Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2023-32083

Microsoft Failover Cluster Information Disclosure Vulnerability

CVE
#vulnerability#microsoft
CVE-2023-32085

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

CVE-2023-35341

Microsoft DirectMusic Information Disclosure Vulnerability

CVE-2023-35324

Microsoft PostScript and PCL6 Class Printer Driver Information Disclosure Vulnerability

CVE-2023-35347

Microsoft Install Service Elevation of Privilege Vulnerability

CVE-2023-24881

Microsoft Teams Information Disclosure Vulnerability

Undocumented driver-based browser hijacker RedDriver targets Chinese speakers and internet cafes

Cisco Talos has identified multiple versions of an undocumented malicious driver named “RedDriver,” a driver-based browser hijacker that uses the Windows Filtering Platform (WFP) to intercept browser traffic.

Old certificate, new signature: Open-source tools forge signature timestamps on Windows drivers

Actors are leveraging multiple open-source tools that alter the signing date of kernel mode drivers to load malicious and unverified drivers signed with expired certificates.

Hackers Exploit Windows Policy Loophole to Forge Kernel-Mode Driver Signatures

A Microsoft Windows policy loophole has been observed being exploited primarily by native Chinese-speaking threat actors to forge signatures on kernel-mode drivers. "Actors are leveraging multiple open-source tools that alter the signing date of kernel mode drivers to load malicious and unverified drivers signed with expired certificates," Cisco Talos said in an exhaustive two-part report shared

Ateme TITAN File 3.9 Job Callbacks Server-Side Request Forgery

Ateme TITAN File version 3.9 suffers from a server-side request forgery vulnerability that allows for file enumeration.