 收錄: 2023-06-29官方(NVD) →The pre-authentication command injection vulnerability in the Zyxel NAS326 firmware versions prior to V5.21(AAZF.14)C0, NAS540 firmware versions prior to V5.21(AATB.11)C0, and NAS542 firmware versions prior to V5.21(ABAG.11)C0 could allow an unauthenticated attacker to execute some operating system (OS) commands remotely by sending a crafted HTTP request.
KEV 收錄: 2023-06-23官方(NVD) →An integer overflow was addressed with improved input validation. This issue is fixed in watchOS 9.5.2, macOS Big Sur 11.7.8, iOS 15.7.7 and iPadOS 15.7.7, macOS Monterey 12.6.7, watchOS 8.8.1, iOS 16.5.1 and iPadOS 16.5.1, macOS Ventura 13.4.1. An app may be able to execute arbitrary code with kernel privileges. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
KEV 收錄: 2023-06-23官方(NVD) →A type confusion issue was addressed with improved checks. This issue is fixed in iOS 16.5.1 and iPadOS 16.5.1, iOS 15.7.7 and iPadOS 15.7.7, macOS Ventura 13.4.1, Safari 16.5.1. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited.
KEV 收錄: 2023-06-23官方(NVD) →A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.7 and iPadOS 15.7.7. Processing web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited against versions of iOS released before iOS 15.7.
KEV 收錄: 2023-06-23官方(NVD) →A fully compromised ESXi host can force VMware Tools to fail to authenticate host-to-guest operations, impacting the confidentiality and integrity of the guest virtual machine.
KEV 收錄: 2023-06-23官方(NVD) →Aria Operations for Networks contains a command injection vulnerability. A malicious actor with network access to VMware Aria Operations for Networks may be able to perform a command injection attack resulting in remote code execution.
KEV 收錄: 2023-06-22官方(NVD) →rcube_image.php in Roundcube Webmail before 1.4.4 allows attackers to execute arbitrary code via shell metacharacters in a configuration setting for im_convert_path or im_identify_path.
KEV 收錄: 2023-06-22官方(NVD) →A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been discovered in the wild targeting Firefox and Tor Browser users on Windows. This vulnerability affects Firefox < 50.0.2, Firefox ESR < 45.5.1, and Thunderbird < 45.5.1.
KEV 收錄: 2023-06-22官方(NVD) →Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
KEV 收錄: 2023-06-22官方(NVD) →An XSS issue was discovered in Roundcube Webmail before 1.2.13, 1.3.x before 1.3.16, and 1.4.x before 1.4.10. The attacker can send a plain text e-mail message, with JavaScript in a link reference element that is mishandled by linkref_addindex in rcube_string_replacer.php.
KEV 收錄: 2023-06-22官方(NVD) →
優先順序 = KEV(正在遭實際利用) + EPSS(30 天內遭利用的機率) + CVSS(嚴重程度) 的綜合。本資訊流以防禦為目的,不涉及攻擊程式碼或 PoC。各 CVE 的詳情連結至官方來源(NVD)。