CISA's list that day
17 April 2025
On CISA added 3 vulnerabilities to its list of exploited vulnerabilities, in Microsoft Windows and Apple Multiple Products. US federal agencies must fix them by .
Added that day
| Vulnerability | Product | Our group | Listed | Deadline | EPSS |
|---|---|---|---|---|---|
| CVE-2025-24054NTLM Hash Disclosure Spoofing | Microsoft Windows | Patch this weekEPSS 0.59 | 0.59 | ||
| CVE-2025-31200Memory Corruption | Apple Multiple Products | Patch soon | 0.19 | ||
| CVE-2025-31201Arbitrary Read and Write | Apple Multiple Products | Patch soon | 0.14 |