NVD disclosure day

Published threat advisories for September 10, 2024

CVE advisoryKnown Exploit

CVE-2024-8190

Ivanti Cloud Services Appliance OS Command Injection Vulnerability.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A vulnerability in the Ivanti Cloud Services Appliance allows authenticated administrators to execute commands, potentially leading to unauthorized system control and data compromise. This poses a business risk due to potential operational disruption and data exposure. Organizations using this appliance should assess t

• CISA KEV

CVE advisoryKnown Exploit

CVE-2024-43461

Windows MSHTML Platform Spoofing Vulnerability.

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A spoofing vulnerability in the Windows MSHTML Platform allows attackers to display fraudulent web pages, potentially deceiving users and leading to data compromise. This impacts organizations by undermining user trust and exposing them to further malicious activity. The risk is heightened as this vulnerability has bee

• CISA KEV

CVE advisoryCRITICAL

CVE-2024-43455

Windows Server Remote Desktop Licensing Service Spoofing Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical spoofing vulnerability exists in the Windows Remote Desktop Licensing Service. Attackers could impersonate this service over the network, potentially leading to unspecified impacts or denial of service, though direct internet exposure of the service is unlikely.

CVE advisoryCRITICAL

CVE-2024-38240

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A critical vulnerability exists in the Windows Remote Access Connection Manager, allowing for elevation of privileges. While the attack vector is rated as network-based, exploitation typically requires local system access, making external reachability unlikely. This means an attacker would need initial access to a syst

CVE advisoryKnown Exploit

CVE-2024-38226

Microsoft Publisher Macro Policy Bypass Vulnerability

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A vulnerability in Microsoft Publisher allows attackers to bypass macro policies, potentially leading to unauthorized code execution. This impacts systems by enabling attackers to circumvent security features, posing a business risk to data confidentiality, integrity, and availability. Exploitation requires local acces

• CISA KEV

CVE advisoryCRITICAL

CVE-2024-38225

Microsoft Dynamics 365 Business Central Privilege Escalation Vulnerability

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

A critical vulnerability in Microsoft Dynamics 365 Business Central could allow an unauthenticated attacker to gain elevated privileges. This issue is externally exposed and potentially internet-reachable, requiring confirmation of relevance and exposure for business-critical systems.

CVE advisoryCRITICAL

CVE-2024-38220

Azure Stack Hub Privilege Escalation Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical privilege escalation vulnerability exists in Microsoft Azure Stack Hub, potentially allowing an attacker with low-privilege access to gain elevated control. This affects hybrid cloud environments, posing risks to system confidentiality, integrity, and availability. Readers should care because unauthorized ad

CVE advisoryKnown Exploit

CVE-2024-38217

Windows Mark of the Web Security Bypass Risk

Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.

A security bypass vulnerability in Windows Mark of the Web can allow attackers to circumvent downloaded file protections, impacting data integrity and availability. This poses a moderate business risk by potentially enabling the execution of malicious files without expected security warnings. Organizations should prior

• CISA KEV

CVE advisoryCRITICAL

CVE-2024-38216

Azure Stack Hub Elevation of Privilege Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical elevation of privilege vulnerability exists in Azure Stack Hub, potentially allowing a low-privileged authenticated attacker to escalate their access. This could impact the confidentiality, integrity, and availability of the system and its data. Confirming the relevance and exposure of your Azure Stack Hub d

CVE advisoryCRITICAL

CVE-2024-38194

Azure Web Apps Improper Authorization Privilege Escalation

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

An improper authorization vulnerability in Azure Web Apps allows an authenticated attacker to elevate privileges over a network. If reachable, this could impact the integrity and availability of hosted services or lead to unauthorized access to sensitive data. This vulnerability is relevant for organizations using Azur

CVE advisoryCRITICAL

CVE-2024-37980

Microsoft SQL Server Privilege Escalation Vulnerability.

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Microsoft SQL Server could allow an unauthenticated attacker to gain elevated privileges. If reachable, this flaw may enable unauthorized control of the server and compromise sensitive data. Confirming your SQL Server deployment's relevance is essential for assessing potential risk.

CVE advisoryCRITICAL

CVE-2024-37341

Microsoft SQL Server Elevation of Privilege Vulnerability

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

A critical vulnerability in Microsoft SQL Server could allow an unauthenticated attacker to gain elevated privileges. If reachable, this could lead to unauthorized access and control over sensitive data, impacting system confidentiality, integrity, and availability. Understanding the exposure of your SQL Server instanc

CVE advisoryCRITICAL

CVE-2024-21416

Windows TCP/IP Remote Code Execution Vulnerability

Halo Surface Signal: 3 out of 5 — possibly public-facing.

A critical vulnerability in the Windows TCP/IP stack could allow an unauthenticated attacker to execute arbitrary code remotely by sending specially crafted network packets. This externally exposed issue poses a significant risk, with potential for full system compromise if exploited. Assessing and understanding system