NVD disclosure day

Published threat advisories for September 11, 2019

CVE advisoryKnown Exploit

CVE-2019-1297

Microsoft Excel Remote Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Microsoft Excel can allow attackers to execute malicious code remotely. This matters to organizations as it could lead to unauthorized access, data modification, or system compromise. The realistic business risk involves potential disruption and loss of control over affected systems.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2019-1253

Windows Elevation of Privilege Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An elevation of privilege vulnerability exists when the Windows AppX Deployment Server improperly handles junctions. An attacker with existing execution on a system could exploit this to gain higher permissions. This poses a business risk to affected Windows systems.

• CISA KEV