Skip to main content

CND News and Blog

New Vulnerabilities Wednesday 12 July


Monthly Patches are out for Microsoft and Adobe. New Alerts for Fortinet, Technicolor, Rockwell Automation, and Linux.

It appears Apple pulled yesterday's RSR patch from the update servers.


Microsoft Exploit

Microsoft Monthly Patches are out, with 132 patched vulnerabilities, 9 rated Critical and 6 exploited in the wild. Highest CVSSv3 score of 9.8
More info. And here. And here.

Microsoft is investigating reports of a series of RCE vulnerabilities impacting Windows and Office products. Microsoft is aware of targeted attacks that attempt to exploit these vulnerabilities by using specially-crafted Microsoft Office documents. Only mitigations, an out-of-cycle fix is expected.
More info.

Adobe 

Adobe has published Monthly Patches for InDesign and ColdFusion. Highest CVSSv3 score of 9.8 (ColdFusion).
More info.

Fortinet 

Fortinet has published several new bulletins. Highest CVSSv3 score of 9.8
More info.

A stack-based overflow vulnerability in FortiOS and FortiProxy may allow a remote attacker to execute arbitrary code or command via crafted packets reaching proxy policies or firewall policies with proxy mode alongside SSL deep packet inspection. CVSSv3 score of 9.8
More info.

Technicolor 

Technicolor TG670 Router DSL Gateway Router contains more than one hard-coded service account. These particular accounts allow full administrative access to the device via the WAN interface.
More info.

Rockwell Automation 

RCE and DoS vulnerabilities exist in several communication modules. Highest CVSSv3 score of 9.8
More info.

The PowerMonitor 1000 contains stored XSS vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code by an attacker. CVSSv3 score of 8.8
More info.

Linux 

SUSE has updated the kernel. More info.
Oracle Linux has updated the kernel. More info.



Security Wizardry Cyber Threat Intelligence - The Mobile Radar Page

A mobile version of our Security Wizardry Radar Page, providing vulnerability details and visibility for a variety of software and industries.

SecurityWizardry.com - Vulnerability Details

Security Wizardry Radar Page provides vulnerability details and visibility for a variety of software and industries.

Report Print
×
Stay Informed

When you subscribe to the blog, we will send you an e-mail when there are new updates on the site so you wouldn't miss them.

 

Comments

No comments made yet. Be the first to submit a comment
Already Registered? Login Here
Saturday, 11 May 2024

Captcha Image

By accepting you will be accessing a service provided by a third-party external to https://www.cndltd.com/