Content Modification: Updates for Kev Content published 2024-09-16 (8)

Total New Fixlets: 8
Total Updated Fixlets: 1711
Total Fixlets in Site: 2577
Total CVEs Covered: 743
Release Date: 2024-09-16

Updated Fixlets (most updates are minor data additions done by CISA that are refected here) :

13950    Microsoft Windows Win32k Privilege Escalation Vulnerability - Windows 11 
5760    Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability - Windows 10 
30340    Microsoft Windows Error Reporting Service Improper Privilege Management Vulnerability - Windows 11 
13960    Microsoft Windows Print Spooler Privilege Escalation Vulnerability - Windows 11 
5770    Microsoft Windows Print Spooler Remote Code Execution Vulnerability - Windows 10 
30350    Roundcube Webmail Cross-Site Scripting (XSS) Vulnerability - Any Operating System 
22160    Microsoft Internet Explorer ASLR Bypass Vulnerability - Windows 8 Gold 
13970    Microsoft Win32k Privilege Escalation Vulnerability - Windows 11 
5780    Microsoft Windows Error Reporting (WER) Privilege Escalation Vulnerability - Windows 10 
30360    Microsoft Word Malformed Object Pointer Vulnerability - Word 2003 Viewer 
22170    Microsoft Win32k Privilege Escalation Vulnerability - Windows 8 Gold 
13980    Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability - Windows 11 
5790    Microsoft Edge and Internet Explorer Type Confusion Vulnerability - Windows 10 
13990    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability - Windows 11 
5800    Microsoft Graphics Device Interface (GDI) Privilege Escalation Vulnerability - Windows 10 
22190    Microsoft Internet Explorer Use-After-Free Vulnerability - Windows 8 Gold 
14000    Microsoft Windows User Profile Service Privilege Escalation Vulnerability - Windows 11 
5810    Microsoft SMBv1 Remote Code Execution Vulnerability - Windows 10 
30390    Linux Kernel Use-After-Free Vulnerability - Debian 
22200    Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability - Windows 8 Gold 
14010    Microsoft Windows CLFS Driver Privilege Escalation Vulnerability - Windows 11 
5820    Microsoft Windows Graphics Device Interface (GDI) Remote Code Execution Vulnerability - Windows 10 
30400    OSGeo GeoServer JAI-EXT Code Injection Vulnerability - Any Operating System 
22210    Microsoft Internet Explorer Use-After-Free Vulnerability - Windows 8 Gold 
14020    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability - Windows 11 
5830    Microsoft Internet Explorer Privilege Escalation Vulnerability - Windows 10 
30410    Microsoft Office OLE DLL Side Loading Vulnerability - Visio 
22220    Microsoft Internet Explorer Memory Corruption Vulnerability - Windows 8 Gold 
14030    Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability - Windows 11 
5840    Microsoft Desktop Window Manager (DWM) Core Library Privilege Escalation Vulnerability - Windows 10 
30420    Microsoft Office OLE DLL Side Loading Vulnerability - Visio Viewer 
14040    Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability - Windows 11 
5850    Microsoft HTTP Protocol Stack Remote Code Execution Vulnerability - Windows 10 
30430    Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability - Commerce Server 
22240    Microsoft Win32k Privilege Escalation Vulnerability - Windows 8 Gold 
5860    Microsoft Windows SMBv1 Information Disclosure Vulnerability - Windows 10 
30440    Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability - SQL Server 
5870    Microsoft Windows Adobe Font Manager Library Remote Code Execution Vulnerability - Windows 10 
30450    Linux Kernel Use-After-Free Vulnerability - SLE 
5880    Microsoft Win32k Privilege Escalation Vulnerability - Windows 10 
22270    Microsoft Internet Explorer Privilege Escalation Vulnerability - Windows 8 Gold 
5890    Microsoft Win32k Privilege Escalation Vulnerability - Windows 10 
30470    Linux Kernel Use-After-Free Vulnerability - RHEL 
