Remove what-is-a-cve
article thumbnail

What Is a CVE? Common Vulnerabilities and Exposures Explained

Heimadal Security

Vulnerability management is quintessential for a successful cybersecurity strategy, and CVEs are an integral part of it. You might have heard the acronym thrown around before, but what does it stand for? The post What Is a CVE? Common Vulnerabilities and Exposures Explained appeared first on Heimdal Security Blog.

article thumbnail

Patch Tuesday, November 2020 Edition

Krebs on Security

” A chief concern among all these updates this month is CVE-2020-17087 , which is an “important” bug in the Windows kernel that is already seeing active exploitation. Unfortunately, this is exactly what Google researchers described witnessing recently. In essence, it would have to be chained with another exploit.

Software 275
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

article thumbnail

Microsoft Issues Emergency Patch for Windows Flaw

Krebs on Security

At issue is CVE-2021-34527 , which involves a flaw in the Windows Print Spooler service that could be exploited by attackers to run code of their choice on a target’s system. Chances are, it will show what’s pictured in the screenshot below — that KB5004945 is available for download and install.

Backups 328
article thumbnail

Multiple APT groups exploited WinRAR flaw CVE-2023-38831

Security Affairs

Google’s Threat Analysis Group (TAG) reported that in recent weeks multiple nation-state actors were spotted exploiting the vulnerability CVE-2023-38831 in WinRAR. “Hours after the blog post was released, proof of concepts and exploit generators were uploaded to public GitHub repositories. . ” reported Google TAG.

article thumbnail

Microsoft Patch Tuesday, April 2021 Edition

Krebs on Security

Microsoft released updates to fix four more flaws in Exchange Server versions 2013-2019 ( CVE-2021-28480 , CVE-2021-28481 , CVE-2021-28482 , CVE-2021-28483 ). A Microsoft blog post published along with today’s patches urges Exchange Server users to make patching their systems a top priority.

article thumbnail

BlueKeep: Understanding the Critical RDP Vulnerability

Heimadal Security

What Is the BlueKeep Vulnerability? Also known as CVE-2019-0708, the vulnerability first emerged in 2019 and is a “wormable” remote code execution vulnerability, being noted first by the UK National Cyber Security Centre and, on 14 May 2019, reported by Microsoft.

article thumbnail

Microsoft Patch Tuesday, November 2021 Edition

Krebs on Security

Microsoft’s revised, more sparse security advisories don’t offer much detail on what exactly is being bypassed in Excel with this flaw. The other critical flaw patched today that’s already being exploited in the wild is CVE-2021-42321 , yet another zero-day in Microsoft Exchange Server.

Backups 243