Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

CVE-2022-21988

Microsoft Office Visio Remote Code Execution Vulnerability.

CVE
#vulnerability#microsoft
CVE-2022-21987

Microsoft SharePoint Server Spoofing Vulnerability.

CVE-2022-22004

Microsoft Office ClickToRun Remote Code Execution Vulnerability.

CVE-2022-22003

Microsoft Office Graphics Remote Code Execution Vulnerability.

CVE-2022-23255: Microsoft OneDrive for Android Security Feature Bypass Vulnerability

**What privileges are required to exploit this vulnerability?** The attacker needs access to an unlocked mobile device to exploit the vulnerability.

CVE-2022-23252: Microsoft Office Information Disclosure Vulnerability

**What type of information could be disclosed by this vulnerability?** The type of information that could be disclosed if an attacker successfully exploited this vulnerability is uninitialized memory.

CVE-2022-23274: Microsoft Dynamics GP Remote Code Execution Vulnerability

**How could an attacker exploit this vulnerability?** An authenticated user could send a specially crafted SQL request to a Dynamics GP Web Service and perform remote code execution.

CVE-2022-23272: Microsoft Dynamics GP Elevation Of Privilege Vulnerability

**How could an attacker exploit this vulnerability?** An attacker could send a specially crafted request to a vulnerable Dynamics site and overwrite database contents.

CVE-2022-23269: Microsoft Dynamics GP Spoofing Vulnerability

**The CVSS Score says user action is required. What type of user action is required?** An authenticated user would have to visit a specific URL that will create an action for a workflow.