Aug 13, 2024 Cyber Threat Intelligence

Track daily vulnerability activity, KEV additions, public exploits, critical disclosures, and EPSS risk shifts.

Daily summary

  • Microsoft Windows: 6 CVEs added to CISA KEV today.
  • 10 new critical disclosures — review patch status on exposed services.

Top threats today

Three highest-priority changes — analyst brief, not a CVE dump.

Critical active threat

CVE-2024-38106 Microsoft Windows Kernel Privilege Escalation

  • Actively exploited (CISA KEV)
  • Listed on CISA KEV
  • Potential privilege escalation to admin/root

Microsoft Windows Privilege Escalation is on CISA KEV — confirmed in-the-wild exploitation. Expect continued targeting while the issue remains on the catalog.

Critical exposure

CVE-2024-20082 In Modem, there is a possible memory corruption due to a missing bounds check.

  • CVSS 9.8
  • Remote code execution exposure

New critical Mediatek Nr15 RCE (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Critical exposure

CVE-2024-20083 In venc, there is a possible out of bounds write due to a missing bounds check.

  • CVSS 9.8

New critical Google Android memory safety (CVSS 9.8) — fresh disclosure window; early internet scanning often precedes mature exploit chains.

Active exploitation

CISA KEV — confirmed in-the-wild exploitation.

Microsoft Windows Power Dependency Coordinator Privilege Escalation

Microsoft Windows Scripting Engine Memory Corruption

Microsoft Windows Ancillary Function Driver for WinSock Privilege Escalation

Microsoft Windows SmartScreen Security Feature Bypass

View KEV additions

Exploit & PoC activity

Nothing flagged in this category for this digest.

View new exploit links

Exploitation dynamics

Nothing flagged in this category for this digest.

See EPSS increases

New critical disclosures

CVE-2024-20082 CVSS 9.8

In Modem, there is a possible memory corruption due to a missing bounds check.

CVE-2024-20083 CVSS 9.8

In venc, there is a possible out of bounds write due to a missing bounds check.

CVE-2024-28986 CVSS 9.8

SolarWinds Web Help Desk Deserialization of Untrusted Data

CVE-2024-38140 CVSS 9.8

Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability

CVE-2024-38159 CVSS 9.1

Windows Network Virtualization Remote Code Execution Vulnerability

CVE-2024-38160 CVSS 9.1

Windows Network Virtualization Remote Code Execution Vulnerability

CVE-2024-38199 CVSS 9.8

Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability

CVE-2024-38652 CVSS 9.1

Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of s...

CVE-2024-7569 CVSS 9.6

An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated...

CVE-2024-7593 CVSS 9.8

Ivanti Virtual Traffic Manager Authentication Bypass

View critical disclosures

cvelogic Threat Intelligence