Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Cisco IOS Denial of Service Vulnerability

A vulnerability was identified in Cisco IOS. A local user can cause denial of service conditions.An unprivileged local user can cause issue IOS Shell commands to cause the target device to crash.
Last Update Date: 11 Feb 2015 16:35 Release Date: 11 Feb 2015 3184 Views

RISK: Medium Risk

Medium Risk

Microsoft Virtual Machine Manager Elevation of Privilege Vulnerability

A vulnerability exists in Virtual Machine Manager (VMM) when VMM improperly validates user roles. The vulnerability could allow elevation of privilege if an attacker logs on an affected system. An attacker must have valid Active Directory logon credentials and be able to log on with those...
Last Update Date: 11 Feb 2015 10:27 Release Date: 11 Feb 2015 3137 Views

RISK: Medium Risk

Medium Risk

Microsoft Graphics Component Information Disclosure Vulnerability

An information disclosure vulnerability exists when Windows fails to properly handle uninitialized memory when parsing certain, specially crafted TIFF image format files. The vulnerability could allow information disclosure if an attacker runs a specially crafted application on an affected system.
Last Update Date: 11 Feb 2015 10:26 Release Date: 11 Feb 2015 3090 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in Microsoft Windows when it fails to properly validate and enforce impersonation levels. An attacker who successfully exploited this vulnerability could bypass impersonation-level security checks and gain elevated privileges on a targeted system. This vulnerability can be exploited only in...
Last Update Date: 11 Feb 2015 10:25 Release Date: 11 Feb 2015 3044 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Group Policy Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in the Group Policy application of Security Configuration policies that could cause Group Policy settings on a targeted system to revert to their default, and potentially less secure, state. An attacker could accomplish this by way of a man-in...
Last Update Date: 11 Feb 2015 10:24 Release Date: 11 Feb 2015 3143 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in Microsoft Office when it fails to use the Address Space Layout Randomization (ASLR) security feature, allowing an attacker to more reliably predict the memory offsets of specific instructions in a given call stack. The security feature bypass by itself...
Last Update Date: 11 Feb 2015 10:23 Release Date: 11 Feb 2015 3072 Views

RISK: Medium Risk

Medium Risk

Microsoft Office Remote Code Execution Vulnerabilities

Excel Remote Code Execution VulnerabilityA remote code execution vulnerability exists in Microsoft Excel that is caused when Excel improperly handles objects in memory while parsing specially crafted Office files. This could corrupt system memory in such a way as to allow an attacker to execute arbitrary code.Office...
Last Update Date: 11 Feb 2015 10:22 Release Date: 11 Feb 2015 3058 Views

RISK: High Risk

High Risk

Microsoft Internet Explorer Security Update

Multiple Memory Corruption Vulnerabilities in Internet ExplorerRemote code execution vulnerabilities exist when Internet Explorer improperly accesses objects in memory. These vulnerabilities could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. The update addresses the vulnerabilities by...
Last Update Date: 11 Feb 2015 10:20 Release Date: 11 Feb 2015 3109 Views

RISK: High Risk

High Risk

Microsoft Windows Kernel-Mode Driver Remote Code Execution Vulnerabilities

Win32k Elevation of Privilege VulnerabilityAn elevation of privilege vulnerability exists in the Windows kernel-mode driver (Win32k.sys) that is caused when it improperly handles objects in memory. An attacker who successfully exploited this vulnerability could gain elevated privileges. An attacker could then install...
Last Update Date: 11 Feb 2015 10:19 Release Date: 11 Feb 2015 3075 Views

RISK: High Risk

High Risk

Microsoft Windows Group Policy Remote Code Execution Vulnerability

A remote code execution vulnerability exists in how Group Policy receives and applies policy data when a domain-joined system connects to a domain controller. To exploit this vulnerability, an attacker would have to convince a victim with a domain-configured system to connect to an...
Last Update Date: 11 Feb 2015 10:18 Release Date: 11 Feb 2015 3143 Views