Today, Microsoft released a patch for a vulnerability with the worm potential in the SMBv3…
For example, in August Tuesday, Microsoft patched two 0-day vulnerabilities that were under attacks, and in April three 0-day vulnerabilities were under active hackers attacks. You can also remember the vulnerability with the potential of the worm in the SMBv3 protocol. Nevertheless, come on, today we have good news.
Thirty-two out of 129 problems allowed remote execution of arbitrary code, and more than 20 of them were assigned critical status, so, they were the most dangerous vulnerabilities of this month. Critical RCE bugs were found in the following products:
All of the listed vulnerabilities are very dangerous, especially those that affect Windows itself, SharePoint and Dynamics 365 (since large corporate networks often use these systems).
It necessary to say that one of the most dangerous problems of this month experts call a bug in Microsoft Exchange Server (CVE-2020-16875) – an RCE vulnerability that scored 9.1 points out of 10 on the CVSS scale.
“In essence, this bug allows simply sending a specially prepared letter to a vulnerable server, and this can lead to the launch of arbitrary code with System-level rights”, — explain the information security specialists.
The issue affects Microsoft Exchange 2016 and 2019.
Less dangerous bugs that have received the status of “important” were found in Windows, Active Directory, Active Directory Federation Services (ADFS), Internet Explorer Browser Helper, Jet Database Engine, ASP.NET Core, Dynamics 365, Excel, Graphics Component, Office, Office SharePoint, SharePoint Server, SharePoint, Word, OneDrive for Windows, Scripting Engine, Visual Studio, Win32k, Windows Defender Application Control, Windows DNS, and so on.
Most of these issues are related to potential information disclosure, privilege escalation, and XSS. Certain vulnerabilities can also lead to remote code execution and can allow bypassing, spoofing, or denial of service.
Pbmsoultions.com is a domain that tries to trick you into clik to its browser notifications…
Prizestash.com is a site that tries to trick you into subscribing to its browser notifications…
Verifiedbreaking.com is a domain that tries to force you into subscribing to its browser notifications…
Themoneyminutes.com is a domain that tries to force you into subscribing to its browser notifications…
News-xcidizi.com is a domain that tries to trick you into clik to its browser notifications…
Everytraffic-flow.com is a domain that tries to trick you into subscribing to its browser notifications…