Security Affairs
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112|Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch|Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION|Hack One Robot, Reach the Next: Unitree G1 Security Flaws|Rhysida Ransomware Group Targets Berlin Government Ahead of Vote|Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator|Love Electric Breach: 877,000 Driver Records Offered for $600|Trump Targets Foreign Technology in New U.S. Power Grid Security Order|U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog|Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 112|Hackers Are Probing PaperCut Servers, and 47% Still Have No Patch|Security Affairs newsletter Round 592 by Pierluigi Paganini – INTERNATIONAL EDITION|Hack One Robot, Reach the Next: Unitree G1 Security Flaws|Rhysida Ransomware Group Targets Berlin Government Ahead of Vote|Philippine Nuclear and Naval Targets Hit by Suspected Chinese Operator|Love Electric Breach: 877,000 Driver Records Offered for $600|Trump Targets Foreign Technology in New U.S. Power Grid Security Order|U.S. CISA adds ownCloud, Linux Kernel, and JFrog Artifactory flaws to its Known Exploited Vulnerabilities catalog|Russian APT BlueDelta Uses HOOKEDGE to Target Defense and Diplomatic Organizations|PaperCut Zero-Day Under Active Attack: Emergency Patch Released|U.S. CISA adds Red Hat, Linux Kernel, Ajax.NET Professional, Microsoft SQL Server, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog|
Advertisement

Ad Placeholder

Full Width × 90

Breaking News

Microsoft September 2023 Patch Tuesday fixed 2 actively exploited zero-day flaws

Microsoft September 2023 Patch Tuesday addressed 59 new flaws, including two vulnerabilities under active attack. Microsoft September 2023 Patch Tuesday security updates addressed 59 vulnerabilities, including two actively exploited zero-day. The flaws addressed by the company impact Microsoft Windows and Windows Components; Exchange Server; Office and Office Components; .NET and Visual Studio; Azure; Microsoft Dynamics; […]

Microsoft Patch Tuesday

Microsoft September 2023 Patch Tuesday addressed 59 new flaws, including two vulnerabilities under active attack.

Microsoft September 2023 Patch Tuesday security updates addressed 59 vulnerabilities, including two actively exploited zero-day.

The flaws addressed by the company impact Microsoft Windows and Windows Components; Exchange Server; Office and Office Components; .NET and Visual Studio; Azure; Microsoft Dynamics; and Windows Defender.

The company also addressed two external bugs and four Chromium bugs.

Five of the vulnerabilities fixed by the IT giant are rated Critical, 55 are rated Important, and one is rated Moderate in severity.

“Two of the CVEs released today are listed as being under active attack at the time of release while only one is listed as publicly known.” reported ZDI.

The two actively exploited zero-day vulnerabilities are:

  • CVE-2023-36802 – Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability – An attacker can trigger the vulnerability to gain SYSTEM privileges.
  • CVE-2023-36761 – Microsoft Word Information Disclosure Vulnerability – An attacker can exploit this vulnerability to lead the disclosure of NTLM hashes

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Microsoft September 2023 Patch Tuesday)