NVD disclosure day

Published threat advisories for February 13, 2024

CVE advisoryKnown Exploit

CVE-2024-21412

Windows Internet Shortcut Security Feature Bypass

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

This vulnerability impacts Microsoft Windows operating systems by allowing attackers to bypass security features through specially crafted Internet Shortcut files. This could enable unauthorized access to data or system compromise, posing a business risk that requires prompt attention and mitigation. The vulnerability

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-21410

Microsoft Exchange Server Elevation of Privilege Vulnerability

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

This vulnerability in Microsoft Exchange Server allows attackers to elevate privileges, potentially leading to unauthorized access and compromise of sensitive data. Organizations with affected Exchange Server deployments face business risks including data breaches and service disruptions. Mitigation is recommended.

• CISA KEV

CVE advisoryCRITICAL

CVE-2024-21403

Azure Kubernetes Service Confidential Container Elevation of Privilege Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A vulnerability in Microsoft Azure Kubernetes Service Confidential Containers could allow an unauthenticated attacker to gain elevated privileges. This elevation of privilege flaw, if reachable, could lead to unauthorized access and control within the confidential container environment. Readers should care to understan

CVE advisoryCRITICAL

CVE-2024-21401

Microsoft Entra Jira SSO Plugin Elevation of Privilege Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability exists in the Microsoft Entra Jira Single-Sign-On Plugin, potentially allowing unauthenticated attackers to gain elevated privileges. This could lead to unauthorized access to system data and sensitive information if the plugin is in use and reachable. Confirming its presence and exposure withi

CVE advisoryCRITICAL

CVE-2024-21376

Azure Kubernetes Service Remote Code Execution Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A remote code execution vulnerability exists in Microsoft Azure Kubernetes Service. This issue could allow an unauthenticated attacker with network access to compromise containerized environments. The potential impact includes unauthorized code execution and control over affected systems, necessitating an assessment of

CVE advisoryKnown Exploit

CVE-2024-21351

Windows SmartScreen Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Windows SmartScreen allows attackers to bypass security features, potentially leading to unauthorized code execution. This could result in data exposure or system downtime for affected organizations. The risk to business operations is significant.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-21338

Windows Kernel Elevation of Privilege Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows kernel allows for privilege escalation by an attacker with local access, potentially impacting system integrity and data confidentiality. The business risk involves unauthorized access and modification of sensitive information on affected systems.

• CISA KEV