Skip to main content

CND News and Blog

New Vulnerabilities Wednesday 11 October


Monthly Patches are out for Microsoft, Adobe, and Fortinet. New Alerts for Apple, Citrix, Google Chrome, HTTP/2 (Exploits), Samba, cURL, and Linux.

Microsoft Exploit

Microsoft Monthly Patches include 103 fixes, 12 are rated Critical and 3 are actively exploited. One is a fix for the HTTP/2 Rapid Reset DDoS vulnerability. Highest CVSSv3 score of 9.8
More info. And here. And here.

Adobe 

Apple has published updates for iOS and iPadOS 16.7.1
More info.

Apple 

Adobe has published Monthly Patches with security updates for Bridge, Commerce, and Photoshop. Highest CVSSv3 score of 8.8
More info.

Citrix 

Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway. Highest CVSSv3 score of 9.4
More info.

Google 

Google has published updates for Chrome for Desktop that include 20 security fixes, at least one of which is rated Critical.
More info.

Microsoft is aware. More info.

HTTP/2 Exploit

A DoS vulnerability in the HTTP/2 protocol known as Rapid Reset has been exploited in the wild August 2023 through October 2023.
More info. And here. And here. And here.

Samba 

Several vulnerabilities have been patched in Samba, two of which could allow a DoS on the AD DC.
More info.

cURL 

A security vulnerability in the cURL tool and libcurl library enables a heap-based buffer overflow during the SOCKS5 proxy handshake, potentially allowing a remote attacker RCE.
More info. And here.

Fortinet 

Fortinet has published 25 new bulletins identifying vulnerabilities in their products.
More info.

Multiple OS command injection vulnerabilities in FortiWLM may allow a remote attacker to execute unauthorized commands via specifically crafted http get request parameters. CVSSv3 score of 9.6
More info.

An insufficient session expiration vulnerability in FortiEDR may allow a remote attacker to reuse the unexpired user API access token to gain privileges. CVSSv3 score of 7.7
More info.
An OS Command vulnerability in FortiSIEM supervisor may allow a remote attacker to execute unauthorized commands via crafted API requests. CVSSv3 score of 9.6
More info.

A use after free vulnerability in FortiOS & FortiProxy may allow a remote attacker to crash the Web Proxy process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection. CVSSv3 score of 4.8
More info.

An interpretation conflict vulnerability in FortiOS IPS Engine may allow a remote attacker to evade NGFW policies or IPS Engine protection via crafted TCP packets. CVSSv3 score of 6.7
More info.

Linux 

SUSE has updated the kernel. More info.
Red Hat has updated the kernel. More info.
Ubuntu has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Friday, 03 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/