NVD disclosure day

Published threat advisories for September 10, 2024

CVE advisoryKnown Exploit

CVE-2024-8190

Ivanti Cloud Services Appliance OS Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Ivanti Cloud Services Appliance allows authenticated administrators to execute commands, potentially leading to unauthorized system control and data compromise. This poses a business risk due to potential operational disruption and data exposure. Organizations using this appliance should assess t

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-43461

Windows MSHTML Platform Spoofing Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A spoofing vulnerability in the Windows MSHTML Platform allows attackers to display fraudulent web pages, potentially deceiving users and leading to data compromise. This impacts organizations by undermining user trust and exposing them to further malicious activity. The risk is heightened as this vulnerability has bee

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-38226

Microsoft Publisher Macro Policy Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Microsoft Publisher allows attackers to bypass macro policies, potentially leading to unauthorized code execution. This impacts systems by enabling attackers to circumvent security features, posing a business risk to data confidentiality, integrity, and availability. Exploitation requires local acces

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-38217

Windows Mark of the Web Security Bypass Risk

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security bypass vulnerability in Windows Mark of the Web can allow attackers to circumvent downloaded file protections, impacting data integrity and availability. This poses a moderate business risk by potentially enabling the execution of malicious files without expected security warnings. Organizations should prior

• CISA KEV