22280    Microsoft Internet Explorer Use-After-Free Vulnerability - Windows 8 Gold 
14090    Cacti Command Injection Vulnerability - Any Operating System 
30480    Microsoft Windows CLFS Driver Privilege Escalation Vulnerability - Windows Server 2008 R2 
22290    Microsoft Internet Explorer Privilege Escalation Vulnerability - Windows 8 Gold 
5910    Microsoft Windows Print Spooler Privilege Escalation Vulnerability - Windows 10 
30490    Microsoft Windows User Profile Service Privilege Escalation Vulnerability - Windows Server 2008 R2 
22300    Microsoft Win32k Privilege Escalation Vulnerability - Windows 8 Gold 
5920    Microsoft Win32k Privilege Escalation Vulnerability - Windows 10 
22310    Microsoft ATM Font Driver Privilege Escalation Vulnerability - Windows 8 Gold 
5930    Microsoft SMBv1 Server Remote Code Execution Vulnerability - Windows 10 
30510    Microsoft Windows Print Spooler Privilege Escalation Vulnerability - Windows Server 2008 R2 
5940    Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability - Windows 10 
30520    Microsoft WordPad Information Disclosure Vulnerability - Windows Server 2008 R2 
22330    Microsoft Windows Remote Code Execution Vulnerability - Windows 8 Gold 
14140    Cisco AnyConnect Secure Mobility Client for Windows DLL Hijacking Vulnerability - Any Version of Windows 
30530    Microsoft Windows SmartScreen Security Feature Bypass Vulnerability - Windows Server 2008 R2 
22340    Microsoft Internet Explorer Memory Corruption Vulnerability - Windows 8 Gold 
5960    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability - Windows 10 
30540    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability - Windows Server 2008 R2 
14160    InduSoft Web Studio NTWebServer Directory Traversal Vulnerability - Any Version of Windows 
30550    Microsoft Windows LSA Spoofing Vulnerability - Windows Server 2008 R2 
5980    Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability - Windows 10 
30560    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability - Windows Server 2008 R2 
22370    Microsoft Internet Explorer Memory Corruption Vulnerability - Windows 8 Gold 
14180    Microsoft Defender Remote Code Execution Vulnerability - Any Version of Windows 
30570    Microsoft Windows Print Spooler Privilege Escalation Vulnerability - Windows Server 2008 R2 
6000    Microsoft Win32k Privilege Escalation Vulnerability - Windows 10 
30580    Microsoft Windows Cloud Files Mini Filter Driver Privilege Escalation Vulnerability - Windows Server 2008 R2 
6010    Microsoft Windows Spoofing Vulnerability - Windows 10 
30590    Microsoft Windows MSHTML Platform Privilege Escalation Vulnerability - Windows Server 2008 R2 
22400    Microsoft Internet Explorer Memory Corruption Vulnerability - Windows 8 Gold 
14210    Microsoft Malware Protection Engine Improper Restriction of Operations Vulnerability - Any Version of Windows 
6020    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability - Windows 10 
30600    Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability - Windows Server 2008 R2 
6030    Microsoft Windows Privilege Common Log File System (CLFS) Escalation Vulnerability - Windows 10 
30610    Microsoft Windows COM+ Event System Service Privilege Escalation Vulnerability - Windows Server 2008 R2 
6040    Microsoft Windows Event Tracing Privilege Escalation Vulnerability - Windows 10 
30620    Microsoft Windows Print Spooler Privilege Escalation Vulnerability - Windows Server 2008 R2 
6050    Microsoft Windows Mark of the Web (MOTW) Security Feature Bypass Vulnerability - Windows 10 
30630    Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability - Windows Server 2008 R2 
6060    Microsoft Task Scheduler Privilege Escalation Vulnerability - Windows 10 
30640    Microsoft Windows Scripting Languages Remote Code Execution Vulnerability - Windows Server 2008 R2 
