Authoritative signal

Known exploited

The current CISA KEV catalog, bound to the active generation and ordered by catalog date and CASCA priority.

As known Jul 19, 2026, 5:00 AM UTCgen-56ccdaf9
KEV JSON is authoritativeCatalog absence remains unknown; CSV is serialization-only and never an independent vote.1,647 catalog members · showing 451500
451

ScienceLogic SL1 Unspecified Vulnerability

ScienceLogic SL1 (formerly EM7) is affected by an unspecified vulnerability involving an unspecified third-party component.

ScienceLogicSL1

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-21
Due
2024-11-11
Priority interval
67.283.4
Coverage
85%
452
CVE-2024-40711CISA KEVKnown ransomware

Veeam Backup and Replication Deserialization Vulnerability

Veeam Backup and Replication contains a deserialization vulnerability allowing an unauthenticated user to perform remote code execution.

VeeamBackup & Replication

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-17
Due
2024-11-07
Priority interval
83.598.5
Coverage
85%
453

SolarWinds Web Help Desk Hardcoded Credential Vulnerability

SolarWinds Web Help Desk contains a hardcoded credential vulnerability that could allow a remote, unauthenticated user to access internal functionality and modify data.

SolarWindsWeb Help Desk

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-15
Due
2024-11-05
Priority interval
82.197.1
Coverage
85%
454
CVE-2024-9680CISA KEVKnown ransomware

Mozilla Firefox Use-After-Free Vulnerability

Mozilla Firefox and Firefox ESR contain a use-after-free vulnerability in Animation timelines that allows for code execution in the content process.

MozillaFirefox

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-15
Due
2024-11-05
Priority interval
74.189.1
Coverage
85%
455
CVE-2024-30088CISA KEVKnown ransomware

Microsoft Windows Kernel TOCTOU Race Condition Vulnerability

Microsoft Windows Kernel contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that could allow for privilege escalation.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-15
Due
2024-11-05
Priority interval
74.089.0
Coverage
85%
456

Fortinet Multiple Products Format String Vulnerability

Fortinet FortiOS, FortiPAM, FortiProxy, and FortiWeb contain a format string vulnerability that allows a remote, unauthenticated attacker to execute arbitrary code or commands via specially crafted requests.

FortinetMultiple Products

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-09
Due
2024-10-30
Priority interval
80.295.2
Coverage
85%
457

Ivanti Cloud Services Appliance (CSA) OS Command Injection Vulnerability

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

IvantiCloud Services Appliance (CSA)

Required actionAs Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

Added
2024-10-09
Due
2024-10-30
Priority interval
73.888.8
Coverage
85%
458
CVE-2024-9379CISA KEVConflicting evidence

Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability

Ivanti Cloud Services Appliance (CSA) contains a SQL injection vulnerability in the admin web console in versions prior to 5.0.2, which can allow a remote attacker authenticated as administrator to run arbitrary SQL statements.

IvantiCloud Services Appliance (CSA)

Required actionAs Ivanti CSA 4.6.x has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line, or later, of supported solution.

Added
2024-10-09
Due
2024-10-30
Priority interval
69.486.2
Coverage
73%
459

Microsoft Windows Management Console Remote Code Execution Vulnerability

Microsoft Windows Management Console contains unspecified vulnerability that allows for remote code execution.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-08
Due
2024-10-29
Priority interval
75.890.8
Coverage
85%
460
CVE-2024-43573CISA KEVConflicting evidence

Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains an unspecified spoofing vulnerability which can lead to a loss of confidentiality.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-08
Due
2024-10-29
Priority interval
69.588.5
Coverage
73%
461

Qualcomm Multiple Chipsets Use-After-Free Vulnerability

Multiple Qualcomm chipsets contain a use-after-free vulnerability due to memory corruption in DSP Services while maintaining memory maps of HLOS memory.

QualcommMultiple Chipsets

Required actionApply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.

