πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-21779 β€Ό

Visual Studio Code Remote Code Execution.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38105 β€Ό

An information disclosure vulnerability exists in the cm_processREQ_NC opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. A specially-crafted network packets can lead to a disclosure of sensitive information. An attacker can send a network request to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21767 β€Ό

Windows Overlay Filter Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21681 β€Ό

Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21748 β€Ό

Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21675, CVE-2023-21747, CVE-2023-21749, CVE-2023-21750, CVE-2023-21754, CVE-2023-21755, CVE-2023-21772, CVE-2023-21773, CVE-2023-21774.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21728 β€Ό

Windows Netlogon Denial of Service Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21733 β€Ό

Windows Bind Filter Driver Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21725 β€Ό

Windows Malicious Software Removal Tool Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21546 β€Ό

Windows Layer 2 Tunneling Protocol (L2TP) Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21543, CVE-2023-21555, CVE-2023-21556, CVE-2023-21679.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21539 β€Ό

Windows Authentication Remote Code Execution Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-35401 β€Ό

An authentication bypass vulnerability exists in the get_IFTTTTtoken.cgi functionality of Asus RT-AX82U 3.0.0.4.386_49674-ge182230. A specially-crafted HTTP request can lead to full administrative access to the device. An attacker would need to send a series of HTTP requests to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21732 β€Ό

Microsoft ODBC Driver Remote Code Execution Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21776 β€Ό

Windows Kernel Information Disclosure Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21760 β€Ό

Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21678, CVE-2023-21765.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21739 β€Ό

Windows Bluetooth Driver Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21771 β€Ό

Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21735 β€Ό

Microsoft Office Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21734.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38393 β€Ό

A denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. A specially-crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21730 β€Ό

Microsoft Cryptographic Services Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21551, CVE-2023-21561.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36441 β€Ό

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use several other applications that are restricted by the admin.

πŸ“– Read

via "National Vulnerability Database".
⚠ Popular JWT cloud security library patches β€œremote” code execution hole ⚠

It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.

πŸ“– Read

via "Naked Security".
πŸ‘Ž1