article thumbnail

CVE-2020-1350: Wormable Remote Code Execution Vulnerability in Windows DNS Server Disclosed (SIGRed)

Tenable

Researchers disclose a 17-year old wormable flaw in Windows DNS servers. On July 14, Microsoft patched a critical vulnerability in Windows Domain Name System (DNS) Server as part of Patch Tuesday for July 2020. According to the researchers, the vulnerability has persisted in Windows DNS Server for 17 years. Background.

Windows 142
article thumbnail

CVE-2021-34527: Microsoft Releases Out-of-Band Patch for PrintNightmare Vulnerability in Windows Print Spooler

Tenable

On July 6, Microsoft updated its advisory to announce the availability of out-of-band patches for a critical vulnerability in its Windows Print Spooler that researchers are calling PrintNightmare. This remote code execution (RCE) vulnerability affects all versions of Microsoft Windows. for 32-bit systems Windows 8.1 Description.

Windows 102
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

Want to tackle technical debt? Sell it as business risk

CIO

A recent example is Windows Server 2012, which was sunsetted by Microsoft in October 2023. Windows Server 2012 is not alone. Despite this sunsetting, companies still run the platform, primarily because they want to defer investing or can’t afford to invest in the upgrade.

Budget 193
article thumbnail

November 2023 Patch Tuesday

Ivanti

This month is also the first patch cycle for Server 2012 and 2012 R2 extended support (ESU). Products affected include Windows OS, Office 365,Net, ASP.NET, Azure DevOps Server, Visual Studio, Exchange Server and SQL Server. Microsoft Server 2012 and 2012 R2 officially reached their end-of-life in October.

Windows 124
article thumbnail

TechCrunch+ roundup: New VC rules, AI biotech investor survey, Instagram ad case study

TechCrunch

” In a data-driven piece that looks at post-money valuations, deal sizes and dilution rates going back to 2012, Mitchem says we’re now heading into a new era where the tech industry will embrace “growth at reasonable costs.” Image Credits: Andriy Onufriyenko (opens in a new window) / Getty Images.

article thumbnail

CVE-2024-4577: Proof of Concept Available for PHP-CGI Argument Injection Vulnerability

Tenable

According to researchers at DEVCORE, this flaw is the result of errors in character encoding conversions, affecting the “ Best Fit ” feature on Windows. CVE-2024-4577 is a patch bypass of CVE-2012-1823 Both PHP and DEVCORE note that CVE-2024-4577 is a patch bypass of CVE-2012-1823. Vulnerability affects PHP running on Windows.

PHP 120
article thumbnail

SMBleed (CVE-2020-1206) and SMBLost (CVE-2020-1301) Vulnerabilities Affect Microsoft SMBv3 and SMBv1

Tenable

The first version of the SMB protocol (SMBv1) was developed at IBM by Barry Feigenbaum in 1983 and it was eventually implemented in Microsoft Windows in 1992. As a result, Microsoft announced in April 2012 that SMB version 2.2 SMBv3) as part of Windows 8 and Windows Server 2012. Windows Server. Windows RT.