NVD disclosure day

Published threat advisories for November 9, 2022

CVE advisoryKnown Exploit

CVE-2022-41128

Windows Scripting Languages Remote Code Execution Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Windows Scripting Languages may allow attackers to execute remote code. This impacts various Windows systems, creating risk of system compromise and data exposure. Organizations should apply available updates to mitigate business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-41125

Windows CNG Key Isolation Service Elevation of Privilege Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows CNG Key Isolation Service allows a local attacker to gain elevated system privileges. This could impact organizations by enabling unauthorized access to sensitive data and system control. Applying vendor security updates is recommended to mitigate this risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-41080

Microsoft Exchange Server Elevation of Privilege Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Exchange Server has an elevation of privilege vulnerability. This could allow an attacker to gain unauthorized access to sensitive data and systems. The risk to business operations and data integrity is significant, particularly as this vulnerability has been observed in active campaigns. Organizations should

• CISA KEV

CVE advisoryKnown Exploit

CVE-2022-41049

Microsoft Windows Mark of the Web Security Bypass.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability exists in Windows that allows attackers to bypass security features. This could affect data integrity and the availability of security protections. The risk to organizations is heightened as this vulnerability is actively exploited.

• CISA KEV