Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2021-42296: Microsoft Word Remote Code Execution Vulnerability

*Is the Preview Pane an attack vector for this vulnerability?* No, the Preview Pane is not an attack vector.

Microsoft Security Response Center
#Microsoft Office Word#Security Vulnerability#vulnerability#microsoft
CVE-2021-43208: 3D Viewer Remote Code Execution Vulnerability

*How do I get the updated app?* The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. Customers using the Microsoft Store for Business and Microsoft Store for Education can get this update through their organizations. *How can I check if the update is installed?* App package versions *7.2107.7012.0* and later contain this update. You can check the package version in PowerShell: Get-AppxPackage -Name Microsoft.Microsoft3DViewer

CVE-2021-43209: 3D Viewer Remote Code Execution Vulnerability

*How do I get the updated app?* The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. Customers using the Microsoft Store for Business and Microsoft Store for Education can get this update through their organizations. *How can I check if the update is installed?* App package versions *7.2107.7012.0* and later contain this update. You can check the package version in PowerShell: Get-AppxPackage -Name Microsoft.Microsoft3DViewer

U.S. Offers $10 Million Reward for Information on DarkSide Ransomware Group

The U.S. government on Thursday announced a $10 million reward for information that may lead to the identification or location of key individuals who hold leadership positions in the DarkSide ransomware group or any of its rebrands. On top of that, the State Department is offering bounties of up to $5 million for intel and tip-offs that could result in the arrest and/or conviction in any country

A week in security (Nov 1 – Nov 7)

A roundup of the previous week's blog post, and the most important and interesting security events and happenings. Categories: A week in security Tags: 0-day BlackMatter card skimmer CERT-France cisa crypo wallet cryptocurrency Discord Nitro facebook Google Graff insider threat insider threat by machine Justin Bieber Labour Party Metaverse microsoft mozilla Outlook phishing phishing kits ransomware ransomware bounty safari SalesForce bug Steam phish The Weeknd twitch zero-day *( Read more... ( https://blog.malwarebytes.com/a-week-in-security/2021/11/a-week-in-security-nov-1-nov-7/ ) )* The post A week in security (Nov 1 – Nov 7) appeared first on Malwarebytes Labs.

CVE-2021-42370: Storage Monitoring EMC² IBM Hitachi HPE NetApp Lenovo

A password mismanagement situation exists in XoruX LPAR2RRD and STOR2RRD before 7.30 because cleartext information is present in HTML password input fields in the device properties. (Viewing the passwords requires configuring a web browser to display HTML password input fields.)