Monthly Patches are out for Microsoft, Adobe, and Fortinet. New Alerts for Apple, Citrix, Google Chrome, HTTP/2 (Exploits), Samba, cURL, and Linux.
Microsoft Exploit
Microsoft Monthly Patches include 103 fixes, 12 are rated Critical and 3 are actively exploited. One is a fix for the HTTP/2 Rapid Reset DDoS vulnerability. Highest CVSSv3 score of 9.8
More info. And here. And here.
Apple has published updates for iOS and iPadOS 16.7.1
More info.
Adobe has published Monthly Patches with security updates for Bridge, Commerce, and Photoshop. Highest CVSSv3 score of 8.8
More info.
Multiple vulnerabilities have been discovered in NetScaler ADC and NetScaler Gateway. Highest CVSSv3 score of 9.4
More info.
Google has published updates for Chrome for Desktop that include 20 security fixes, at least one of which is rated Critical.
More info.
Microsoft is aware. More info.
A DoS vulnerability in the HTTP/2 protocol known as Rapid Reset has been exploited in the wild August 2023 through October 2023.
More info. And here. And here. And here.
Several vulnerabilities have been patched in Samba, two of which could allow a DoS on the AD DC.
More info.
A security vulnerability in the cURL tool and libcurl library enables a heap-based buffer overflow during the SOCKS5 proxy handshake, potentially allowing a remote attacker RCE.
More info. And here.
Fortinet has published 25 new bulletins identifying vulnerabilities in their products.
More info.
Multiple OS command injection vulnerabilities in FortiWLM may allow a remote attacker to execute unauthorized commands via specifically crafted http get request parameters. CVSSv3 score of 9.6
More info.
An insufficient session expiration vulnerability in FortiEDR may allow a remote attacker to reuse the unexpired user API access token to gain privileges. CVSSv3 score of 7.7
More info.
An OS Command vulnerability in FortiSIEM supervisor may allow a remote attacker to execute unauthorized commands via crafted API requests. CVSSv3 score of 9.6
More info.
A use after free vulnerability in FortiOS & FortiProxy may allow a remote attacker to crash the Web Proxy process via multiple crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection. CVSSv3 score of 4.8
More info.
An interpretation conflict vulnerability in FortiOS IPS Engine may allow a remote attacker to evade NGFW policies or IPS Engine protection via crafted TCP packets. CVSSv3 score of 6.7
More info.
SUSE has updated the kernel. More info.
Red Hat has updated the kernel. More info.
Ubuntu has updated the kernel. More info.