NVD disclosure day

Published threat advisories for February 14, 2023

CVE advisoryKnown Exploit

CVE-2023-21823

Windows Graphics Component Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

The Windows Graphics Component has a vulnerability that allows for privilege escalation, potentially impacting system integrity and data confidentiality. Attackers with local, low-level access can exploit this by opening specially crafted documents, leading to unauthorized control of systems. Organizations should prior

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-23376

Windows Driver Vulnerability Allows for Privilege Escalation.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A flaw in the Windows Common Log File System Driver allows local attackers to elevate privileges, potentially impacting system integrity and data confidentiality. This presents a risk to organizations due to the possibility of unauthorized system access or disruption.

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-21803

Windows iSCSI Discovery Service Remote Code Execution Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in the Windows iSCSI Discovery Service that could permit remote code execution by an unauthenticated attacker. While this service is typically used for internal storage networks and not exposed externally, its reachability could lead to system compromise. Understanding if this internal s

CVE advisoryCRITICAL

CVE-2023-21716

Microsoft Word Remote Code Execution Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Microsoft Word and related Office and SharePoint products, potentially allowing remote code execution if a user opens a specially crafted document. This could lead to unauthorized commands being run on affected systems. It is important to determine if the organization uses vulnerable

CVE advisoryKnown Exploit

CVE-2023-21715

Microsoft Publisher Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security feature bypass vulnerability in Microsoft Publisher may allow attackers to circumvent security measures. This could impact data confidentiality, integrity, and availability. The realistic business risk involves potential unauthorized access or system disruption, particularly if the vulnerability is actively

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-21692

Microsoft PEAP Remote Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Microsoft's Protected Extensible Authentication Protocol (PEAP), potentially allowing remote code execution. This issue affects network authentication services on various Windows systems. While typically used internally, an attacker could exploit this flaw over the network, leading to

CVE advisoryCRITICAL

CVE-2023-21690

Microsoft PEAP Remote Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability exists in Microsoft's Protected Extensible Authentication Protocol (PEAP) that could allow an unauthenticated remote attacker to execute code. This may impact the confidentiality, integrity, and availability of affected systems. It is important to confirm if this protocol is in use and exposed

CVE advisoryCRITICAL

CVE-2023-21689

Microsoft PEAP Remote Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Microsoft's Protected Extensible Authentication Protocol (PEAP) could allow an attacker to execute arbitrary code on affected systems. This protocol is used for secure authentication, and exploitation could lead to a compromise of system integrity and confidentiality. The extent of impact de

CVE advisoryKnown Exploit

CVE-2023-21529

Microsoft Exchange Server Remote Code Execution Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Exchange Server has a vulnerability allowing authenticated attackers to execute remote code. This could lead to unauthorized system access and data compromise, posing a business risk to affected organizations. The vulnerability is known to be exploited in ransomware campaigns.

• CISA KEV