NVD disclosure day

Published threat advisories for July 14, 2015

CVE advisoryKnown Exploit

CVE-2015-2387

Microsoft Font Driver Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory corruption vulnerability in the Adobe Type Manager Font Driver affects various Microsoft Windows operating systems, allowing local users to gain elevated privileges by running a crafted application. This poses a business risk by enabling unauthorized access and control over sensitive data and systems. organiza

• CISA KEV

CVE advisoryKnown Exploit

CVE-2015-2424

Microsoft Office Document Handling Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Microsoft Office applications are susceptible to a memory corruption vulnerability that could allow attackers to execute arbitrary code or cause a denial of service via a crafted document. This poses a business risk if employees open malicious files. Organizations should address this by applying vendor security updates

• CISA KEV

CVE advisoryKnown Exploit

CVE-2015-5123

Adobe Flash Player Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Adobe Flash Player could permit attackers to execute code or disrupt services through malicious content. Organizations utilizing this software face a business risk of unauthorized code execution or denial of service. The affected product is end-of-life and should be disconnected.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2015-5122

Adobe Flash Player Code Execution Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Adobe Flash Player could permit attackers to execute arbitrary code or cause denial-of-service by exploiting memory corruption. This impacts organizations using affected versions, posing a risk to system integrity and data. The vulnerability has been observed in the wild.

• CISA KEV