NVD disclosure day

Published threat advisories for April 15, 2020

CVE advisoryKnown Exploit

CVE-2020-3161

Cisco IP Phones Web Server Vulnerability Leads to Code Execution

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A vulnerability in the web server of Cisco IP Phones allows unauthenticated remote attackers to execute code with root privileges or cause a denial of service. This impacts organizations by potentially compromising voice network devices. Business risk includes unauthorized access and service interruption.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-1027

Windows Kernel Elevation of Privilege Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A Windows Kernel vulnerability allows unauthorized privilege escalation, impacting system control and data integrity. Local attackers can execute code with elevated permissions. Organizations should apply vendor updates to mitigate this risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-0938

Microsoft Windows Font Library Remote Code Execution Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Adobe Type Manager Library allows remote code execution via crafted font files. This poses a risk to system integrity and confidentiality. Affected organizations should identify and remediate systems.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-2883

Oracle WebLogic Server Network Access Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An unauthenticated attacker with network access can compromise Oracle WebLogic Server. Successful attacks can lead to a complete takeover of the server, impacting data confidentiality, integrity, and availability. This poses a significant business risk due to the potential for extensive data breaches and operational di

• CISA KEV