By michele654 on Friday, 26 January 2024
Category: Vulnerabilities

New Vulnerabilities Friday 26 January


New Alerts for SystemK (Exploit), Microsoft Edge, Lexmark, GnuPG, and Linux.

SystemK Exploit

NVR 504/508/516 contains a command injection vulnerability that could allow a remote attacker to execute commands with root privileges. CVSSv3 score of 9.8
PoC exists. No response from vendor.
More info.

Microsoft 

Microsoft has updated Edge to correct the latest chromium fixes as well as 6 Edge-specific vulnerabilities.
More info.

Lexmark 

Lexmark printers contain several vulnerabilities in the PostScript interpreter taht allows a remote attacker to execute arbitrary code. Highest CVSSv3 score of 9
More info.

GnuPG 

When generating keys on a smartcard the encryption subkey may exist in an unprotected file on disk.
More info.

Linux 

Ubuntu has updated the kernel. More info.

Security Wizardry Cyber Threat Intelligence - The Radar Page

Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

SecurityWizardry.com - Vulnerability Details

Leave Comments