This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-36804.
Daily Archives: November 15, 2023
ZDI-23-1645: Microsoft Windows win32kfull UMPDDrvBitBlt Use-After-Free Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-36804.
ZDI-23-1646: Microsoft Exchange GsmWriter Deserialization of Untrusted Data NTLM Relay Vulnerability
This vulnerability allows remote attackers to create a denial-of-service condition or relay NTLM credentials on affected installations of Microsoft Exchange. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2023-38181.
xen-4.17.2-5.fc38
FEDORA-2023-56901a79a1
Packages in this update:
xen-4.17.2-5.fc38
Update description:
x86/AMD: mismatch in IOMMU quarantine page table levels [XSA-445,
CVE-2023-46835]
x86: BTC/SRSO fixes not fully effective [XSA-446, CVE-2023-46836]
DSA-5555-1 openvpn – security update
Two vulnerabilities were discovered in openvpn, a virtual private
network application which could result in memory disclosure or denial
of service.
The oldstable distribution (bullseye) is not affected.
DSA-5556-1 chromium – security update
Multiple security issues were discovered in Chromium, which could result
in the execution of arbitrary code, denial of service or information
disclosure.
DSA-5555 openvpn – security update
Two vulnerabilities were discovered in openvpn, a virtual private
network application which could result in memory disclosure or denial
of service.