Security Vulnerabilities
- CVEs Published In February 2024
Dynamics 365 Sales Spoofing Vulnerability
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Insufficient verification of data authenticity in
the configuration state machine may allow a local attacker to potentially load
arbitrary bitstreams.
Zimbra Collaboration before Kepler 9.0.0 Patch 38 GA allows DOM-based JavaScript injection in the Modern UI.
Azure DevOps Server Remote Code Execution Vulnerability
Microsoft Office Remote Code Execution Vulnerability
Azure Stack Hub Spoofing Vulnerability
Windows Hyper-V Denial of Service Vulnerability
In Zimbra Collaboration (ZCS) 8.8.15 and 9.0, a closed account (with 2FA and generated passwords) can send e-mail messages when configured for Imap/smtp.
An issue was discovered in Zimbra Collaboration (ZCS) 8.8.15, 9.0, and 10.0. Through the help document endpoint in webmail, an attacker can inject JavaScript or HTML code that leads to cross-site scripting (XSS). (Adding an adequate message to avoid malicious code will mitigate this issue.)