NVD disclosure day

Published threat advisories for November 10, 2016

CVE advisoryKnown Exploit

CVE-2016-5195

Linux Kernel Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Linux kernel's memory handling can permit local users to gain elevated privileges. This impacts organizations by potentially allowing attackers with existing system access to modify sensitive data or disrupt operations. The business risk involves unauthorized system control and data compromise.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2016-7256

Microsoft Windows Font Library Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in the Windows font library allows attackers to execute arbitrary code through crafted web content. This could lead to unauthorized code execution and compromise of system integrity for organizations using vulnerable Windows versions. The business risk involves potential system compromise through malici

• CISA KEV

CVE advisoryKnown Exploit

CVE-2016-7255

Microsoft Win32k Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

This vulnerability affects Microsoft Windows kernel-mode drivers, allowing local users to gain elevated privileges via a crafted application. This matters because it can lead to unauthorized access to system data and resources, posing a business risk. The realistic risk involves attackers with local access potentially

• CISA KEV

CVE advisoryKnown Exploit

CVE-2016-7201

Microsoft Edge Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Microsoft Edge's scripting engine could allow attackers to execute arbitrary code or cause a denial of service via a crafted website. This impacts organizations by exposing systems to potential data compromise or operational disruption. The realistic business risk involves unauthorized code execution

• CISA KEV