NVD disclosure day

Published threat advisories for August 8, 2023

CVE advisoryKnown Exploit

CVE-2023-38180

.NET and Visual Studio Denial of Service Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A denial-of-service vulnerability affects .NET and Visual Studio, allowing attackers to disrupt services. This matters because it can make systems unresponsive, leading to business downtime. The risk involves service unavailability for legitimate users.

• CISA KEV

CVE advisoryCRITICAL

CVE-2023-38186

Windows MDM Elevation of Privilege Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical elevation of privilege vulnerability exists in Windows Mobile Device Management that could allow an unauthenticated attacker to gain elevated access to affected systems. The vulnerability is externally classified and has a high CVSS score, indicating potential risk if reachable.

CVE advisoryCRITICAL

CVE-2023-36911

Microsoft Message Queuing Remote Code Execution Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Microsoft Message Queuing allows for remote code execution, enabling attackers to potentially run malicious software on affected systems. This technology is used for internal server communication, and the primary concern is whether MSMQ services are exposed externally and actively utilized.

CVE advisoryCRITICAL

CVE-2023-36910

Microsoft Message Queuing Remote Code Execution Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Microsoft Message Queuing (MSMQ) that could allow remote code execution. This affects various Windows systems, and while MSMQ is typically used internally, its presence means this flaw could be exploited if reachable, potentially leading to system compromise. Readers should care becau

CVE advisoryCRITICAL

CVE-2023-36903

Windows System Assessment Tool Elevation of Privilege Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical elevation of privilege vulnerability exists in the Windows System Assessment Tool. If reachable, an attacker could leverage this to gain elevated privileges on affected systems. This could impact system integrity and confidentiality. Please confirm if your environment uses the affected tool and assess any po

CVE advisoryCRITICAL

CVE-2023-35385

Microsoft MSMQ Remote Code Execution Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability exists in Microsoft Message Queuing (MSMQ) that could allow remote code execution by an unauthenticated attacker. This issue could affect the availability and integrity of services relying on MSMQ. It is important to determine if MSMQ is used within your environment and assess potential exposur

CVE advisoryCRITICAL

CVE-2023-21709

Microsoft Exchange Server Elevation of Privilege Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Microsoft Exchange Server has an elevation of privilege vulnerability that could allow an unauthenticated attacker to gain elevated privileges on a system. This could affect system data and service behavior. Remediation involves inventorying Exchange Server instances and prioritizing efforts based on risk.

CVE advisoryCRITICAL

CVE-2023-3386

Attacker can steal sensitive data or control the tracking system

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

An external attacker can access the a2 Camera Trap Tracking System through its web interface to compromise the backend database. This could allow them to steal, change, or delete sensitive monitoring data, leading to a loss of proprietary information.

CVE advisoryCRITICAL

CVE-2023-3651

Digital Ant E-Commerce Software can be exploited to steal customer data or disrupt services

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

Digital Ant E-Commerce Software has a critical flaw allowing unauthorized access to steal or alter sensitive customer data. This issue is exploitable over the internet without needing a login, making your business a potential target.

CVE advisoryCRITICAL

CVE-2023-3716

Attacker can steal customer data or disrupt Oduyo Online Collection Software by tricking it into running malicious database commands.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical flaw in Oduyo Online Collection Software could let attackers steal sensitive data or disrupt services by sending malicious commands to the database. Update now to protect your financial information.