Showing posts with label CVE. Show all posts
Showing posts with label CVE. Show all posts

Thursday, 29 June 2017

AlienVault v5.4 Addresses 72 vulnerabilities

Several vulnerabilities were discovered in the underlying OS packages in AlienVault USM Appliance and OSSIM v5.3.7 and earlier. All of the vulnerabilities below have been confirmed and fixed in the AlienVault v5.4. AlienVault encourages customers to upgrade all AlienVault appliances to eliminate the vulnerabilities.

See the v5.4 release notice for details on the release.

Microsoft announce another CVE - Win32k Information Disclosure Vulnerability

An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory. An attacker who successfully exploited this vulnerability could obtain information to further compromise the user’s system.

Microsoft has reserved CVE candidate CVE-2017-8554 ready for announcement, but an early indication for MSRC shows the following OS Versions affected:

Windows 10
Windows 8.1
Windows 7

Server 2016
Server 2012 R2
Server 2012
Server 2008 R2
Server 2008

This vulnerability has been rated CVSS 4.7 resulting in a Medium Risk