Security
Headlines
HeadlinesLatestCVEs

Tag

#windows

CVE-2023-23419

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability

CVE
#vulnerability#windows
CVE-2023-23420

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-23422

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-23421

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-24859

Windows Internet Key Exchange (IKE) Extension Denial of Service Vulnerability

CVE-2023-23423

Windows Kernel Elevation of Privilege Vulnerability

CVE-2023-1391: Online Tours & Travels Management System ab.php unrestricted upload_Dwayne_Wade的博客-CSDN博客

A vulnerability, which was classified as problematic, was found in SourceCodester Online Tours & Travels Management System 1.0. Affected is an unknown function of the file admin/ab.php. The manipulation of the argument img leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-222978 is the identifier assigned to this vulnerability.

Microsoft Mitigates Outlook Elevation of Privilege Vulnerability

May 9, 2023 update: Releases for Microsoft Products has been updated with the release of CVE-2023-29324 - Security Update Guide - Microsoft - Windows MSHTML Platform Security Feature Bypass Vulnerability March 24, 2023 update: Impact Assessment has been updated to a link to Guidance for investigating attacks using CVE-2023-23397 - Microsoft Security Blog.

Microsoft Mitigates Outlook Elevation of Privilege Vulnerability

Summary Summary Microsoft Threat Intelligence discovered limited, targeted abuse of a vulnerability in Microsoft Outlook for Windows that allows for new technology LAN manager (NTLM) credential theft. Microsoft has released CVE-2023-23397 to address the critical elevation of privilege (EoP) vulnerability affecting Microsoft Outlook for Windows. We strongly recommend all customers update Microsoft Outlook for Windows to remain secure.

Talos uncovers espionage campaigns targeting CIS countries, Turkey, and European institutions including Embassies and a critical EU Health care Agency

Cisco Talos has identified a new espionage oriented threat actor, which we are naming “YoroTrooper,” targeting a multitude of entities in Europe and Turkey.