NVD disclosure day

Published threat advisories for July 11, 2023

CVE advisoryKnown Exploit

CVE-2023-36884

Windows Search Remote Code Execution Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

This vulnerability affects Microsoft Windows systems, allowing attackers to execute unauthorized code by tricking users into opening malicious files. This poses a risk to organizational systems and data. Mitigation involves applying vendor security updates.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-36874

Windows Error Reporting Privilege Escalation Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Error Reporting Service allows an attacker with local access to elevate their privileges. This could impact organizations by allowing unauthorized access to sensitive data or control over systems. The business risk involves potential data compromise and disruption of operations.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-35311

Microsoft Outlook Security Feature Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Microsoft Outlook applications are affected by a security feature bypass that allows attackers to circumvent security prompts. This poses a risk to organizational data and operations if an attacker can trick a user into interacting with malicious content. The realistic business risk involves potential unauthorized acce

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-32049

Windows SmartScreen Security Feature Bypass Advisory

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows SmartScreen allows attackers to bypass security warnings when opening files, potentially leading to unauthorized access or execution of malicious content. This impacts Windows operating systems and presents a business risk of data compromise and system infiltration. Organizations should apply

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-32046

Windows MSHTML Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows MSHTML Platform allows an attacker to elevate privileges on a system. This could impact organizations using affected Windows operating systems, potentially leading to unauthorized data access or modification, posing a business risk.

• CISA KEV