The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a vulnerability in Microsoft’s Windows 10 software to its Known Exploited Vulnerability Catalog. This issue involves a deserialization of untrusted data in Microsoft COM for Windows, which could lead to privilege escalation and remote code execution. CISA has advised users to either cease using the affected software or apply a patch provided by Windows.