Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

Microsoft Zero-Day Bugs Allow Security Feature Bypass

Security vendors urge organizations to fix the actively exploited bugs, in Microsoft Outlook and the Mark of the Web feature, immediately.

DARKReading
#vulnerability#web#mac#windows#microsoft#rce#auth#zero_day
Microsoft Patch Tuesday for March 2023 — Snort rules and prominent vulnerabilities

Microsoft disclosed 83 vulnerabilities across the company’s hardware and software line, including two issues that are actively being exploited in the wild, continuing a trend of zero-days appearing in Patch Tuesdays over the past few months.

CISA Trials Ransomware Warning System for Critical Infrastructure Orgs

An agency team will identify vulnerabilities being exploited by ransomware groups and alert organizations ahead of attacks, CISA says.

Access Control Gap in Microsoft Active Directory Widens Enterprise Attack Surface

One researcher thinks trust is broken in AD. Microsoft disagrees that there's a security vulnerability. But enterprise IT environments should be aware of an authentication gap either way.

CVE-2023-23397

Microsoft Outlook Elevation of Privilege Vulnerability

CVE-2023-23413

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

CVE-2023-23396

Microsoft Excel Denial of Service Vulnerability

CVE-2023-23398

Microsoft Excel Spoofing Vulnerability

CVE-2023-24892

Microsoft Edge (Chromium-based) Webview2 Spoofing Vulnerability

CVE-2023-24913

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability