⚠ Patch Tuesday fixes 4 critical RCE bugs, and a bunch of Office holes ⚠
📖 Read
via "Naked Security".
No zero-days this month, if you ignore the Edge RCE hole patched last week📖 Read
via "Naked Security".
Sophos News
Naked Security – Sophos News
‼ CVE-2023-31142 ‼
📖 Read
via "National Vulnerability Database".
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, if a site has modified their general category permissions, they could be set back to the default. This issue is patched in version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches. A workaround, only if you are modifying the general category permissions, is to use a new category for the same purpose.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32301 ‼
📖 Read
via "National Vulnerability Database".
Discourse is an open source discussion platform. Prior to version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches, multiple duplicate topics could be created if topic embedding is enabled. This issue is patched in version 3.0.4 of the `stable` branch and version 3.1.0.beta5 of the `beta` and `tests-passed` branches. As a workaround, disable topic embedding if it has been enabled.📖 Read
via "National Vulnerability Database".
🛠 AIDE 0.18.4 🛠
📖 Read
via "Packet Storm Security".
AIDE (Advanced Intrusion Detection Environment) is a free replacement for Tripwire(tm). It generates a database that can be used to check the integrity of files on server. It uses regular expressions for determining which files get added to the database. You can use several message digest algorithms to ensure that the files have not been tampered with.📖 Read
via "Packet Storm Security".
Packetstormsecurity
AIDE 0.18.4 ≈ Packet Storm
Information Security Services, News, Files, Tools, Exploits, Advisories and Whitepapers
👍1
‼ CVE-2023-29357 ‼
📖 Read
via "National Vulnerability Database".
Microsoft SharePoint Server Elevation of Privilege Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29364 ‼
📖 Read
via "National Vulnerability Database".
Windows Authentication Elevation of Privilege Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29366 ‼
📖 Read
via "National Vulnerability Database".
Windows Geolocation Service Remote Code Execution Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-24938 ‼
📖 Read
via "National Vulnerability Database".
Windows CryptoAPI Denial of Service Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29353 ‼
📖 Read
via "National Vulnerability Database".
Sysinternals Process Monitor for Windows Denial of Service Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32010 ‼
📖 Read
via "National Vulnerability Database".
Windows Bus Filter Driver Elevation of Privilege Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32011 ‼
📖 Read
via "National Vulnerability Database".
Windows iSCSI Discovery Service Denial of Service Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29372 ‼
📖 Read
via "National Vulnerability Database".
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32032 ‼
📖 Read
via "National Vulnerability Database".
.NET and Visual Studio Elevation of Privilege Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32017 ‼
📖 Read
via "National Vulnerability Database".
Microsoft PostScript Printer Driver Remote Code Execution Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-32015 ‼
📖 Read
via "National Vulnerability Database".
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29363 ‼
📖 Read
via "National Vulnerability Database".
Windows Pragmatic General Multicast (PGM) Remote Code Execution Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29367 ‼
📖 Read
via "National Vulnerability Database".
iSCSI Target WMI Provider Remote Code Execution Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-29355 ‼
📖 Read
via "National Vulnerability Database".
DHCP Server Service Information Disclosure Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-3198 ‼
📖 Read
via "National Vulnerability Database".
The MStore API plugin for WordPress is vulnerable to Cross-Site Request Forgery due to missing nonce validation on the mstore_update_status_order_message function. This makes it possible for unauthenticated attackers to update status order message via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.📖 Read
via "National Vulnerability Database".
‼ CVE-2023-33145 ‼
📖 Read
via "National Vulnerability Database".
Microsoft Edge (Chromium-based) Information Disclosure Vulnerability📖 Read
via "National Vulnerability Database".
‼ CVE-2023-33144 ‼
📖 Read
via "National Vulnerability Database".
Visual Studio Code Spoofing Vulnerability📖 Read
via "National Vulnerability Database".