About this tag
The attacker tag on WindowsForum.com covers security advisories and patch announcements where an attacker exploits vulnerabilities in Microsoft and SAP software. Discussions focus on remote code execution, elevation of privilege, and security feature bypass scenarios. Common themes include unauthenticated attackers targeting SAP NetWeaver, crafted Office files, malicious webpages in Internet Explorer, and specially crafted applications for Windows kernel-mode drivers. The content emphasizes the importance of applying security updates promptly to mitigate risks. For enterprise IT professionals and home users, this tag highlights real-world attack vectors and the need for proactive patch management to protect systems from compromise.
-
AA20-195A: Critical Vulnerability in SAP NetWeaver AS Java
Original release date: July 13, 2020 Summary On July 13, 2020 EST, SAP released a Link Removed to address a critical vulnerability, Link Removed, affecting the SAP NetWeaver Application Server (AS) Java component LM Configuration Wizard. An unauthenticated attacker can exploit this...- News
- Thread
- access application attacker cisa configuration cve-2020-6287 cybersecurity data exploitation integrity java mitigation monitoring netweaver patch recommendations sap security system vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS16-123 - Important: Security Update for Windows Kernel-Mode Drivers (3192892) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (October 11, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The more severe of the vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a...- News
- Thread
- application attacker bulletin control drivers exploitation important kernel-mode microsoft ms16-123 october patch privilege revision security system technical update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-118 - Critical: Cumulative Security Update for Internet Explorer (3192887) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (October 11, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet...- News
- Thread
- admin rights attacker bulletin critical update cumulative update data security exploit internet explorer ms16-118 october patch remote code execution revision note security system control update user account user rights vulnerability webpage threats
- Replies: 0
- Forum: Security Alerts
-
MS16-098 - Important: Security Update for Windows Kernel-Mode Drivers (3178466) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (August 9, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted...- News
- Thread
- 2016 attacker bulletin control crafted application drivers elevation important kernel-mode microsoft ms16-098 patch privilege revision security system update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-100 - Important: Security Update for Secure Boot (3179577) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (August 9, 2016): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow security feature bypass if an attacker installs an affected boot manager and bypasses Windows security...- News
- Thread
- 2016 attacker boot manager bypass microsoft ms16-100 revision note secure boot security security features update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-090 - Important: Security Update for Windows Kernel-Mode Drivers (3171481) - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (July 12, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The more severe of the vulnerabilities could allow elevation of privilege if an attacker logs on to an affected system and runs a...- News
- Thread
- attacker bulletin control drivers elevation of privilege july kernel-mode ms16-090 revision note security system update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS16-070 - Critical: Security Update for Microsoft Office (3163610) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (June 14, 2016): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Office. The vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An attacker who...- News
- Thread
- arbitrary code attacker bulletin critical execution exploitation files june microsoft ms16-070 office patch remote code execution revision security software update user rights vulnerability
- Replies: 0
- Forum: Security Alerts
-
Microsoft TLS FalseStart Update Blocks Cipher Suite Downgrades
Revision Note: V1.0 (May 10, 2016): Advisory published. Summary: FalseStart allows the TLS client to send application data before receiving and verifying the server Finished message. This allows an attacker to launch a man-in-the-middle (MiTM) attack to force the TLS client to encrypt the first...- News
- Thread
- advisory application data attacker cipher cipher suites client downgrade attack encryption falsestart man-in-the-middle microsoft mitm network security revision note security tls transport layer security update version 1.0
- Replies: 0
- Forum: Security Alerts
-
MS15-124 - Critical: Cumulative Security Update for Internet Explorer (3116180) - Version: 1.0
Severity Rating: Critical Revision Note: V1.0 (December 8, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Internet Explorer. The most severe of the vulnerabilities could allow remote code execution if a user views a specially crafted webpage using Internet...- News
- Thread
- 2015 admin rights attacker bulletin critical cumulative exploitation internet explorer ms15-124 patch remote code execution security technet update user account user rights vulnerability webpage
- Replies: 0
- Forum: Security Alerts
-
MS15-135 - Important: Security Update for Windows Kernel-Mode Drivers to Address Elevation...
