2023年8月16日星期三

Microsoft Monthly Security Update (June 2023)

Last Update Date: 16 Aug 2023 Release Date: 14 Jun 2023

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

Microsoft has released monthly security update for their products:

 

[Updated on 2023-06-21]

Installation of the June 2023 Windows update will not enable the resolution of the CVE-2023-32019 vulnerability. To enable the resolution, please refer to the following reference link: https://support.microsoft.com/en-gb/topic/kb5028407-how-to-manage-the-vulnerability-associated-with-cve-2023-32019-bd6ed35f-48b1-41f6-bd19-d2d97270f080

 

[Updated on 2023-08-16]

Microsoft has been released the mitigation of CVE-2023-32019 vulnerability enabled by default. To apply the enabled by default resolution, install the August 2023 Windows update that is dated on or after August 8, 2023. No further user action is required.

 

Vulnerable ProductRisk LevelImpactsNotes
BrowserMedium Risk Medium RiskSecurity Restriction Bypass
Elevation of Privilege
Information Disclosure
 
Exchange ServerMedium Risk Medium RiskRemote Code Execution 
Microsoft DynamicsLow Risk Low RiskSpoofing 
Developer ToolsMedium Risk Medium RiskRemote Code Execution
Denial of Service
Information Disclosure
Spoofing
Elevation of Privilege
 
WindowsMedium Risk Medium RiskDenial of Service
Elevation of Privilege
Security Restriction Bypass
Information Disclosure
Remote Code Execution
Spoofing
 
Microsoft OfficeMedium Risk Medium RiskRemote Code Execution
Elevation of Privilege
Denial of Service
Spoofing
 
AzureLow Risk Low RiskSpoofing 
Extended Security Updates (ESU)Medium Risk Medium RiskElevation of Privilege
Remote Code Execution
Denial of Service
Information Disclosure
Spoofing
 

 

Number of 'Extremely High Risk' product(s): 0

Number of 'High Risk' product(s): 0

Number of 'Medium Risk' product(s): 6

Number of 'Low Risk' product(s): 2

Evaluation of overall 'Risk Level': Medium Risk

 


Impact

  • Denial of Service
  • Elevation of Privilege
  • Information Disclosure
  • Remote Code Execution
  • Spoofing
  • Security Restriction Bypass

System / Technologies affected

  • Browser
  • Exchange Server
  • Microsoft Dynamics
  • Developer Tools
  • Windows
  • Microsoft Office
  • Azure
  • Extended Security Updates (ESU)

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  •  Apply fixes issued by the vendor.

Vulnerability Identifier


Source


Related Link

2023年8月15日星期二

Debian Linux 內核多個漏洞

發佈日期: 2023年08月15日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Debian Linux 內核發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發權限提升及洩露敏感資料。


影響

  • 權限提升
  • 資料洩露

受影響之系統或技術

  • Debian 10 buster  5.10.179-5~deb10u1 以前的版本
  • Debian bullseye 5.10.179-5  以前的版本
  • Debian bookworm 6.1.38-4 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

 

安裝供應商提供的修補程式:


漏洞識別碼


資料來源


相關連結

Debian Linux Kernel Multiple Vulnerabilities

Release Date: 15 Aug 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Debian Linux Kernel. A remote attacker could exploit some of these vulnerabilities to trigger elevation of privilege and sensitive information disclosure on the targeted system.


Impact

  • Elevation of Privilege
  • Information Disclosure

System / Technologies affected

  • Debian 10 buster versions prior to 5.10.179-5~deb10u1
  • Debian bullseye versions prior to 5.10.179-5
  • Debian bookworm versions prior to 6.1.38-4

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

三星產品多個漏洞

發佈日期: 2023年08月15日

風險: 中度風險

類型: 操作系統 - 流動裝置及操作系統

類型: 流動裝置及操作系統

於三星產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行程式碼、篡改及洩露敏感資料。


Samsung Products Multiple Vulnerabilities

Release Date: 15 Aug 2023

RISK: Medium Risk

TYPE: Operating Systems - Mobile & Apps

TYPE: Mobile & Apps

Multiple vulnerabilities were identified in Samsung Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution, data manipulation and sensitive information disclosure on the targeted system.


