article thumbnail

Microsoft’s February 2024 Patch Tuesday Addresses 73 CVEs (CVE-2024-21351, CVE-2024-21412)

Tenable

Moderate CVE-2024-21351 | Windows SmartScreen Security Feature Bypass Vulnerability CVE-2024-21351 is a security feature bypass vulnerability in Windows SmartScreen. Since 2022, there have been five Windows SmartScreen vulnerabilities disclosed across Patch Tuesday. It was assigned a CVSSv3 score of 7.6 and is rated moderate.

LAN 124
article thumbnail

CVE-2020-1472: 'Zerologon' Vulnerability in Netlogon Could Allow Attackers to Hijack Windows Domain Controller

Tenable

Security researchers reveal how the cryptographic authentication scheme in Netlogon can be exploited to take control of a Windows domain controller (DC). This disclosure follows a previous Netlogon related vulnerability, CVE-2019-1424 , which Secura detailed at the end of last year. Background. the maximum score. the maximum score.

Windows 114
Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

Microsoft’s October 2023 Patch Tuesday Addresses 103 CVEs (CVE-2023-36563, CVE-2023-41763)

Tenable

Successful exploitation could lead to the disclosure of New Technology LAN Manager (NTLM) hashes. Researcher Florian Hauser of Code White GmbH published a two-part blog series in September 2022 investigating Skype for Business 2019. However, this vulnerability is noted to have been publicly disclosed previously. and rated critical.

Windows 114
article thumbnail

How COVID-19 Response Is Expanding the Cyberattack Surface

Tenable

This post is intended to provide guidance for security teams, sysadmins and end users alike about the VPNs, SMTP servers, Windows Remote Desktop Protocols, browsers and routers working overtime to keep organizations up and running. The remote environment: Windows Remote Desktop Protocol, web browsers and home networks.

LAN 62
article thumbnail

SMB Revealed

Infinidat

Tue, 02/26/2019 - 9:48am. mostly in the Windows OS environment. Microsoft adopted it in its LAN Manager product and has continued to drive the development of the protocol ever since. We clearly see that the real demand is not for a real Windows file sharing experience, not just the SMB protocol. Eric Klinefelter.

SMB 66
article thumbnail

One Year Later: What Can We Learn from Zerologon?

Tenable

CVE-2020-1350: Wormable Remote Code Execution Vulnerability in Windows DNS Server Disclosed (SIGRed). Copy-Paste Compromises: Threat Actors Target Telerik UI, Citrix, and SharePoint Vulnerabilities (CVE-2019-18935). CVE-2019-0230: Apache Struts Potential Remote Code Execution Vulnerability. September 1. Secura Whitepaper.

article thumbnail

Best of…: Classic WTF: The Glitch Who Stole Christmas

The Daily WTF

It's Christmas, and we're going to spend the next week remembering the best moments of 2019, but for now, let's go back to an old Christmas classic. They’d stand, lan-on-lan. All their windows were dark. Every Dev down in Devville liked Christmas a lot…. But the PM who lived in the corner office did NOT!

LAN 15