NVD disclosure day

Published threat advisories for January 14, 2020

CVE advisoryKnown Exploit

CVE-2020-0646

Microsoft .NET Framework Remote Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A remote code execution vulnerability in the Microsoft .NET Framework allows attackers to run arbitrary code. This impacts organizations using affected .NET Framework components, posing a risk of unauthorized system access and control. Attackers can exploit improper input validation to compromise systems, leading to po

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-0638

Microsoft Update Notification Manager Elevation of Privilege.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

An elevation of privilege vulnerability exists in the Update Notification Manager that allows an attacker with prior system access to gain higher-level control. This poses a business risk of unauthorized data access and operational disruption. Affected systems include specific versions of Windows 10 and Windows Server.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-0601

Microsoft Windows CryptoAPI Spoofing Vulnerability Advisory

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows CryptoAPI allows attackers to disguise malicious software as legitimate by using spoofed digital certificates. This impacts organizations by enabling the execution of unauthorized code, potentially leading to data breaches and system disruptions. The realistic business risk involves compromis

• CISA KEV