6070    Microsoft Windows AppX Deployment Service (AppXSVC) Privilege Escalation Vulnerability - Windows 10 
30650    Microsoft Win32k Privilege Escalation Vulnerability - Windows Server 2008 R2 
14270    Atlassian Confluence Server and Data Center Remote Code Execution Vulnerability - Any Operating System 
30660    Microsoft Windows Error Reporting Service Privilege Escalation Vulnerability - Windows Server 2008 R2 
6090    Microsoft Windows Privilege Escalation Vulnerability - Windows 10 
30670    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability - Windows Server 2008 R2 
22480    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability - Windows 11 
14290    WordPress File Manager Plugin Remote Code Execution Vulnerability - Any Operating System 
6100    Microsoft Windows Kernel Privilege Escalation Vulnerability - Windows 10 
30680    Microsoft Windows Search Remote Code Execution Vulnerability - Windows Server 2008 R2 
6110    Microsoft .NET Framework Remote Code Execution Vulnerability - Windows 10 
30690    Microsoft Windows Client Server Runtime Subsystem (CSRSS) Privilege Escalation Vulnerability - Windows Server 2008 R2 
6120    Microsoft Win32k Privilege Escalation Vulnerability - Windows 10 
30700    Microsoft Windows Graphic Component Privilege Escalation Vulnerability - Windows Server 2008 R2 
14320    dotCMS Unrestricted Upload of File Vulnerability - Any Operating System 
6130    Microsoft Windows Error Reporting Manager Privilege Escalation Vulnerability - Windows 10 
30710    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability - Windows Server 2008 R2 
14330    Atlassian Confluence Server Pre-Authorization Arbitrary File Read Vulnerability - Any Operating System 
6140    Microsoft Windows SMB Information Disclosure Vulnerability - Windows 10 
30720    Microsoft Silverlight Information Disclosure Vulnerability - Silverlight 5 
6150    Microsoft Windows MSHTML Platform Remote Code Execution Vulnerability - Windows 10 
30730    Microsoft Silverlight Double Dereference Vulnerability - Silverlight 5 
14350    ThinkPHP "noneCms" Remote Code Execution Vulnerability - Any Operating System 
6160    Microsoft Active Directory Domain Services Privilege Escalation Vulnerability - Windows 10 
30740    Microsoft Silverlight Runtime Remote Code Execution Vulnerability - Silverlight 5 
6170    Microsoft Internet Explorer Information Disclosure Vulnerability - Windows 10 
6180    Microsoft Win32k Privilege Escalation Vulnerability - Windows 10 
30760    Microsoft Skype for Business Privilege Escalation Vulnerability - Skype for Business Server 
22570    Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability - Any Version of Windows 
6190    Microsoft Windows Background Intelligent Transfer Service (BITS) Improper Privilege Management Vulnerability - Windows 10 
30770    Microsoft SharePoint Server Privilege Escalation Vulnerability - SharePoint 
14390    Atlassian Confluence Server and Data Center Object-Graph Navigation Language (OGNL) Injection Vulnerability - Any Operating System 
6200    Microsoft Windows CNG Key Isolation Service Privilege Escalation Vulnerability - Windows 10 
30780    Microsoft .NET Framework, SharePoint, and Visual Studio Remote Code Execution Vulnerability - SharePoint 
22590    Microsoft Excel Security Feature Bypass - Any Version of Windows 
6210    Microsoft Windows Privilege Escalation Vulnerability - Windows 10 
6220    Microsoft Win32k Privilege Escalation Vulnerability - Windows 10 
30800    Microsoft Word Memory Corruption Vulnerability - SharePoint 
6230    Microsoft Update Notification Manager Privilege Escalation Vulnerability - Windows 10 
30810    Microsoft Word Remote Code Execution Vulnerability - SharePoint 
22620    Microsoft Office Access Connectivity Engine Remote Code Execution Vulnerability - Any Version of Windows 
6240    Microsoft Win32k Privilege Escalation Vulnerability - Windows 10 
