Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Microsoft Windows Elevation of Privilege Vulnerabilities

Windows Object Manager Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists in Windows Object Manager when it fails to properly validate and enforce impersonation levels. An attacker who successfully exploited this vulnerability could bypass impersonation-level security and gain elevated privileges on a targeted system. Windows...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6105 Views

RISK: Medium Risk

Medium Risk

Microsoft WebDAV Information Disclosure Vulnerability

An information disclosure vulnerability exists in the Microsoft Web Distributed Authoring and Versioning (WebDAV) client that is caused when it explicitly allows the use of Secure Socket Layer (SSL) 2.. An attacker who successfully exploited this vulnerability could decrypt portions of encrypted traffic.
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6035 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Unsafe Command Line Parameter Passing Vulnerability

An information disclosure vulnerability exists in Microsoft Windows, Internet Explorer, and Microsoft Office when files at a medium integrity level become accessible to Internet Explorer running in Enhanced Protection Mode (EPM).
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6097 Views

RISK: Medium Risk

Medium Risk

Microsoft UDDI Services Elevation of Privilege Vulnerability

An elevation of privilege exists in Microsoft Windows when the Universal Description, Discovery, and Integration (UDDI) Services improperly validate or sanitize the search parameter in a FRAME tag. An attacker who successfully exploited this vulnerability could leak authorization cookies or unexpectedly redirect a user to...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6103 Views

RISK: Medium Risk

Medium Risk

Microsoft System Center Operations Manager Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft System Center Operations Manager that is caused by the improper validation of input. An attacker who successfully exploited this vulnerability could inject a client-side script into the user's browser. The script could spoof content, disclose...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 5950 Views

RISK: Medium Risk

Medium Risk

Microsoft Mount Manager Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists when the Mount Manager component improperly processes symbolic links. An attacker who successfully exploited this vulnerability could write a malicious binary to disk and execute it.
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6254 Views

RISK: Medium Risk

Medium Risk

Microsoft XML Core Services Information Disclosure Vulnerabilities

Multiple MSXML Information Disclosure VulnerabilitiesInformation disclosure vulnerabilities exist when Microsoft XML Core Services (MSXML) explicitly allows the use of Secure Sockets Layer (SSL) 2.. An attacker who successfully exploited these vulnerabilities could decrypt portions of encrypted network information traffic. MSXML Information Disclosure VulnerabilityAn...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6098 Views

RISK: High Risk

High Risk

Microsoft Server Message Block Remote Code Execution Vulnerability

An authenticated remote code execution vulnerability exists in Windows that is caused when Server Message Block (SMB) improperly handles certain logging activities, resulting in memory corruption. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6162 Views

RISK: High Risk

High Risk

Microsoft RDP Remote Code Execution Vulnerabilities

Remote Desktop Session Host Spoofing Vulnerability A spoofing vulnerability exists when the Remote Desktop Session Host (RDSH) improperly validates certificates during authentication. An attacker who successfully exploited this vulnerability could impersonate the client session. Remote Desktop Protocol DLL Planting Remote Code Execution Vulnerability A...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6070 Views

RISK: High Risk

High Risk

Microsoft Office Remote Code Execution Vulnerabilities

Multiple Microsoft Office Memory Corruption VulnerabilitiesRemote code execution vulnerabilities exist in Microsoft Office software when the Office software fails to properly handle objects in memory. An attacker who successfully exploited the vulnerability could use a specially crafted file to perform actions in the security context of the current user...
Last Update Date: 14 Aug 2015 Release Date: 12 Aug 2015 6153 Views