Home > 취약점 정보 공유 > 보안공지
보안공지

목록

조회수 : 2,510


美 CISA 발표 주요 Exploit 정보공유(Update. 2026-02-10)2026-02-10
현재 자주 악용되고 있는 취약점 목록으로, 취약한 버전의 SW를 사용 중인 경우 긴급 패치를 권고 드립니다.
* 참조 링크 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog

cveIDvendorProjectvulnerabilityNamedateAddedshortDescriptionrequiredActiondueDate
CVE-2026-21514MicrosoftMicrosoft Office Word Reliance on Untrusted Inputs in a Security Decision Vulnerability2026-02-10Microsoft Office Word contains a reliance on untrusted inputs in a security decision vulnerability that could allow an authorized attacker to elevate privileges locally.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2026-03-03
CVE-2026-21519MicrosoftMicrosoft Windows Type Confusion Vulnerability2026-02-10Microsoft Desktop Windows Manager contains a type confusion vulnerability that could allow an authorized attacker to elevate privileges locally.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2026-03-03
CVE-2026-21533MicrosoftMicrosoft Windows Improper Privilege Management Vulnerability2026-02-10Microsoft Windows Remote Desktop Services contains an improper privilege management vulnerability that could allow an authorized attacker to elevate privileges locally.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2026-03-03
CVE-2026-21510MicrosoftMicrosoft Windows Shell Protection Mechanism Failure Vulnerability2026-02-10Microsoft Windows Shell contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network. Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2026-03-03
CVE-2026-21525MicrosoftMicrosoft Windows NULL Pointer Dereference Vulnerability2026-02-10Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2026-03-03
CVE-2026-21513MicrosoftMicrosoft MSHTML Framework Protection Mechanism Failure Vulnerability2026-02-10Microsoft MSHTML Framework contains a protection mechanism failure vulnerability that could allow an unauthorized attacker to bypass a security feature over a network.Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.2026-03-03
출처 사이트 : https://www.cisa.gov/known-exploited-vulnerabilities-catalog