30820    Microsoft Office Memory Corruption Vulnerability - SharePoint 
14440    Telerik UI for ASP.NET AJAX Insecure Direct Object Reference Vulnerability - Any Version of Windows 
6250    Microsoft Windows Print Spooler Privilege Escalation Vulnerability - Windows 10 
30830    Microsoft Office Object Record Corruption Vulnerability - SharePoint 
14450    Plex Media Server Remote Code Execution Vulnerability - Any Version of Windows 
6260    Microsoft Windows Installer Privilege Escalation Vulnerability - Windows 10 
30840    Microsoft Office Remote Code Execution Vulnerability - SharePoint 
6270    Microsoft Internet Explorer Memory Corruption Vulnerability - Windows 10 
30850    Microsoft SharePoint Server Code Injection Vulnerability - SharePoint 
30860    Microsoft Office Memory Corruption Vulnerability - SharePoint 
6290    Microsoft Windows Common Log File System (CLFS) Driver Privilege Escalation Vulnerability - Windows 10 
30870    Microsoft PowerPoint Memory Corruption Vulnerability - SharePoint 
22680    Zoho ManageEngine ADSelfService Plus Remote Code Execution Vulnerability - Any Version of Windows 
14490    Progress Telerik UI for ASP.NET AJAX and Sitefinity Cryptographic Weakness Vulnerability - Any Version of Windows 
6300    Microsoft Windows User Profile Service Privilege Escalation Vulnerability - Windows 10 
30880    Microsoft Forefront TMG Remote Code Execution Vulnerability - Forefront 
14500    Telerik UI for ASP.NET AJAX Unrestricted File Upload Vulnerability - Any Version of Windows 
6310    Microsoft Windows Server Message Block (SMBv1) Remote Code Execution Vulnerability - Windows 10 
30890    Microsoft Outlook Security Feature Bypass Vulnerability - Outlook 
6320    Microsoft Windows NTFS Privilege Escalation Vulnerability - Windows 10 
30900    Microsoft PowerPoint Buffer Overflow Vulnerability - Office 
14520    Microsoft XML Core Services Memory Corruption Vulnerability - Windows Vista SP2 
6330    Microsoft Windows Privilege Escalation Vulnerability - Windows 10 
30910    Microsoft Office Remote Code Execution Vulnerability - Word Viewer 
22720    Zoho ManageEngine Multiple Products Remote Code Execution Vulnerability - Any Version of Linux 
14530    Microsoft XML Core Services Memory Corruption Vulnerability - Windows Server 2008 SP2 
6340    Microsoft Windows Privilege Escalation Vulnerability - Windows 10 
30920    Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability - Commerce Server 
6350    Microsoft Enhanced Cryptographic Provider Privilege Escalation Vulnerability - Windows 10 
30930    Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability - Visual FoxPro 
6360    Microsoft Windows SMB Remote Code Execution Vulnerability - Windows 10 
30940    Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability - Visual Basic 6.0 
6370    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability - Windows 10 
30950    Microsoft MSCOMCTL.OCX Remote Code Execution Vulnerability - Visual Basic 6.0 
14570    Microsoft XML Core Services Memory Corruption Vulnerability - Windows 7 
30960    Microsoft Office MSCOMCTL.OCX Remote Code Execution Vulnerability - SQL Server 
14580    Microsoft XML Core Services Memory Corruption Vulnerability - Windows Server 2008 R2 
6390    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability - Windows 10 
30970    Microsoft Windows Authenticode Signature Verification Remote Code Execution Vulnerability - Windows 7 
6400    Microsoft Internet Explorer Scripting Engine Memory Corruption Vulnerability - Windows 10 
30980    Microsoft XML Core Services Memory Corruption Vulnerability - Microsoft XML Core Services 4.0 
6410    Microsoft Windows CLFS Driver Privilege Escalation Vulnerability - Windows 10 
30990    Microsoft XML Core Services Memory Corruption Vulnerability - Microsoft XML Core Services 6.0

This topic was automatically closed after 30 days. New replies are no longer allowed.