Added
2024-10-08
Due
2024-10-29
Priority interval
61.176.1
Coverage
85%
462

Synacor Zimbra Collaboration Suite (ZCS) Command Execution Vulnerability

Synacor Zimbra Collaboration Suite (ZCS) contains an unspecified vulnerability in the postjournal service that may allow an unauthenticated user to execute commands.

SynacorZimbra Collaboration Suite (ZCS)

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-03
Due
2024-10-24
Priority interval
84.5100.0
Coverage
85%
463
CVE-2024-29824CISA KEVConflicting evidence

Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability

Ivanti Endpoint Manager (EPM) contains a SQL injection vulnerability in Core server that allows an unauthenticated attacker within the same network to execute arbitrary code.

IvantiEndpoint Manager (EPM)

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-10-02
Due
2024-10-23
Priority interval
82.099.0
Coverage
73%
464

D-Link DIR-820 Router OS Command Injection Vulnerability

D-Link DIR-820 routers contain an OS command injection vulnerability that allows a remote, unauthenticated attacker to escalate privileges to root via a crafted payload with the ping_addr parameter to ping.ccp.

D-LinkDIR-820 Router

Required actionThe impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Added
2024-09-30
Due
2024-10-21
Priority interval
84.399.3
Coverage
85%
465
CVE-2020-15415CISA KEVConflicting evidence

DrayTek Multiple Vigor Routers OS Command Injection Vulnerability

DrayTek Vigor3900, Vigor2960, and Vigor300B devices contain an OS command injection vulnerability in cgi-bin/mainfunction.cgi/cvmcfgupload that allows for remote code execution via shell metacharacters in a filename when the text/x-python-script content type is used.

DrayTekMultiple Vigor Routers

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-30
Due
2024-10-21
Priority interval
77.197.9
Coverage
73%
466
CVE-2019-0344CISA KEVConflicting evidence

SAP Commerce Cloud Deserialization of Untrusted Data Vulnerability

SAP Commerce Cloud (formerly known as Hybris) contains a deserialization of untrusted data vulnerability within the mediaconversion and virtualjdbc extension that allows for code injection.

SAPCommerce Cloud

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-30
Due
2024-10-21
Priority interval
64.184.8
Coverage
73%
467

Ivanti Virtual Traffic Manager Authentication Bypass Vulnerability

Ivanti Virtual Traffic Manager contains an authentication bypass vulnerability that allows a remote, unauthenticated attacker to create a chosen administrator account.

IvantiVirtual Traffic Manager

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-24
Due
2024-10-15
Priority interval
84.599.5
Coverage
85%
468

Ivanti Cloud Services Appliance (CSA) Path Traversal Vulnerability

Ivanti Cloud Services Appliance (CSA) contains a path traversal vulnerability that could allow a remote, unauthenticated attacker to access restricted functionality. If CVE-2024-8963 is used in conjunction with CVE-2024-8190, an attacker could bypass admin authentication and execute arbitrary commands on the appliance.

IvantiCloud Services Appliance (CSA)

Required actionAs Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive security updates.

Added
2024-09-19
Due
2024-10-10
Priority interval
82.698.4
Coverage
85%
469

Apache HugeGraph-Server Improper Access Control Vulnerability

Apache HugeGraph-Server contains an improper access control vulnerability that could allow a remote attacker to execute arbitrary code.

ApacheHugeGraph-Server

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-18
Due
2024-10-09
Priority interval
84.499.4
Coverage
85%
470
CVE-2020-0618CISA KEVConflicting evidence

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability

Microsoft SQL Server Reporting Services contains a deserialization vulnerability when handling page requests incorrectly. An authenticated attacker can exploit this vulnerability to execute code in the context of the Report Server service account.

