Skip to main content

Security Bulletin

Filter by:

RISK: High Risk

High Risk

Microsoft Windows WinVerifyTrust Signature Validation Vulnerability

A remote code execution vulnerability exists in the way that the WinVerifyTrust function handles Windows Authenticode signature verification for portable executable (PE) files. An anonymous attacker could exploit the vulnerability by modifying an existing signed executable file to leverage unverified portions of the file in such a...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 8845 Views

RISK: High Risk

High Risk

Microsoft Scripting Runtime Object Library Use-After-Free Vulnerability

This is a remote code execution vulnerability in the Microsoft Scripting Runtime Object Library. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6212 Views

RISK: Medium Risk

Medium Risk

Microsoft SharePoint Page Content Vulnerabilities

Remote code execution vulnerabilities exist in Microsoft SharePoint Server. An authenticated attacker who successfully exploited these vulnerabilities could run arbitrary code in the security context of the W3WP service account.
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 5832 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Kernel-Mode Drivers Elevation of Privilege Vulnerabilities

Win32k Memory Corruption VulnerabilityAn elevation of privilege vulnerability exists in the way that the Win32k.sys kernel-mode driver validates address values in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code with elevated privileges.Win32k Use After Free VulnerabilityAn elevation of privilege...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6180 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows LRPC Client Buffer Overrun Vulnerability

An elevation of privilege vulnerability exists in Microsoft Local Remote Procedure Call (LRPC) where an attacker spoofs an LRPC Server and uses a specially crafted LPC port message to cause a stack-based buffer overflow condition on the LRPC client. LRPC internally uses Microsoft Local Procedure...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6415 Views

RISK: Medium Risk

Medium Risk

ASP.NET SignalR XSS Vulnerability

An elevation of privilege vulnerability exists in ASP.NET SignalR that could allow an attacker access to resources in the context of the targeted user.
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6789 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Token Hijacking Vulnerability

An information disclosure vulnerability exists when affected Microsoft Office software does not properly handle a specially crafted response while attempting to open an Office file hosted on the malicious website. An attacker who successfully exploited this vulnerability could ascertain access tokens used to authenticate the current user on a...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6019 Views

RISK: High Risk

High Risk

Microsoft Exchange Server Remote Code Execution Vulnerabilities

Oracle Outside In Contains Multiple Exploitable VulnerabilitiesTwo of the vulnerabilities addressed in this bulletin, CVE-2013-5763 and CVE-2013-5791, exist in Exchange Server 2007, Exchange Server 2010, and Exchange Server 2013 through the WebReady Document Viewing feature. The vulnerabilities...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6176 Views

RISK: Medium Risk

Medium Risk

Microsoft Office HXDS ASLR Vulnerability

A security feature bypass exists in an Office shared component that does not properly implement Address Space Layout Randomization (ASLR). The vulnerability could allow an attacker to bypass the ASLR security feature, after which the attacker could load additional malicious code in the process in an attempt...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 6017 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Cumulative Security Update

Multiple Elevation of Privilege Vulnerabilities in Internet ExplorerElevation of privilege vulnerabilities exist within Internet Explorer during validation of local file installation and during secure creation of registry keys.Multiple Memory Corruption Vulnerabilities in Internet ExplorerRemote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These...
Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 5891 Views