NVD disclosure day

Published threat advisories for June 9, 2020

CVE advisoryKnown Exploit

CVE-2020-0986

Microsoft Windows Kernel Elevation of Privilege Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows kernel allows for privilege escalation when objects are improperly handled in memory. This could enable an attacker with local access to execute code with elevated privileges, potentially impacting system control and data.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-9819

Apple Mail Memory Issue Exposes Devices to Heap Corruption.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A memory consumption flaw in Apple operating systems may allow attackers to cause heap corruption by processing a crafted email. This could impact system availability and disrupt operations for affected organizations. The risk is rated medium and requires user interaction for exploitation.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2020-13965

Roundcube Webmail Attachment Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Roundcube Webmail has a cross-site scripting flaw allowing malicious XML attachments to compromise user sessions and data. This impacts organizations using the email client, posing a risk to data integrity and authorized actions within the system. Mitigation involves applying vendor updates.

• CISA KEV