MicrosoftSQL Server

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-18
Due
2024-10-09
Priority interval
76.299.4
Coverage
73%
471
CVE-2020-14644CISA KEVConflicting evidence

Oracle WebLogic Server Remote Code Execution Vulnerability

Oracle WebLogic Server, a product within the Fusion Middleware suite, contains a deserialization vulnerability. Unauthenticated attackers with network access via T3 or IIOP can exploit this vulnerability to achieve remote code execution.

OracleWebLogic Server

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-18
Due
2024-10-09
Priority interval
78.298.9
Coverage
73%
472
CVE-2022-21445CISA KEVConflicting evidence

Oracle ADF Faces Deserialization of Untrusted Data Vulnerability

Oracle ADF Faces library, included with Oracle JDeveloper Distribution, contains a deserialization of untrusted data vulnerability leading to unauthenticated remote code execution.

OracleADF Faces

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-18
Due
2024-10-09
Priority interval
74.695.3
Coverage
73%
473
CVE-2014-0497CISA KEVConflicting evidence

Adobe Flash Player Integer Underflow Vulnerablity

Adobe Flash Player contains an integer underflow vulnerability that allows a remote attacker to execute arbitrary code.

AdobeFlash Player

Required actionThe impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Added
2024-09-17
Due
2024-10-08
Priority interval
82.0100.0
Coverage
73%
474
CVE-2014-0502CISA KEVConflicting evidence

Adobe Flash Player Double Free Vulnerablity

Adobe Flash Player contains a double free vulnerability that allows a remote attacker to execute arbitrary code.

AdobeFlash Player

Required actionThe impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Added
2024-09-17
Due
2024-10-08
Priority interval
71.889.8
Coverage
73%
475

Adobe Flash Player Code Execution Vulnerability

Adobe Flash Player contains an unspecified vulnerability in the ExternalInterface ActionScript functionality that allows a remote attacker to execute arbitrary code via crafted SWF content.

AdobeFlash Player

Required actionThe impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Added
2024-09-17
Due
2024-10-08
Priority interval
68.784.9
Coverage
85%
476

Adobe Flash Player Incorrect Default Permissions Vulnerability

Adobe Flash Player contains an incorrect default permissions vulnerability in the Firefox sandbox that allows a remote attacker to execute arbitrary code via crafted SWF content.

AdobeFlash Player

Required actionThe impacted product is end-of-life (EoL) and/or end-of-service (EoS). Users should discontinue utilization of the product.

Added
2024-09-17
Due
2024-10-08
Priority interval
68.584.7
Coverage
85%
477
CVE-2024-6670CISA KEVKnown ransomware

Progress WhatsUp Gold SQL Injection Vulnerability

Progress WhatsUp Gold contains a SQL injection vulnerability that allows an unauthenticated attacker to retrieve the user's encrypted password if the application is configured with only a single user.

ProgressWhatsUp Gold

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-16
Due
2024-10-07
Priority interval
84.099.0
Coverage
85%
478

Microsoft Windows MSHTML Platform Spoofing Vulnerability

Microsoft Windows MSHTML Platform contains a user interface (UI) misrepresentation of critical information vulnerability that allows an attacker to spoof a web page. This vulnerability was exploited in conjunction with CVE-2024-38112.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-16
Due
2024-10-07
Priority interval
76.491.4
Coverage
85%
479

Ivanti Cloud Services Appliance OS Command Injection Vulnerability

Ivanti Cloud Services Appliance (CSA) contains an OS command injection vulnerability in the administrative console which can allow an authenticated attacker with application admin privileges to pass commands to the underlying OS.

IvantiCloud Services Appliance

Required actionAs Ivanti CSA has reached End-of-Life status, users are urged to remove CSA 4.6.x from service or upgrade to the 5.0.x line of supported solutions, as future vulnerabilities on the 4.6.x version of CSA are unlikely to receive future security updates.