Ubuntu Linux 核心多個漏洞

發佈日期: 2023年08月15日

風險: 中度風險

類型: 操作系統 - LINUX

類型: LINUX

於 Ubuntu 產品發現多個漏洞。遠端攻擊者可利用這些漏洞,於目標系統觸發阻斷服務狀況、權限提升、遠端執行任意程式碼及洩露敏感資料。

 

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 15 Aug 2023

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

Multiple vulnerabilities were identified in Ubuntu Products. A remote attacker could exploit some of these vulnerabilities to trigger denial of service condition, elevation of privilege, remote code execution and sensitive information disclosure on the targeted system.


Python 遠端執行程式碼漏洞

發佈日期: 2023年08月14日

風險: 中度風險

類型: 操作系統 - 應用程式平台

類型: 應用程式平台

於 Python 發現一個漏洞。遠端攻擊者可利用此漏洞,於目標系統觸發遠端執行任意程式碼、洩露敏感資料及繞過保安限制。


影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • Python 3.12 之前的版本
  • Python 3.11.4 之前的版本
  • Python 3.10.12 之前的版本
  • Python 3.9.17 之前的版本
  • Python 3.8.17 之前的版本
  • Python 3.7.17 之前的版本

解決方案

在安裝軟體之前,請先瀏覽軟體供應商之網站,以獲得更多詳細資料。

 

 
 
 
 

漏洞識別碼


資料來源


相關連結

Python Remote Code Execution Vulnerability

Release Date: 14 Aug 2023

RISK: Medium Risk

TYPE: Operating Systems - Application Platforms

TYPE: Application Platforms

A vulnerability was identified in Python. A remote attacker could exploit this vulnerability to trigger remote code execution, sensitive information disclosure and security restriction bypass on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Python version prior to 3.12
  • Python version prior to 3.11.4
  • Python version prior to 3.10.12
  • Python version prior to 3.9.17
  • Python version prior to 3.8.17
  • Python version prior to 3.7.17

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

 


Vulnerability Identifier


Source


Related Link

2023年8月11日星期五

Node.js 多個漏洞

發佈日期: 2023年08月10日

風險: 中度風險

類型: 伺服器 - 其他伺服器

類型: 其他伺服器

於 Node.js 發現一些漏洞,遠端攻擊者可利用這些漏洞,於目標系統觸發遠端執行程式碼、繞過保安限制及敏感資料洩露。

 

影響

  • 遠端執行程式碼
  • 繞過保安限制
  • 資料洩露

受影響之系統或技術

  • Node.js 16.20.2 (LTS) 以前的版本
  • Node.js 18.17.1 (LTS) 以前的版本
  • Node.js 20.5.1 以前的版本

解決方案

在安裝軟體之前,請先瀏覽供應商之網站,以獲得更多詳細資料。

  • 更新至 Node.js 16.20.2 (LTS) 版本
  • 更新至 Node.js 18.17.1 (LTS) 版本
  • 更新至 Node.js 20.5.1 版本

漏洞識別碼


資料來源


相關連結

Node.js Multiple Vulnerabilities

Release Date: 10 Aug 2023

RISK: Medium Risk

TYPE: Servers - Other Servers

TYPE: Other Servers

Multiple vulnerabilities have been identified in Node.js. A remote attacker can exploit these vulnerabilities to trigger remote code execution, security restriction bypass and sensitive information disclosure on the targeted system.


Impact

  • Remote Code Execution
  • Security Restriction Bypass
  • Information Disclosure

System / Technologies affected

  • Node.js versions prior to 16.20.2 (LTS)
  • Node.js versions prior to 18.17.1 (LTS)
  • Node.js versions prior to 20.5.1

Solutions

Before installation of the software, please visit the vendor web-site for more details.

  • Update to Node.js version 16.20.2 (LTS)
  • Update to Node.js version 18.17.1 (LTS)
  • Update to Node.js version 20.5.1

Vulnerability Identifier


Source


Related Link

F5 BIG-IP 遠端執行程式碼漏洞

F5 BIG-IP 遠端執行程式碼漏洞 發佈日期 : 2026 年 09 月 23 日 於 F5 BIG-IP 發現一個漏洞。遠端攻擊者可利用這漏洞,於目標系統觸發遠端執行程式碼狀況。   注意: CVE-2026-94127 正被廣泛利用。此漏洞僅在 B...