NVD disclosure day

Published threat advisories for September 12, 2023

CVE advisoryKnown Exploit

CVE-2023-36802

Microsoft Streaming Service Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A privilege escalation vulnerability in the Microsoft Streaming Service Proxy impacts Microsoft Windows systems. This flaw allows an attacker with local access to gain elevated privileges, potentially leading to unauthorized system control and data modification. The vulnerability is listed as a known exploited vulnerab

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-36761

Microsoft Word Information Disclosure Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Microsoft Word applications are affected by an information disclosure vulnerability. This impacts organizations by potentially exposing sensitive data, increasing the risk of data breaches and unauthorized access to confidential business information. Organizations should consult Microsoft's guidance for mitigation step

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-4863

Google Chrome WebP Vulnerability: Remote Code Execution Risk

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A heap buffer overflow in the libwebp library can allow attackers to write data outside of allocated memory via a crafted HTML page. This impacts organizations using affected browsers or image viewers, posing a risk to data integrity and system operation.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-41990

Apple Operating Systems Font Processing Code Execution Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Apple operating systems allows for arbitrary code execution when processing a font file. This could impact affected systems and data. Organizations should identify all affected devices and apply vendor-provided security updates.

• CISA KEV