Security Vulnerabilities
- CVEs Published In December 2023
Microsoft Dynamics 365 Finance and Operations Denial of Service Vulnerability
Windows DNS Spoofing Vulnerability
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Azure Machine Learning Compute Instance for SDK Users Information Disclosure Vulnerability
Windows MSHTML Platform Remote Code Execution Vulnerability
Microsoft USBHUB 3.0 Device Driver Remote Code Execution Vulnerability
A vulnerability in the AnyConnect SSL VPN feature of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, remote attacker to send packets with another VPN user's source IP address. This vulnerability is due to improper validation of the packet's inner source IP address after decryption. An attacker could exploit this vulnerability by sending crafted packets through the tunnel. A successful exploit could allow the attacker to send a packet impersonating another VPN user's IP address. It is not possible for the attacker to receive return packets.
Windows Media Remote Code Execution Vulnerability
Microsoft Outlook for Mac Spoofing Vulnerability
Umbraco is an ASP.NET content management system (CMS). Starting in version 8.0.0 and prior to versions 8.18.10, 10.7.0, and 12.3.0, Backoffice users with send for approval permission but not publish permission are able to publish in some scenarios. Versions 8.18.10, 10.7.0, and 12.3.0 contains a patch for this issue. No known workarounds are available.