Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

Microsoft discloses more than 130 vulnerabilities as part of July’s Patch Tuesday, four exploited in the wild

Four of the disclosed vulnerabilities — albeit “important” ones — have been detected being exploited in the wild: CVE-2023-32046, CVE-2023-32049, CVE-2023-35311 and CVE-2023-36874.

TALOS
#vulnerability#windows#microsoft#cisco#rce#auth
CVE-2023-36884

Microsoft is investigating reports of a series of remote code execution vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents. An attacker could create a specially crafted Microsoft Office document that enables them to perform remote code execution in the context of the victim. However, an attacker would have to convince the victim to open the malicious file. Upon completion of this investigation, Microsoft will take the appropriate action to help protect our customers. This might include providing a security update through our monthly release process or providing an out-of-cycle security update, depending on customer needs. Please see the Microsoft Threat Intelligence Blog https://aka.ms/Storm-0978  Entry for important information about steps you can take to protect your system from this vulnerability. This CVE will be updated with new inform...

CVE-2023-32049

Windows SmartScreen Security Feature Bypass Vulnerability

CVE-2023-21756

Windows Win32k Elevation of Privilege Vulnerability

CVE-2023-29347

Windows Admin Center Spoofing Vulnerability

CVE-2023-32037

Windows Layer-2 Bridge Network Driver Information Disclosure Vulnerability

CVE-2023-32041

Windows Update Orchestrator Service Information Disclosure Vulnerability

CVE-2023-32043

Windows Remote Desktop Security Feature Bypass Vulnerability

CVE-2023-21526

Windows Netlogon Information Disclosure Vulnerability

CVE-2023-35364

Windows Kernel Elevation of Privilege Vulnerability