Added
2024-09-13
Due
2024-10-04
Priority interval
76.991.9
Coverage
85%
480

Microsoft Windows Installer Improper Privilege Management Vulnerability

Microsoft Windows Installer contains an improper privilege management vulnerability that could allow an attacker to gain SYSTEM privileges.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-10
Due
2024-10-01
Priority interval
64.479.4
Coverage
85%
481

Microsoft Publisher Protection Mechanism Failure Vulnerability

Microsoft Publisher contains a protection mechanism failure vulnerability that allows attacker to bypass Office macro policies used to block untrusted or malicious files.

MicrosoftPublisher

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-10
Due
2024-10-01
Priority interval
61.576.5
Coverage
85%
482

Microsoft Windows Mark of the Web (MOTW) Protection Mechanism Failure Vulnerability

Microsoft Windows Mark of the Web (MOTW) contains a protection mechanism failure vulnerability that allows an attacker to bypass MOTW-based defenses. This can result in a limited loss of integrity and availability of security features such as Protected View in Microsoft Office, which rely on MOTW tagging.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-10
Due
2024-10-01
Priority interval
59.774.7
Coverage
85%
483
CVE-2016-3714CISA KEVConflicting evidence

ImageMagick Improper Input Validation Vulnerability

ImageMagick contains an improper input validation vulnerability that affects the EPHEMERAL, HTTPS, MVG, MSL, TEXT, SHOW, WIN, and PLT coders. This allows a remote attacker to execute arbitrary code via shell metacharacters in a crafted image.

ImageMagickImageMagick

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-09
Due
2024-09-30
Priority interval
80.799.7
Coverage
73%
484
CVE-2024-40766CISA KEVKnown ransomware

SonicWall SonicOS Improper Access Control Vulnerability

SonicWall SonicOS contains an improper access control vulnerability that could lead to unauthorized resource access and, under certain conditions, may cause the firewall to crash.

SonicWallSonicOS

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-09
Due
2024-09-30
Priority interval
71.187.4
Coverage
85%
485
CVE-2017-1000253CISA KEVKnown ransomware

Linux Kernel PIE Stack Buffer Corruption Vulnerability

Linux kernel contains a position-independent executable (PIE) stack buffer corruption vulnerability in load_elf_ binary() that allows a local attacker to escalate privileges.

LinuxKernel

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-09
Due
2024-09-30
Priority interval
64.581.0
Coverage
85%
486

Draytek VigorConnect Path Traversal Vulnerability

Draytek VigorConnect contains a path traversal vulnerability in the DownloadFileServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

DrayTekVigorConnect

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-03
Due
2024-09-24
Priority interval
76.091.7
Coverage
85%
487

Draytek VigorConnect Path Traversal Vulnerability

Draytek VigorConnect contains a path traversal vulnerability in the file download functionality of the WebServlet endpoint. An unauthenticated attacker could leverage this vulnerability to download arbitrary files from the underlying operating system with root privileges.

DrayTekVigorConnect

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-03
Due
2024-09-24
Priority interval
75.491.1
Coverage
85%
488
CVE-2024-7262CISA KEVConflicting evidence

Kingsoft WPS Office Path Traversal Vulnerability

Kingsoft WPS Office contains a path traversal vulnerability in promecefpluginhost.exe on Windows that allows an attacker to load an arbitrary Windows library.

KingsoftWPS Office

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-09-03
Due
2024-09-24
Priority interval
62.280.9
Coverage
73%
489

Google Chromium V8 Inappropriate Implementation Vulnerability

Google Chromium V8 contains an inappropriate implementation vulnerability that allows a remote attacker to potentially exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-28
Due
2024-09-18
Priority interval
70.385.3
Coverage
85%
490
CVE-2024-38856CISA KEVConflicting evidence

Apache OFBiz Incorrect Authorization Vulnerability

Apache OFBiz contains an incorrect authorization vulnerability that could allow remote code execution via a Groovy payload in the context of the OFBiz user process by an unauthenticated attacker.