Severity Rating: Important Revision Note: V1.0 (December 8, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Windows. The vulnerabilities could allow elevation of privilege if an attacker logs on to a target system and runs a specially crafted...- News
- Thread
- 2015 application attacker bulletin critical drivers kernel-mode microsoft ms15-135 patch management privilege protection revision note security software system update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS15-105 - Important: Vulnerability in Windows Hyper-V Could Allow Security Feature Bypass...
Severity Rating: Important Revision Note: V1.0 (September 8, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. The vulnerability could allow security feature bypass if an attacker runs a specially crafted application that could cause Windows...- News
- Thread
- 2015 application attacker bulletin configuration extended security updates feature bypass hyper-v important microsoft ms15-105 patch revision note security technet update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS15-058 - Important: Vulnerabilities in SQL Server Could Allow Remote Code Execution...
Severity Rating: Important Revision Note: V1.0 (July 14, 2015): Bulletin published Summary: This security update resolves vulnerabilities in Microsoft SQL Server. The most severe vulnerabilities could allow remote code execution if an authenticated attacker runs a specially crafted query that is...- News
- Thread
- 2015 attacker authentication database execution risk function call memory management ms15-058 patch query execution remote code execution revision note security server security sql server technet technical bulletin update vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS15-006 - Important: Vulnerability in Windows Error Reporting Could Allow Security Feature...
Severity Rating: Important Revision Note: V1.0 (January 13, 2015): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Windows Error Reporting (WER). The vulnerability could allow security feature bypass if successfully exploited by an attacker. An...- News
- Thread
- admin rights attacker error reporting memory ms15-006 security update user rights vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS14-084 - Critical: Vulnerability in VBScript Scripting Engine Could Allow Remote Code...
Severity Rating: Critical Revision Note: V1.0 (December 9, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the VBScript scripting engine in Microsoft Windows. The vulnerability could allow remote code execution if a user visits a specially...- News
- Thread
- administrative attacker control critical cybersecurity data management execution microsoft patch programs remote code execution security update user account user rights vbscript vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS14-067 - Critical: Vulnerability in XML Core Services Could Allow Remote Code Execution...
Severity Rating: Critical Revision Note: V1.0 (November 11, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a logged-on user visits a specially crafted website that...- News
- Thread
- attacker critical internet explorer microsoft remote code execution security update user awareness vulnerability xml core services
- Replies: 0
- Forum: Security Alerts
-
Vulnerability in Windows Shell Handler Could Allow Elevation of Privilege - Version: 1.0
Severity Rating: Important Revision Note: V1.0 (May 13, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker runs a specially crafted application that uses...- News
- Thread
- attacker credentials elevation microsoft privilege security shell handler update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
Microsoft Security Bulletin MS14-018 - Critical: Cumulative Security Update for Internet...
Severity Rating: Critical Revision Note: V1.1 (April 17, 2014): Revised bulletin to help clarify that although Internet Explorer 10 is not affected by the vulnerabilities described in this bulletin, an update is available for Internet Explorer 10 that includes non-security updates. See the...- News
- Thread
- administrative attacker bulletin code critical cumulative details execution explorer impact internet microsoft patch remote revision rights security update users vulnerability
- Replies: 0
- Forum: Security Alerts
-
MS14-016 - Important : Vulnerability in Security Account Manager Remote (SAMR) Protocol Could...
Severity Rating: Important Revision Note: V1.0 (March 11, 2014): Bulletin published. Summary: This security update resolves one privately reported vulnerability in Microsoft Windows. The vulnerability could allow security feature bypass if an attacker attempts to match passwords to a username...- News
- Thread
- attacker features ms14-016 password protocol samr security update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-081 - Critical : Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code...
Severity Rating: Critical Revision Note: (October 8, 2013) Bulletin published. Summary: This security update resolves seven privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if a user views shared content that...- News
- Thread
- attacker control critical drivers execution kernel-mode microsoft opentype remote code execution security truetype update vulnerability windows
- Replies: 0
- Forum: Security Alerts
-
MS13-087 - Important : Vulnerability in Silverlight Could Allow Information Disclosure...
Severity Rating: Important Revision Note: V1.0 (October 8, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Silverlight. The vulnerability could allow information disclosure if an attacker hosts a website that contains a specially...- News
- Thread
- attacker exploit information disclosure ms13-087 safety security silverlight update vulnerability web content
- Replies: 0
- Forum: Security Alerts