Aggregator
Windows 11 KB5055523 & KB5055528 cumulative updates released
8 months 3 weeks ago
Microsoft has released Windows 11 KB5055523 and KB5055528 cumulative updates for versions 24H2 and 23H2 to fix security vulnerabilities and issues. [...]
Mayank Parmar
CVE-2025-20570 | Microsoft Visual Studio Code access control
8 months 3 weeks ago
A vulnerability was found in Microsoft Visual Studio Code. It has been declared as critical. This vulnerability affects unknown code. The manipulation leads to improper access controls.
This vulnerability was named CVE-2025-20570. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Hackers lurked in Treasury OCC’s systems since June 2023 breach
8 months 3 weeks ago
Unknown attackers who breached the Treasury's Office of the Comptroller of the Currency (OCC) in June 2023 gained access to over 150,000 emails. [...]
Sergiu Gatlan
CVE-2023-29359 | Microsoft Windows up to Server 2022 GDI input validation
8 months 3 weeks ago
A vulnerability was found in Microsoft Windows. It has been classified as critical. Affected is an unknown function of the component GDI. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2023-29359. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29361 | Microsoft Windows 10 21H2/10 22H2/11 21H2/11 22H2/Server 2022 Cloud Files Mini Filter Driver use after free
8 months 3 weeks ago
A vulnerability was found in Microsoft Windows 10 21H2/10 22H2/11 21H2/11 22H2/Server 2022. It has been rated as critical. Affected by this issue is some unknown functionality of the component Cloud Files Mini Filter Driver. The manipulation leads to use after free.
This vulnerability is handled as CVE-2023-29361. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29362 | Microsoft Windows up to Server 2022 Remote Desktop Client heap-based overflow
8 months 3 weeks ago
A vulnerability classified as critical has been found in Microsoft Windows. This affects an unknown part of the component Remote Desktop Client. The manipulation leads to heap-based buffer overflow.
This vulnerability is uniquely identified as CVE-2023-29362. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29363 | Microsoft Windows up to Server 2022 Pragmatic General Multicast heap-based overflow
8 months 3 weeks ago
A vulnerability classified as very critical was found in Microsoft Windows. This vulnerability affects unknown code of the component Pragmatic General Multicast. The manipulation leads to heap-based buffer overflow.
This vulnerability was named CVE-2023-29363. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29364 | Microsoft Windows up to Server 2022 Authentication integer overflow
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Microsoft Windows. This issue affects some unknown processing of the component Authentication. The manipulation leads to integer overflow.
The identification of this vulnerability is CVE-2023-29364. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29365 | Microsoft Windows up to Server 2022 Media use after free
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Microsoft Windows. Affected is an unknown function of the component Media. The manipulation leads to use after free.
This vulnerability is traded as CVE-2023-29365. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29368 | Microsoft Windows up to Server 2022 Filtering Platform double free
8 months 3 weeks ago
A vulnerability was found in Microsoft Windows. It has been classified as critical. This affects an unknown part of the component Filtering Platform. The manipulation leads to double free.
This vulnerability is uniquely identified as CVE-2023-29368. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29370 | Microsoft Windows up to Server 2022 Media heap-based overflow
8 months 3 weeks ago
A vulnerability was found in Microsoft Windows up to Server 2022. It has been rated as critical. This issue affects some unknown processing of the component Media. The manipulation leads to heap-based buffer overflow.
The identification of this vulnerability is CVE-2023-29370. Local access is required to approach this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29371 | Microsoft Windows up to Server 2022 GDI input validation
8 months 3 weeks ago
A vulnerability classified as critical has been found in Microsoft Windows. Affected is an unknown function of the component GDI. The manipulation leads to improper input validation.
This vulnerability is traded as CVE-2023-29371. Attacking locally is a requirement. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29372 | Microsoft Windows up to Server 2022 WDAC OLE DB Provider for SQL Server heap-based overflow
8 months 3 weeks ago
A vulnerability classified as critical was found in Microsoft Windows. Affected by this vulnerability is an unknown functionality of the component WDAC OLE DB Provider for SQL Server. The manipulation leads to heap-based buffer overflow.
This vulnerability is known as CVE-2023-29372. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-29373 | Microsoft Windows up to Server 2022 ODBC Driver out-of-bounds
8 months 3 weeks ago
A vulnerability, which was classified as critical, has been found in Microsoft Windows. Affected by this issue is some unknown functionality of the component ODBC Driver. The manipulation leads to out-of-bounds read.
This vulnerability is handled as CVE-2023-29373. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2023-32008 | Microsoft Windows up to Server 2022 Resilient File System null pointer dereference
8 months 3 weeks ago
A vulnerability, which was classified as critical, was found in Microsoft Windows up to Server 2022. This affects an unknown part of the component Resilient File System. The manipulation leads to null pointer dereference.
This vulnerability is uniquely identified as CVE-2023-32008. An attack has to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
美国货币监理署邮件系统遭入侵事件被形容为"惊人且严重"
8 months 3 weeks ago
"美金融监管机构遭严重入侵,15万邮件泄露!专家警告:国家网络安全亮红灯"
21 Countries Sign Onto Voluntary Pact to Stem the Proliferation of Spyware
8 months 3 weeks ago
Twenty-one countries signed onto the Pall Mall Process, an effort a year in the making that was created to develop a framework nations could adopt to address the proliferation and malicious use of spyware by governments that want it to track human rights workers, activists, journalists, and other such targets.
The post 21 Countries Sign Onto Voluntary Pact to Stem the Proliferation of Spyware appeared first on Security Boulevard.
Jeffrey Burt
Когда сегодня зависит от завтра: в современной Вселенной нашли отголоски конца света
8 months 3 weeks ago
Мы-то думали, время работает в одну сторону, а оно вон как обернулось…
ISCC线下如何配置代理攻击其他私地及高地
8 months 3 weeks ago
介绍如何进行流量转发