NVD disclosure day

Published threat advisories for August 13, 2024

CVE advisoryKnown Exploit

CVE-2024-28986

SolarWinds Web Help Desk Remote Code Execution Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in SolarWinds Web Help Desk may allow an attacker to execute commands on affected systems. This could lead to unauthorized access, data compromise, and operational disruption. Organizations using this software face significant business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-38213

Windows Security Feature Bypass Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security flaw in Windows allows attackers to bypass the Mark of the Web feature, potentially leading to unauthorized execution of malicious files. This impacts organizations using affected Windows systems, increasing the risk of compromise through user interaction with crafted files. Applying vendor mitigations is ad

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-38193

Windows Ancillary Function Driver Privilege Escalation Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in the Windows Ancillary Function Driver for WinSock allows local attackers to escalate privileges to SYSTEM level. This impacts affected Windows operating systems, potentially leading to unauthorized access to data and disruption of business operations. The risk is elevated due to the potential for com

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-38189

Microsoft Project Remote Code Execution Vulnerability.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Microsoft Project could allow remote code execution via a malicious file, affecting organizational data and systems. The risk to business operations is elevated as this is a known exploited vulnerability. Affected organizations should apply vendor updates.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-38178

Windows Scripting Engine Memory Corruption Vulnerability in Microsoft Windows.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A scripting engine memory corruption vulnerability affects multiple Windows versions. Attackers can execute malicious code via a crafted URL, leading to potential data compromise and service disruption. Organizations should identify affected systems and apply vendor updates to mitigate business risk.

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-38107

Windows Elevation Of Privilege Vulnerability In Power Dependency Coordinator.

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

Certain Microsoft Windows systems are affected by a vulnerability allowing local privilege escalation. This can lead to unauthorized system access and control, impacting data confidentiality and system integrity. Organizations should prioritize identifying and mitigating affected assets.

• CISA KEV