NVD disclosure day

Published threat advisories for February 14, 2023

CVE advisoryKnown Exploit

CVE-2023-21823

Windows Graphics Component Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Windows Graphics Component has a vulnerability that allows for privilege escalation, potentially impacting system integrity and data confidentiality. Attackers with local, low-level access can exploit this by opening specially crafted documents, leading to unauthorized control of systems. Organizations should prior

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-23376

Windows Driver Vulnerability Allows for Privilege Escalation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the Windows Common Log File System Driver allows local attackers to elevate privileges, potentially impacting system integrity and data confidentiality. This presents a risk to organizations due to the possibility of unauthorized system access or disruption.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-21715

Microsoft Publisher Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security feature bypass vulnerability in Microsoft Publisher may allow attackers to circumvent security measures. This could impact data confidentiality, integrity, and availability. The realistic business risk involves potential unauthorized access or system disruption, particularly if the vulnerability is actively

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-21529

Microsoft Exchange Server Remote Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Exchange Server has a vulnerability allowing authenticated attackers to execute remote code. This could lead to unauthorized system access and data compromise, posing a business risk to affected organizations. The vulnerability is known to be exploited in ransomware campaigns.

• CISA KEV