Skip to main content

Security Bulletin

Filter by:

RISK: Medium Risk

Medium Risk

Network Location Awareness Service Security Feature Bypass Vulnerability

A security feature bypass vulnerability exists in the Network Location Awareness (NLA) service that could unintentionally relax the firewall policy and/or configuration of certain services. This could increase the surface exposed to an attacker. The vulnerability is caused when the NLA service fails to...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 4007 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Components Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in the TS WebProxy Windows component. The vulnerability is caused when Windows fails to properly sanitize file paths. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 3897 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows User Profile Service Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in how the Windows User Profile Service (ProfSvc) validates user privilege. An authenticated attacker who successfully exploits the vulnerability could leverage the Windows User Profile Service (ProfSvc) to load registry hives associated with other user accounts and potentially execute...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 3992 Views

RISK: High Risk

High Risk

Microsoft Windows Telnet Service Remote Code Execution Vulnerability

A buffer overflow vulnerability exists in Windows Telnet service that could allow remote code execution. The vulnerability is caused when the Telnet service improperly validates user input. An attacker could attempt to exploit this vulnerability by sending specially crafted telnet packets to a Windows server, and if...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 4415 Views

RISK: Medium Risk

Medium Risk

Microsoft Windows Application Compatibility Cache Elevation of Privilege Vulnerability

An elevation of privilege vulnerability exists in how the Microsoft Windows Application Compatibility Infrastructure (AppCompat) improperly checks the authorization of the caller's impersonation token. An attacker could attempt to exploit this to run a privileged application. The update addresses the vulnerability by implementing proper...
Last Update Date: 15 Jan 2015 Release Date: 14 Jan 2015 3931 Views

RISK: High Risk

High Risk

Adobe Flash Player Multiple Vulnerabilities

Multiple vulnerabilities were identified in Adobe Flash Player. A remote user can cause arbitrary code to be executed on the target user's system, and obtain potentially sensitive information. A remote user can create specially crafted Flash content that, when loaded by the target user...
Last Update Date: 14 Jan 2015 09:47 Release Date: 14 Jan 2015 3962 Views

RISK: High Risk

High Risk

Windows Kernel Elevation of Privilege Vulnerability

A vulnerability has been identified in Windows Kernel, which can be exploited by local user to obtain elevated privileges on the target system. The NtApphelpCacheControl() function in 'ahcache.sys' does not properly validate the caller's impersonation token for administrator privileges. A...
Last Update Date: 5 Jan 2015 10:26 Release Date: 5 Jan 2015 4309 Views

RISK: Medium Risk

Medium Risk

Docker Multiple Vulnerabilities

Multiple vulnerabilities have been identified in Docker, which can be exploited by malicious users to bypass certain security restrictions and by malicious people to manipulate certain data.An error when extracting images or mounting volumes can be exploited to e.g. manipulate certain...
Last Update Date: 29 Dec 2014 10:13 Release Date: 29 Dec 2014 4155 Views

RISK: High Risk

High Risk

"Misfortune Cookie" Vulnerability on Multiple Broadband Routers

Many home and office/home office (SOHO) routers have been identitied to be using vulnerable versions of the Allegro RomPager embedded web server. Allegro RomPager versions prior to 4.34 contain a vulnerability in cookie processing code that can be leveraged to grant attackers administrative...
Last Update Date: 22 Dec 2014 10:56 Release Date: 22 Dec 2014 4237 Views

RISK: Medium Risk

Medium Risk

Network Time Protocol daemon (ntpd) Multiple Vulnerabilities

The buffer overflow vulnerabilities were identified in ntpd, which may allow a remote unauthenticated attacker to execute arbitrary malicious code with the privilege level of the ntpd process. The weak default key and non-cryptographic random number generator in ntp-keygen may allow an attacker to...
Last Update Date: 22 Dec 2014 10:45 Release Date: 22 Dec 2014 4475 Views