Top 20 Most Exploited Vulnerabilities: Microsoft Products Draw Hackers
In the current cybersecurity landscape, identifying and addressing open vulnerabilities is a critical task for security teams. Highlighting high-risk CVEs that are actively exploited by threat actors is essential for maintaining security.
In the current cybersecurity landscape, identifying and addressing open vulnerabilities is a critical task for security teams. Highlighting high-risk CVEs that are actively exploited by threat actors is essential for maintaining security.
Research from Qualys has identified the top 20 most exploited vulnerabilities, with a significant focus on Microsoft products. These findings are also reflected in the CISA Joint Cybersecurity Advisory (CSA) dated Thu, Aug 3, 2023.
CVE-2017-11882
Description: Microsoft Office Memory Corruption Vulnerability Trending: 2018, 2020, 2021, 2022, 2023 (79 times) Qualys ID: 110308
CVE-2017-0199
Description: Microsoft Wordpad Remote Code Execution Vulnerability Trending: 2017, 2020, 2021, 2023 (59 times) Qualys ID: 110297
CVE-2012-0158
Description: Vulnerability in Windows Common Controls Could Allow RCE Trending: 2013, 2020, 2021, 2023 (33 times) Qualys ID: 90793
CVE-2017-8570
Description: Microsoft Office Remote Code Execution Vulnerability Trending: 2018, 2020, 2023 (25 times) Qualys ID: 110300
CVE-2020-1472
Description: Zerologon – An Unauthenticated Privilege Escalation to Full Domain Privileges Trending: 2020, 2021, 2022, 2023 (56 times) Qualys ID: 91680
CVE-2017-0144 , CVE-2017-0145 , CVE-2017-0143
Description: Windows SMBv1 Remote Code Execution Vulnerability (WannaCry, Petya) Trending: 2017, 2020, 2021, 2023 (50 times) Qualys ID: 91361, 91360, 91359, 91345
CVE-2012-1723
Description: Java Applet Field Bytecode Verifier Cache Remote Code Execution Trending: 2023 (6 times) Qualys ID: 120274
In the current cybersecurity landscape, identifying and addressing open vulnerabilities is a critical task for security teams.
CVE-2021-34473 , CVE-2021-34523 , CVE-2021-31207
Description: Microsoft Exchange Server RCE (ProxyShell) Trending: 2021, 2022, 2023 (39 times) Qualys ID: 50114, 50111, 50112
CVE-2019-11510
Description: Pulse Secure Pulse Connect Secure SSL VPN Unauthenticated Path Trending: 2019, 2020, 2023 (53 times) Qualys ID: 38771
CVE-2021-44228
Description: Apache Log4j Remote Code Execution Vulnerability Trending: 2021, 2022, 2023 (77 times) Qualys ID: 376157, 730297
CVE-2014-6271
Description: Shellshock – Linux Bash Vulnerability Trending: 2014, 2016, 2017, 2020, 2021, 2022, 2023 (70 times) Qualys ID: 122693, 13038, 150134
CVE-2018-8174
Description: Windows VBScript Engine Remote Code Execution Vulnerability Trending: 2018, 2020, 2023 (30 times) Qualys ID: 91447
CVE-2013-0074
Description: Microsoft Silverlight Could Allow Remote Code Execution Trending: 2023 (8 times) Qualys ID: 90870
CVE-2012-0507
Description: Oracle Java SE Remote Java Runtime Environment Vulnerability Trending: 2023 (10 times) Qualys ID: 119956
CVE-2019-19781
Description: Citrix ADC and Citrix Gateway – Remote Code Execution (RCE) Vulnerability Trending: 2020, 2022, 2023 (60 times) Qualys ID: 372305, 150273
CVE-2018-0802
Description: Microsoft Office Memory Corruption Vulnerability Trending: 2021, 2022, 2023 (19 times) Qualys ID: 110310
CVE-2021-26855
Description: Microsoft Exchange Server Authentication Bypass (RCE) Trending: 2021, 2023 (46 times) Qualys ID: 50107, 50108
CVE-2019-2725
Description: Oracle WebLogic Affected by Unauthenticated RCE Vulnerability Trending: 2019, 2020, 2022, 2023 (53 times) Qualys ID: 150267, 87386
CVE-2018-13379
Description: Fortinet FortiGate (FortiOS) System File Leak through SSL Trending: 2020, 2021, 2023 (41 times) Qualys ID: 43702
CVE-2021-26084
Description: Atlassian Confluence Server Webwork OGNL Injection RCE Vulnerability Trending: 2021, 2022, 2023 (35 times) Qualys ID: 730172, 150368, 375839
Security analysts at Qualys recommend that users promptly identify assets vulnerable to these top CVEs and prioritize remediation. Utilizing Qualys Patch can effectively reduce risk. Additionally, leveraging Qualys VMDR's dynamic Threat Intelligence is advised to streamline the prioritization of high-risk vulnerabilities.
Based on reporting by Cyber Security News.
