🛡 Cybersecurity & Privacy 🛡 - News
25.8K subscribers
89.2K links
🗞 The finest daily news on cybersecurity and privacy.

🔔 Daily releases.

💻 Is your online life secure?

📩 lalilolalo.dev@gmail.com
Download Telegram
CVE-2022-41054

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-39879

Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.

📖 Read

via "National Vulnerability Database".
CVE-2022-41048

Microsoft ODBC Driver Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41047.

📖 Read

via "National Vulnerability Database".
👍1
CVE-2022-41085

Azure CycleCloud Elevation of Privilege Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-41063

Microsoft Excel Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41106.

📖 Read

via "National Vulnerability Database".
CVE-2022-41050

Windows Extensible File Allocation Table Elevation of Privilege Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-39885

Improper access control vulnerability in BootCompletedReceiver_CMCC in DeviceManagement prior to SMR Nov-2022 Release 1 allows local attacker to access to Device information.

📖 Read

via "National Vulnerability Database".
CVE-2022-44550

The graphics display module has a UAF vulnerability when traversing graphic layers. Successful exploitation of this vulnerability may affect system availability.

📖 Read

via "National Vulnerability Database".
CVE-2022-41101

Windows Overlay Filter Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41102.

📖 Read

via "National Vulnerability Database".
CVE-2022-41118

Windows Scripting Languages Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41128.

📖 Read

via "National Vulnerability Database".
CVE-2022-41086

Windows Group Policy Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37992.

📖 Read

via "National Vulnerability Database".
CVE-2022-41092

Windows Win32k Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-41109.

📖 Read

via "National Vulnerability Database".
CVE-2022-44549

The LBS module has a vulnerability in geofencing API access. Successful exploitation of this vulnerability may cause third-party apps to access the geofencing APIs without authorization, affecting user confidentiality.

📖 Read

via "National Vulnerability Database".
CVE-2022-41078

Microsoft Exchange Server Spoofing Vulnerability. This CVE ID is unique from CVE-2022-41079.

📖 Read

via "National Vulnerability Database".
CVE-2022-41088

Windows Point-to-Point Tunneling Protocol Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41039, CVE-2022-41044.

📖 Read

via "National Vulnerability Database".
CVE-2022-41098

Windows GDI+ Information Disclosure Vulnerability.

📖 Read

via "National Vulnerability Database".
CVE-2022-39890

Improper Authorization in Samsung Billing prior to version 5.0.56.0 allows attacker to get sensitive information.

📖 Read

via "National Vulnerability Database".
CVE-2022-39893

Sensitive information exposure vulnerability in FmmBaseModel in Galaxy Buds Pro Manage prior to version 4.1.22092751 allows local attackers with log access permission to get device identifier data through device log.

📖 Read

via "National Vulnerability Database".
CVE-2022-39306

Grafana is an open-source platform for monitoring and observability. Versions prior to 9.2.4, or 8.5.15 on the 8.X branch, are subject to Improper Input Validation. Grafana admins can invite other members to the organization they are an admin for. When admins add members to the organization, non existing users get an email invite, existing members are added directly to the organization. When an invite link is sent, it allows users to sign up with whatever username/email address the user chooses and become a member of the organization. This introduces a vulnerability which can be used with malicious intent. This issue is patched in version 9.2.4, and has been backported to 8.5.15. There are no known workarounds.

📖 Read

via "National Vulnerability Database".
CVE-2022-27674

Insufficient validation in the IOCTL input/output buffer in AMD ?Prof may allow an attacker to bypass bounds checks potentially leading to a Windows kernel crash resulting in denial of service.

📖 Read

via "National Vulnerability Database".
CVE-2022-39881

Improper input validation vulnerability for processing SIB12 PDU in Exynos modems prior to SMR Sep-2022 Release allows remote attacker to read out of bounds memory.

📖 Read

via "National Vulnerability Database".