AnalysisMembers
CISA just added four old local privilege escalation bugs to KEV. That is the interesting part.
Between 25 and 27 August, KEV gained CVEs from 2015, 2021 and 2022 — most of them local, none of them remote entry points. A catalogue of what attackers are actively using is telling you about the second stage, and about how much end-of-life software is still running.
CVE-2015-3246CVE-2015-5287T1068T1190