NVD disclosure day

Published threat advisories for October 10, 2023

CVE advisoryKnown Exploit

CVE-2023-41763

Microsoft Skype for Business Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in Microsoft Skype for Business Server could allow an attacker to gain elevated privileges. This impacts organizations using the server software, potentially leading to unauthorized access or system disruption. The business risk involves unauthorized control over affected systems.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-36584

Microsoft Windows Security Bypass Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows' Mark of the Web security feature allows attackers to bypass warnings, potentially leading to a limited loss of integrity and availability. This impacts organizations using affected Windows systems and poses a risk if users interact with specially crafted files. Mitigation is recommended.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-36563

Microsoft WordPad Information Disclosure Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Microsoft WordPad has an information disclosure vulnerability. Affected systems could allow attackers to access sensitive data if a specially crafted file is opened by a user. This presents a risk to organizational data confidentiality. Organizations should apply vendor updates to mitigate this risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2023-4966

Citrix NetScaler Gateway Information Disclosure.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

The NetScaler ADC and NetScaler Gateway are affected by a vulnerability enabling sensitive information disclosure. This matters because unauthorized access to confidential data can occur when these systems are configured as Gateways. The business risk involves potential exposure of organizational data.

• CISA KEV