|
1 | 1 | { |
2 | 2 | "title": "CISA Catalog of Known Exploited Vulnerabilities", |
3 | | - "catalogVersion": "2025.07.18", |
4 | | - "dateReleased": "2025-07-18T17:00:02.4347Z", |
5 | | - "count": 1381, |
| 3 | + "catalogVersion": "2025.07.20", |
| 4 | + "dateReleased": "2025-07-20T19:06:00.8332Z", |
| 5 | + "count": 1382, |
6 | 6 | "vulnerabilities": [ |
| 7 | + { |
| 8 | + "cveID": "CVE-2025-53770", |
| 9 | + "vendorProject": "Microsoft", |
| 10 | + "product": "SharePoint", |
| 11 | + "vulnerabilityName": "Microsoft SharePoint Deserialization of Untrusted Data Vulnerability", |
| 12 | + "dateAdded": "2025-07-20", |
| 13 | + "shortDescription": "Microsoft SharePoint Server on-premises contains a deserialization of untrusted data vulnerability that could allow an unauthorized attacker to execute code over a network.", |
| 14 | + "requiredAction": "CISA recommends configuring AMSI integration in SharePoint and deploying Defender AV on all SharePoint servers. If AMSI cannot be enabled, CISA recommends disconnecting affected products that are public-facing on the internet from service until official mitigations are available. Once mitigations are provided, apply them according to CISA and vendor instructions. Follow the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. ", |
| 15 | + "dueDate": "2025-07-21", |
| 16 | + "knownRansomwareCampaignUse": "Unknown", |
| 17 | + "notes": "CISA Mitigation Instructions: https:\/\/www.cisa.gov\/news-events\/alerts\/2025\/07\/20\/microsoft-releases-guidance-exploitation-sharepoint-vulnerability-cve-2025-53770 ; https:\/\/msrc.microsoft.com\/blog\/2025\/07\/customer-guidance-for-sharepoint-vulnerability-cve-2025-53770\/ ; https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2025-53770 ; https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-53770", |
| 18 | + "cwes": [ |
| 19 | + "CWE-502" |
| 20 | + ] |
| 21 | + }, |
7 | 22 | { |
8 | 23 | "cveID": "CVE-2025-25257", |
9 | 24 | "vendorProject": "Fortinet", |
|
0 commit comments