β Microsoft Patch Tuesday Update Fixes 17 Critical Bugs β
π Read
via "Threat Post".
Remote code execution vulnerabilities dominate this monthβs security bulletin of warnings and patches.π Read
via "Threat Post".
Threat Post
Microsoft Patch Tuesday Update Fixes 17 Critical Bugs
Remote code execution vulnerabilities dominate this monthβs security bulletin of warnings and patches.
π΄ Microsoft Patches Windows Kernel Flaw Under Active Attack π΄
π Read
via "Dark Reading".
This month's Patch Tuesday addressed a Windows zero-day in a release of 112 vulnerabilities, 17 of which are critical.π Read
via "Dark Reading".
Darkreading
Microsoft Patches Windows Kernel Flaw Under Active Attack
This month's Patch Tuesday addressed a Windows zero-day in a release of 112 vulnerabilities, 17 of which are critical.
π΄ Claroty Details Vulnerabilities in Schneider PLCs π΄
π Read
via "Dark Reading".
The vulnerabilities in a common line of programmable logic controllers could allow attackers to gain control of industrial equipment.π Read
via "Dark Reading".
Dark Reading
Claroty Details Vulnerabilities in Schneider PLCs
The vulnerabilities in a common line of programmable logic controllers could allow attackers to gain control of industrial equipment.
βΌ CVE-2020-25268 βΌ
π Read
via "National Vulnerability Database".
Remote Code Execution can occur via the external news feed in ILIAS 6.4 because of incorrect parameter sanitization for Magpie RSS data.π Read
via "National Vulnerability Database".
βΌ CVE-2020-25267 βΌ
π Read
via "National Vulnerability Database".
An XSS issue exists in the question-pool file-upload preview feature in ILIAS 6.4.π Read
via "National Vulnerability Database".
βΌ CVE-2020-28408 βΌ
π Read
via "National Vulnerability Database".
The server in Dundas BI through 8.0.0.1001 allows XSS via an HTML label when creating or editing a dashboard.π Read
via "National Vulnerability Database".
βΌ CVE-2020-28409 βΌ
π Read
via "National Vulnerability Database".
The server in Dundas BI through 8.0.0.1001 allows XSS via addition of a Component (e.g., a button) when events such as click, hover, etc. occur.π Read
via "National Vulnerability Database".
βΌ CVE-2020-24367 βΌ
π Read
via "National Vulnerability Database".
Incorrect file permissions in BlueStacks 4 through 4.230 on Windows allow a local attacker to escalate privileges by modifying a file that is later executed by a higher-privileged user.π Read
via "National Vulnerability Database".
βΌ CVE-2020-24063 βΌ
π Read
via "National Vulnerability Database".
The Canto plugin 1.3.0 for WordPress allows includes/lib/download.php?subdomain= SSRF.π Read
via "National Vulnerability Database".
π΄ Malware Hidden in Encrypted Traffic Surges Amid Pandemic π΄
π Read
via "Dark Reading".
Zscaler says attacks involving the use of SSL/TLS encryption jumped 260% in the first nine months of 2020 compared to the same period last year.π Read
via "Dark Reading".
Dark Reading
Malware Hidden in Encrypted Traffic Surges Amid Pandemic
Zscaler says attacks involving the use of SSL/TLS encryption jumped 260% in the first nine months of 2020 compared to the same period last year.
π΄ Flaws in Privileged Management Apps Expose Machines to Attack π΄
π Read
via "Dark Reading".
The Intel Support Assistant is the latest Windows utility to be found that could expose millions of computers to privilege-escalation attacks through file manipulation and symbolic links.π Read
via "Dark Reading".
Dark Reading
Flaws in Privileged Management Apps Expose Machines to Attack
The Intel Support Assistant is the latest Windows utility to be found that could expose millions of computers to privilege-escalation attacks through file manipulation and symbolic links.
βΌ CVE-2020-16126 βΌ
π Read
via "National Vulnerability Database".
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, improperly dropped the ruid, allowing untrusted users to send signals to AccountService, thus stopping it from handling D-Bus messages in a timely fashion.π Read
via "National Vulnerability Database".
βΌ CVE-2020-16127 βΌ
π Read
via "National Vulnerability Database".
An Ubuntu-specific modification to AccountsService in versions before 0.6.55-0ubuntu13.2, among other earlier versions, would perform unbounded read operations on user-controlled ~/.pam_environment files, allowing an infinite loop if /dev/zero is symlinked to this location.π Read
via "National Vulnerability Database".
βΌ CVE-2020-17053 βΌ
π Read
via "National Vulnerability Database".
, aka 'Internet Explorer Memory Corruption Vulnerability'.π Read
via "National Vulnerability Database".
βΌ CVE-2020-17019 βΌ
π Read
via "National Vulnerability Database".
, aka 'Microsoft Excel Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17064, CVE-2020-17065, CVE-2020-17066.π Read
via "National Vulnerability Database".
βΌ CVE-2020-17055 βΌ
π Read
via "National Vulnerability Database".
, aka 'Windows Remote Access Elevation of Privilege Vulnerability'. This CVE ID is unique from CVE-2020-17025, CVE-2020-17026, CVE-2020-17027, CVE-2020-17028, CVE-2020-17031, CVE-2020-17032, CVE-2020-17033, CVE-2020-17034, CVE-2020-17043, CVE-2020-17044.π Read
via "National Vulnerability Database".
βΌ CVE-2020-17071 βΌ
π Read
via "National Vulnerability Database".
, aka 'Windows Delivery Optimization Information Disclosure Vulnerability'.π Read
via "National Vulnerability Database".
βΌ CVE-2020-17070 βΌ
π Read
via "National Vulnerability Database".
, aka 'Windows Update Medic Service Elevation of Privilege Vulnerability'.π Read
via "National Vulnerability Database".
βΌ CVE-2020-17106 βΌ
π Read
via "National Vulnerability Database".
, aka 'HEVC Video Extensions Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2020-17107, CVE-2020-17108, CVE-2020-17109, CVE-2020-17110.π Read
via "National Vulnerability Database".
βΌ CVE-2020-17040 βΌ
π Read
via "National Vulnerability Database".
, aka 'Windows Hyper-V Security Feature Bypass Vulnerability'.π Read
via "National Vulnerability Database".
βΌ CVE-2020-17012 βΌ
π Read
via "National Vulnerability Database".
, aka 'Windows Bind Filter Driver Elevation of Privilege Vulnerability'.π Read
via "National Vulnerability Database".