Microsoft and other software companies have released their monthly updates for the month of March. In total Microsoft has fixed 101 vulnerabilities both of them are zero-days. Additionally, Adobe fixed a zero-day in ColdFusion.
The Common Vulnerabilities and Exposures (CVE) database lists publicly disclosed (zero-day) security flaws. The CVEs are:
CVE-2023-23397: a critical Microsoft Outlook Elevation of Privilege (EoP) vulnerability. External attackers could send specially crafted emails to induce a connection from the victim to an external UNC site that they control. This would leak the victim's Net-NTLMv2 hashes to the attacker, who could then verify the victim's identity.
The vulnerability could be used for "pass-the-hash" attacks.
CVE-2023-24880: a moderate Windows SmartScreen security feature bypass vulnerability. An attacker could create a malicious file that would evade Mark of the Web (MOTW) defenses, resulting in limited integrity of security features such as Protected View in Microsoft Office that rely on MOTW. This vulnerability was reportedly used in attacks related to ransomware.
CVE-2023-26360: ranked as a #1 priority vulnerability in Adobe ColdFusion. The vulnerability could lead to arbitrary code execution.
Adobe says it is aware that CVE-2023-26360 has already been exploited online in very limited attacks targeting Adobe ColdFusion.
Η company συνιστά την ενημέρωση των εκδόσεων ColdFusion 2021 και 2018 JDK/JRE στην τελευταία version LTS for JDK 11. Applying the ColdFusion update without a corresponding JDK update will NOT secure the server.