NVD disclosure day

Published threat advisories for March 5, 2019

CVE advisoryKnown Exploit

CVE-2019-0676

Internet Explorer Information Disclosure Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An information disclosure vulnerability in Internet Explorer allows attackers to test for the presence of files on disk. This could expose sensitive data, increasing business risk related to data confidentiality. Organizations using affected versions of Internet Explorer are impacted.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-0604

Microsoft SharePoint Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A remote code execution vulnerability in Microsoft SharePoint allows attackers to run arbitrary code. This can impact affected SharePoint applications, leading to potential business data compromise and service disruption. The risk to business operations is significant due to the potential for unauthorized access.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-6223

Apple FaceTime Logic Flaw Impacts Call Recipients.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A logic flaw in Group FaceTime calls could allow an attacker to cause a recipient's device to answer the call. This impacts Apple iOS and macOS systems, potentially exposing audio data and user privacy. Organizations should apply vendor updates to mitigate this risk.

• CISA KEV