Security
Headlines
HeadlinesLatestCVEs

Tag

#microsoft

Microsoft Patch Tuesday March 2022

Hello everyone! I am glad to greet you from the most sanctioned country in the world. Despite all the difficulties, we carry on. I even have some time to release new episodes. This time it will be about Microsoft Patch Tuesday for March 2022. Alternative video link (for Russia): https://vk.com/video-149273431_456239076 I do the analysis as […]

Alexander V. Leonov
#microsoft#blog
CVE-2021-42262: OPC and OPC UA | Softing

An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.

CVE-2021-42577

An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.

CVE-2022-26355: Citrix Federated Authentication Service (FAS) Security Update

Citrix Federated Authentication Service (FAS) 7.17 - 10.6 causes deployments that have been configured to store a registration authority certificate's private key in a Trusted Platform Module (TPM) to incorrectly store that key in the Microsoft Software Key Storage Provider (MSKSP). This issue only occurs if PowerShell was used when configuring FAS to store the registration authority certificate’s private key in the TPM. It does not occur if the TPM was not selected for use or if the FAS administration console was used for configuration.

CVE-2022-24509

Microsoft Office Visio Remote Code Execution Vulnerability

CVE-2022-24511

Microsoft Office Word Tampering Vulnerability

CVE-2022-24510

Microsoft Office Visio Remote Code Execution Vulnerability

CVE-2022-23277

Microsoft Exchange Server Remote Code Execution Vulnerability.

CVE-2022-24511

Microsoft Office Word Tampering Vulnerability.

CVE-2022-24510

Microsoft Office Visio Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-24461, CVE-2022-24509.