NVD disclosure day

Published threat advisories for May 12, 2017

CVE advisoryKnown Exploit

CVE-2017-0263

Microsoft Win32k Local Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Microsoft Windows kernel-mode drivers allows local users to gain elevated privileges by running a crafted application. This impacts affected Windows operating systems by enabling attackers with existing local access to increase their control over a system, potentially leading to unauthorized data acc

• CISA KEV

CVE advisoryKnown Exploit

CVE-2017-0262

Microsoft Office Memory Handling Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Microsoft Office has a memory handling vulnerability that could allow unauthorized code execution. This impacts organizations using affected versions of Office by potentially compromising systems and data. The realistic business risk involves attackers gaining control through user interaction with malicious files.

• CISA KEV