exploitation

  1. MS15-037 - Important: Vulnerability in Windows Task Scheduler Could Allow Elevation of...

    Severity Rating: Important Revision Note: V1.0 (April 14, 2015): Bulletin published. Summary: This security update resolves a vulnerability in Microsoft Windows. An attacker who successfully exploited the vulnerability could leverage a known invalid task to cause Task Scheduler to run a...
  2. TA15-103A: DNS Zone Transfer AXFR Requests May Leak Domain Information

    Original release date: April 13, 2015 Systems Affected Misconfigured Domain Name System (DNS) servers that respond to global Asynchronous Transfer Full Range (AXFR) requests. Overview A remote unauthenticated user may request a DNS zone transfer from a public-facing DNS server. If...
  3. MS15-022 - Critical: Vulnerabilities in Microsoft Office Could Allow Remote Code Execution...

    Severity Rating: Critical Revision Note: V1.0 (March 10, 2015): Bulletin published. Summary: This security update resolves vulnerabilities in Microsoft Office. The most severe of the vulnerabilities could allow remote code execution if a user opens a specially crafted Microsoft Office file. An...
  4. MS15-011 - Critical: Vulnerability in Group Policy Could Allow Remote Code Execution...

    Severity Rating: Critical Revision Note: V1.0 (February 10, 2015): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. A remote code execution vulnerability exists in how group policy receives and applies connection data when a...
  5. MS14-073 - Important: Vulnerability in Microsoft SharePoint Foundation Could Allow Elevation...

    Severity Rating: Important Revision Note: V1.0 (November 11, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft SharePoint Server. An authenticated attacker who successfully exploited this vulnerability could run arbitrary script in...
  6. MS14-076 - Important: Vulnerability in Internet Information Services (IIS) Could Allow...

    Severity Rating: Important Revision Note: V1.0 (November 11, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Internet Microsoft Information Services (IIS) that could lead to a bypass of the "IP and domain restrictions" security feature...
  7. TA14-300A: Phishing Campaign Linked with “Dyre” Banking Malware

    Original release date: October 27, 2014 Systems Affected Microsoft Windows Overview Since mid-October 2014, a phishing campaign has targeted a wide variety of recipients while employing the Dyre/Dyreza banking malware. Elements of this phishing campaign vary from target to target including...
  8. TA14-290A: SSL 3.0 Protocol Vulnerability and POODLE Attack

    Original release date: October 17, 2014 Systems Affected All systems and applications utilizing the Secure Socket Layer (SSL) 3.0 with cipher-block chaining (CBC) mode ciphers may be vulnerable. However, the POODLE (Padding Oracle On Downgraded Legacy Encryption) attack demonstrates this...
  9. MS14-061 - Important: Vulnerability in Microsoft Word and Office Web Apps Could Allow Remote...

    Severity Rating: Important Revision Note: V1.0 (October 14, 2014): Bulletin published. Summary: This security update resolves one privately reported vulnerability in Microsoft Office. The vulnerability could allow remote code execution if an attacker convinces a user to open a specially crafted...
  10. MS14-046 - Important: Vulnerability in .NET Framework Could Allow Security Feature Bypass...

    Severity Rating: Important Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft .NET Framework. The vulnerability could allow security feature bypass if a user visits a specially crafted website. In a...
  11. MS14-043 - Critical: Vulnerability in Windows Media Center Could Allow Remote Code Execution...

    Severity Rating: Critical Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if a user opens a specially crafted Microsoft Office file that...
  12. MS14-048 - Important: Vulnerability in OneNote Could Allow Remote Code Execution (2977201) -...

    Severity Rating: Important Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Microsoft OneNote. The vulnerability could allow remote code execution if a specially crafted file is opened in an affected version...
  13. MS14-050 - Important: Vulnerability in Microsoft SharePoint Server Could Allow Elevation of...

    Severity Rating: Important Revision Note: V1.0 (August 12, 2014): Bulletin published. Summary: This security update resolves one privately reported vulnerability in Microsoft SharePoint Server. An authenticated attacker who successfully exploited this vulnerability could use a specially crafted...
  14. TA14-013A: NTP Amplification Attacks Using CVE-2013-5211

    Original release date: January 13, 2014 | Last revised: February 05, 2014 Systems Affected NTP servers Overview A Network Time Protocol (NTP) Amplification attack is an emerging form of Distributed Denial of Service (DDoS) that relies on the use of publically accessible NTP servers to...
  15. Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Execution - Version: 2.0

    Severity Rating: Critical Revision Note: V2.0 (January 14, 2014): Rereleased bulletin to announce the reoffering of the 2862330 update to systems running Windows 7 or Windows Server 2008 R2. See the Update FAQ for details. Summary: This security update resolves seven privately reported...
  16. VIDEO From Missingno to Heartbleed: Buffer Exploits and Buffer Overflows

    :eek: :headache: :shocked:
  17. MS13-102 - Important : Vulnerability in LRPC Client Could Allow Elevation of Privilege...

    Severity Rating: Important Revision Note: V1.0 (December 10, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in Windows. The vulnerability could allow elevation of privilege if an attacker sends a specially crafted LPC port message to any LPC...
  18. Microsoft Security Advisory (2914486): Vulnerability in Microsoft Windows Kernel Could Allow...

    Revision Note: V1.0 (November 27, 2013): Advisory published. Summary: Microsoft is investigating new reports of a vulnerability in a kernel component of Windows XP and Windows Server 2003. We are aware of limited, targeted attacks that attempt to exploit this vulnerability. Continue reading...
  19. MS13-060 - Critical : Vulnerability in Unicode Scripts Processor Could Allow Remote Code...

    Severity Rating: Critical Revision Note: V1.0 (August 13, 2013): Bulletin published. Summary: This security update resolves a privately reported vulnerability in the Unicode Scripts Processor included in Microsoft Windows. The vulnerability could allow remote code execution if a user viewed a...
  20. MS13-053 - Critical : Vulnerabilities in Windows Kernel-Mode Drivers Could Allow Remote Code Executi

    Severity Rating: Critical Revision Note: V1.0 (July 9, 2013): Bulletin published. Summary: This security update resolves two publicly disclosed and six privately reported vulnerabilities in Microsoft Windows. The most severe vulnerability could allow remote code execution...