Home

2023年02月の脆弱性

誤りがあった場合はTwitterに報告をお願いします。-> Twitter《Har-sia》

今月話題になった脆弱性まとめ

CVE-2017-2997

Description from NVD

Adobe Flash Player versions 24.0.0.221 and earlier have an exploitable buffer overflow / underflow vulnerability in the Primetime TVSDK that supports customizing ad information. Successful exploitation could lead to arbitrary code execution.

Information Acquisition Date:2023/03/01
CVSS 2.0: 9.3 HIGH CVSS 3.x: 8.8 HIGH

Highest Score:36 (2023/02/06)

脆弱性情報:Har-sia CVE-2017-2997


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2018-0265


Highest Score:46 (2023/02/03)

脆弱性情報:Har-sia CVE-2018-0265


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2018-43712163


Highest Score:42 (2023/02/26)

脆弱性情報:Har-sia CVE-2018-43712163


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2021-21974

Description from NVD

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

Information Acquisition Date:2023/03/01
CVSS 2.0: 5.8 MEDIUM CVSS 3.x: 8.8 HIGH
This vulnerability may involve a PoC.

Highest Score:99 (2023/02/06)

脆弱性情報:Har-sia CVE-2021-21974


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2022-1613

Description from NVD

The Restricted Site Access WordPress plugin before 7.3.2 prioritizes getting a visitor's IP from certain HTTP headers over PHP's REMOTE_ADDR, which makes it possible to bypass IP-based limitations in certain situations.

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 5.3 MEDIUM

Highest Score:66 (2023/02/20)

脆弱性情報:Har-sia CVE-2022-1613


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2022-38038

Description from NVD

Windows Kernel Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2022-37988, CVE-2022-37990, CVE-2022-37991, CVE-2022-37995, CVE-2022-38022, CVE-2022-38037, CVE-2022-38039.

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 7.8 HIGH

Highest Score:36 (2023/02/22)

脆弱性情報:Har-sia CVE-2022-38038


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2022-39952

Description from NVD

A external control of file name or path in Fortinet FortiNAC versions 9.4.0, 9.2.0 through 9.2.5, 9.1.0 through 9.1.7, 8.8.0 through 8.8.11, 8.7.0 through 8.7.6, 8.6.0 through 8.6.5, 8.5.0 through 8.5.4, 8.3.7 may allow an unauthenticated attacker to execute unauthorized code or commands via specifically crafted HTTP request.

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 9.8 CRITICAL
This vulnerability may involve a PoC.

Highest Score:111 (2023/02/22)

脆弱性情報:Har-sia CVE-2022-39952


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2023-20858

Description from NVD

VMware Carbon Black App Control 8.7.x prior to 8.7.8, 8.8.x prior to 8.8.6, and 8.9.x.prior to 8.9.4 contain an injection vulnerability. A malicious actor with privileged access to the App Control administration console may be able to use specially crafted input allowing access to the underlying server operating system.

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 0.0 None

Highest Score:59 (2023/02/22)

脆弱性情報:Har-sia CVE-2023-20858


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2023-21715

Description from NVD

Microsoft Publisher Security Features Bypass Vulnerability

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 5.0 MEDIUM

Description from Forti

February Microsoft Patch Tuesday Fixes Three Zero-days

Information Acquisition Date:2023/02/17

Affected Products

Impact

Recommended Actions

References


Highest Score:61 (2023/02/15)

脆弱性情報:Har-sia CVE-2023-21715


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2023-21823

Description from NVD

Windows Graphics Component Remote Code Execution Vulnerability

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 7.8 HIGH

Highest Score:56 (2023/02/15)

脆弱性情報:Har-sia CVE-2023-21823


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2023-22501

Description from NVD

An authentication vulnerability was discovered in Jira Service Management Server and Data Center which allows an attacker to impersonate another user and gain access to a Jira Service Management instance under certain circumstances_._ With write access to a User Directory and outgoing email enabled on a Jira Service Management instance, an attacker could gain access to signup tokens sent to users with accounts that have never been logged into. Access to these tokens can be obtained in two cases: * If the attacker is included on Jira issues or requests with these users, or * If the attacker is forwarded or otherwise gains access to emails containing a “View Request” link from these users. Bot accounts are particularly susceptible to this scenario. On instances with single sign-on, external customer accounts can be affected in projects where anyone can create their own account.

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 9.1 CRITICAL

Highest Score:50 (2023/02/03)

脆弱性情報:Har-sia CVE-2023-22501


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2023-23376

Description from NVD

Windows Common Log File System Driver Elevation of Privilege Vulnerability

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 7.8 HIGH

Highest Score:57 (2023/02/15)

脆弱性情報:Har-sia CVE-2023-23376


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2023-23529

Description from NVD

A type confusion issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2.1, iOS 16.3.1 and iPadOS 16.3.1, Safari 16.3. Processing maliciously crafted web content may lead to arbitrary code execution. Apple is aware of a report that this issue may have been actively exploited..

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 0.0 None

Highest Score:141 (2023/02/14)

脆弱性情報:Har-sia CVE-2023-23529


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2023-25136

Description from NVD

OpenSSH server (sshd) 9.1 introduced a double-free vulnerability during options.kex_algorithms handling. This is fixed in OpenSSH 9.2. The double free can be leveraged, by an unauthenticated remote attacker in the default configuration, to jump to any location in the sshd address space. One third-party report states "remote code execution is theoretically possible."

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 9.8 CRITICAL

Highest Score:60 (2023/02/09)

脆弱性情報:Har-sia CVE-2023-25136


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


CVE-2023-25725

Description from NVD

HAProxy before 2.7.3 may allow a bypass of access control because HTTP/1 headers are inadvertently lost in some situations, aka "request smuggling." The HTTP header parsers in HAProxy may accept empty header field names, which could be used to truncate the list of HTTP headers and thus make some headers disappear after being parsed and processed for HTTP/1.0 and HTTP/1.1. For HTTP/2 and HTTP/3, the impact is limited because the headers disappear before being parsed and processed, as if they had not been sent by the client. The fixed versions are 2.7.3, 2.6.9, 2.5.12, 2.4.22, 2.2.29, and 2.0.31.

Information Acquisition Date:2023/03/01
CVSS 2.0: 0.0 None CVSS 3.x: 9.1 CRITICAL

Highest Score:40 (2023/02/15)

脆弱性情報:Har-sia CVE-2023-25725


管理者コメント

(自動翻訳)脆弱性まとめる際にここに自動翻訳を挿入します。次月までお待ちください。(自動翻訳ここまで)

###---###

参考URL:

上に戻る


計15件

Tweet