NVD disclosure day

Published threat advisories for March 17, 2017

CVE advisoryKnown Exploit

CVE-2017-3881

Cisco IOS/XE: Remote Code Execution via Cluster Management Protocol

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Cisco IOS and IOS XE Software's Cluster Management Protocol could allow an unauthenticated, remote attacker to execute code with elevated privileges or cause a device reload. This impacts various Cisco Catalyst and industrial Ethernet switches. The business risk involves potential device compromise,

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0149

Microsoft Internet Explorer Code Execution Risk.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

Microsoft Internet Explorer contains a memory corruption vulnerability that permits remote attackers to execute arbitrary code or cause a denial of service via a crafted website. The realistic business risk involves unauthorized code execution and system instability impacting affected organizations and their data.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0147

Windows SMB Information Disclosure Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the Windows SMBv1 server allows remote attackers to obtain sensitive information from system memory, posing a risk of confidential data disclosure. Organizations should identify affected systems and apply necessary updates to mitigate potential business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0146

Microsoft Windows SMB Vulnerability Allows Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Microsoft's Server Message Block version 1 (SMBv1) allows remote attackers to execute arbitrary code. This could lead to unauthorized control of affected systems, posing a risk to organizational data and operations. Organizations should identify and mitigate exposure to SMBv1.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0143

Microsoft Windows SMB Remote Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in Microsoft's Server Message Block protocol allows remote attackers to execute arbitrary code. This could lead to unauthorized access and control over affected systems, posing a significant business risk. Organizations should prioritize addressing this vulnerability to mitigate potential data loss and

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0101

Windows Privilege Escalation via Transaction Manager Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows Transaction Manager allows local users to gain elevated privileges via a crafted application. This impacts affected Windows systems, potentially leading to unauthorized access and control, affecting data integrity and system availability. The realistic business risk involves unauthorized syst

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0059

Microsoft Internet Explorer Information Disclosure Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Microsoft Internet Explorer versions 9 through 11 have a vulnerability allowing remote attackers to access sensitive information from process memory via a crafted website. This exposes organizations to business risk if confidential data is disclosed. This vulnerability is listed on the CISA Known Exploited Vulnerabilit

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0022

Microsoft XML Core Services Information Disclosure Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Microsoft XML Core Services could allow attackers to discover files on a system. This matters because it could enable attackers to test for files on disk via a crafted website, posing a risk of information disclosure. Organizations should apply vendor updates to mitigate this risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0005

Microsoft Windows GDI Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Local users can gain elevated privileges on affected Windows systems by running a malicious application. This can lead to unauthorized access and control over the system, impacting data and operations. The risk is to systems with potential for unauthorized local access.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0001

Microsoft Windows GDI Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Microsoft Windows' Graphics Device Interface allows local users to gain elevated privileges through a crafted application. This could impact systems and data by enabling unauthorized control. Affected organizations should apply vendor security updates to mitigate this risk.

• CISA KEV