Remove 2012 Remove Internet Remove Windows
article thumbnail

CVE-2020-1350: Wormable Remote Code Execution Vulnerability in Windows DNS Server Disclosed (SIGRed)

Tenable

Researchers disclose a 17-year old wormable flaw in Windows DNS servers. On July 14, Microsoft patched a critical vulnerability in Windows Domain Name System (DNS) Server as part of Patch Tuesday for July 2020. According to the researchers, the vulnerability has persisted in Windows DNS Server for 17 years. Background.

Windows 141
article thumbnail

CVE-2024-4577: Proof of Concept Available for PHP-CGI Argument Injection Vulnerability

Tenable

According to researchers at DEVCORE, this flaw is the result of errors in character encoding conversions, affecting the “ Best Fit ” feature on Windows. CVE-2024-4577 is a patch bypass of CVE-2012-1823 Both PHP and DEVCORE note that CVE-2024-4577 is a patch bypass of CVE-2012-1823. Vulnerability affects PHP running on Windows.

PHP 118
article thumbnail

August 2024 Patch Tuesday

Ivanti

Microsoft update summary Microsoft has released updates for the Windows OS, Office, Edge,Net and Visual Studio and several Azure services. The good news is the Windows OS and Office will knock out most of the risk pretty quick. The vulnerability affects Windows Server 2012 and later OS editions. CVSS rating is 8.8,

Windows 59
article thumbnail

Microsoft’s February 2020 Patch Tuesday Addresses 99 CVEs Including Internet Explorer Zero-Day (CVE-2020-0674)

Tenable

This month’s updates include patches for Microsoft Windows, Microsoft Office, Microsoft Edge, Internet Explorer, Microsoft Exchange Server, Microsoft SQL Server, Microsoft Office Service and Web Apps, Windows Malicious Software Removal Tool and Windows Surface Hub. Maddie Stone (@maddiestone) February 11, 2020.

Internet 107
article thumbnail

CVE-2022-37958: FAQ for Critical Microsoft SPNEGO NEGOEX Vulnerability

Tenable

CVE-2022-37958 is a remote code execution (RCE) vulnerability in the SPNEGO NEGOEX protocol of Windows operating systems, which supports authentication in applications. KB5017308: Windows 10 Version 20H2 / 21H1 / 21H2 Security Update (September 2022). KB5017328: Windows 11 Security Update (September 2022). What is SPNEGO NEGOEX?

Windows 98
article thumbnail

NSA Urges Legacy Windows Users to Patch BlueKeep Vulnerability

Kaseya

The National Security Agency (NSA) has jumped into the fray recently with an advisory urging Microsoft Windows administrators and users to patch older versions of Windows. It affects Windows XP, Windows 7, Windows Server 2003 and 2008. This vulnerability is in the Remote Desktop Protocol (RDP).

Windows 45
article thumbnail

NSA Urges Legacy Windows Users to Patch BlueKeep Vulnerability

Kaseya

The National Security Agency (NSA) has jumped into the fray recently with an advisory urging Microsoft Windows administrators and users to patch older versions of Windows. It affects Windows XP, Windows 7, Windows Server 2003 and 2008. This vulnerability is in the Remote Desktop Protocol (RDP).

Windows 45