ApacheOFBiz

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-27
Due
2024-09-17
Priority interval
80.299.4
Coverage
73%
491
CVE-2024-7971CISA KEVConflicting evidence

Google Chromium V8 Type Confusion Vulnerability

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to exploit heap corruption via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

GoogleChromium V8

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-26
Due
2024-09-16
Priority interval
70.887.8
Coverage
73%
492
CVE-2024-39717CISA KEVConflicting evidence

Versa Director Dangerous File Type Upload Vulnerability

The Versa Director GUI contains an unrestricted upload of file with dangerous type vulnerability that allows administrators with Provider-Data-Center-Admin or Provider-Data-Center-System-Admin privileges to customize the user interface. The “Change Favicon” (Favorite Icon) enables the upload of a .png file, which can be exploited to upload a malicious file with a .png extension disguised as an image.

VersaDirector

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-23
Due
2024-09-13
Priority interval
60.577.0
Coverage
73%
493
CVE-2021-33044CISA KEVConflicting evidence

Dahua IP Camera Authentication Bypass Vulnerability

Dahua IP cameras and related products contain an authentication bypass vulnerability when the NetKeyboard type argument is specified by the client during authentication.

DahuaIP Camera Firmware

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-21
Due
2024-09-11
Priority interval
84.5100.0
Coverage
73%
494
CVE-2021-33045CISA KEVConflicting evidence

Dahua IP Camera Authentication Bypass Vulnerability

Dahua IP cameras and related products contain an authentication bypass vulnerability when the loopback device is specified by the client during authentication.

DahuaIP Camera Firmware

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-21
Due
2024-09-11
Priority interval
84.5100.0
Coverage
73%
495
CVE-2021-31196CISA KEVConflicting evidence

Microsoft Exchange Server Information Disclosure Vulnerability

Microsoft Exchange Server contains an information disclosure vulnerability that allows for remote code execution.

MicrosoftExchange Server

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-21
Due
2024-09-11
Priority interval
69.986.6
Coverage
73%
496
CVE-2022-0185CISA KEVConflicting evidence

Linux Kernel Heap-Based Buffer Overflow Vulnerability

Linux kernel contains a heap-based buffer overflow vulnerability in the legacy_parse_param function in the Filesystem Context functionality. This allows an attacker to open a filesystem that does not support the Filesystem Context API and ultimately escalate privileges.

LinuxKernel

Required actionApply updates per vendor instructions or discontinue use of the product if updates are unavailable.

Added
2024-08-21
Due
2024-09-11
Priority interval
68.086.0
Coverage
73%
497
CVE-2024-23897CISA KEVKnown ransomware

Jenkins Command Line Interface (CLI) Path Traversal Vulnerability

Jenkins Command Line Interface (CLI) contains a path traversal vulnerability that allows attackers limited read access to certain files, which can lead to code execution.

JenkinsJenkins Command Line Interface (CLI)

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-19
Due
2024-09-09
Priority interval
84.599.5
Coverage
85%
498

SolarWinds Web Help Desk Deserialization of Untrusted Data Vulnerability

SolarWinds Web Help Desk contains a deserialization of untrusted data vulnerability that could allow for remote code execution.

SolarWindsWeb Help Desk

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-15
Due
2024-09-05
Priority interval
82.997.9
Coverage
85%
499

Microsoft Windows Scripting Engine Memory Corruption Vulnerability

Microsoft Windows Scripting Engine contains a memory corruption vulnerability that allows unauthenticated attacker to initiate remote code execution via a specially crafted URL.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-13
Due
2024-09-03
Priority interval
71.386.3
Coverage
85%
500

Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation Vulnerability

Microsoft Windows Ancillary Function Driver for WinSock contains an unspecified vulnerability that allows for privilege escalation, enabling a local attacker to gain SYSTEM privileges.

MicrosoftWindows

Required actionApply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Added
2024-08-13
Due
2024-09-03
Priority interval
70.085.0
Coverage
85%