May 9, 2023 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Win32k added to CISA KEV — confirmed in-the-wild exploitation.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2023-29336 Microsoft Win32K Privilege Escalation

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Potential privilege escalation to admin/root

Microsoft Win32k Privilege Escalation is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2021-26379 Amd Epyc 7232p Firmware Privilege Escalation

  • CVSS 9.8
  • Potential privilege escalation to admin/root

New critical Amd Epyc 7232p Firmware Privilege Escalation (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2021-46760 Amd Ryzen 3945wx Firmware Code Execution

  • CVSS 9.8
  • Remote code execution exposure

New critical Amd Ryzen 3945wx Firmware Code Execution (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2021-26379 CVSS 9.8

Insufficient input validation of mailbox data in the SMU may allow an attacker to coerce the SMU to corrupt SMRAM, potentially leading to...

CVE-2021-46753 CVSS 9.1

Failure to validate the length fields of the ASP (AMD Secure Processor) sensor fusion hub headers may allow an attacker with a malicious...

CVE-2021-46754 CVSS 9.1

Insufficient input validation in the ASP (AMD Secure Processor) bootloader may allow an attacker with a compromised Uapp or ABL to coerce...

CVE-2021-46756 CVSS 9.1

Insufficient validation of inputs in SVC_MAP_USER_STACK in the ASP (AMD Secure Processor) bootloader may allow an attacker with a malicio...

CVE-2021-46760 CVSS 9.8

A malicious or compromised UApp or ABL can send a malformed system call to the bootloader, which may result in an out-of-bounds memory ac...

CVE-2023-20520 CVSS 9.8

Improper access control settings in ASP Bootloader may allow an attacker to corrupt the return address causing a stack-based buffer overr...

CVE-2023-24941 CVSS 9.8

Windows Network File System Remote Code Execution Vulnerability

CVE-2023-24943 CVSS 9.8

Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability

CVE-2023-28316 CVSS 9.8

A security vulnerability has been discovered in the implementation of 2FA on the rocket.chat platform, where other active sessions are no...

View critical disclosures

cvelogic Threat Intelligence