* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Tuesday, September 9, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    Jobs roundup: September 2025 | Blizzard Entertainment appoints Walter Kong SVP of live games/mobile development – GamesIndustry.biz

    Blizzard Entertainment Names Walter Kong as SVP of Live Games and Mobile Development in September 2025 Jobs Update

    Monumental Sports & Entertainment Sets Corporate Direction at Nasdaq – PR Newswire

    Monumental Sports & Entertainment Reveals Bold New Corporate Vision at Nasdaq

    The Secret to What Made ‘CarJack’ Work on As the World Turns – yahoo.com

    The Surprising Secret Behind ‘CarJack’s’ Success on As the World Turns

    Victor Garber on his viral “And Just Like That” toilet scene: ‘I was delighted to be doing something ridiculous’ (exclusive) – yahoo.com

    Victor Garber on his viral “And Just Like That” toilet scene: ‘I was delighted to be doing something ridiculous’ (exclusive) – yahoo.com

    Pendulum Announce Homecoming 2026 Australian Tour – yahoo.com

    Pendulum Announces Thrilling Homecoming Tour Across Australia in 2026

    ITV Studios Launches New Entertainment Label – Global Bulletin – IMDb

    ITV Studios Unveils Exciting New Entertainment Label

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Tri-Counties Bank marks 50 years of growth with focus on technology and personal service – thebusinessjournal.com

    Tri-Counties Bank Celebrates 50 Years of Growth Driven by Technology and Personal Service

    AI will reshape internet, create jobs in West Virginia says High Technology Foundation’s Estep – WV News

    How AI Is Set to Transform the Internet and Boost Job Growth in West Virginia

    Industry partner provides Ferris State Plastics Engineering Technology students with state-of-the-art equipment to gain in-demand skills – Ferris State University

    Industry Partner Equips Ferris State Plastics Engineering Students with Cutting-Edge Technology to Boost In-Demand Skills

    Health Technology Ecosystem – Centers for Medicare & Medicaid Services | CMS (.gov)

    Discover the Future of Health Technology: Innovations Revolutionizing Patient Care

    Coherent Joins LLNL’s STARFIRE Diode Technology Working Group to Advance Inertial Fusion Energy – GlobeNewswire

    Coherent Partners with LLNL’s STARFIRE Team to Drive Breakthroughs in Inertial Fusion Energy

    Gene Associated With Deadly Heart Disease in Golden Retrievers Identified – Technology Networks

    Breakthrough Discovery Uncovers Gene Behind Deadly Heart Disease in Golden Retrievers

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    Jobs roundup: September 2025 | Blizzard Entertainment appoints Walter Kong SVP of live games/mobile development – GamesIndustry.biz

    Blizzard Entertainment Names Walter Kong as SVP of Live Games and Mobile Development in September 2025 Jobs Update

    Monumental Sports & Entertainment Sets Corporate Direction at Nasdaq – PR Newswire

    Monumental Sports & Entertainment Reveals Bold New Corporate Vision at Nasdaq

    The Secret to What Made ‘CarJack’ Work on As the World Turns – yahoo.com

    The Surprising Secret Behind ‘CarJack’s’ Success on As the World Turns

    Victor Garber on his viral “And Just Like That” toilet scene: ‘I was delighted to be doing something ridiculous’ (exclusive) – yahoo.com

    Victor Garber on his viral “And Just Like That” toilet scene: ‘I was delighted to be doing something ridiculous’ (exclusive) – yahoo.com

    Pendulum Announce Homecoming 2026 Australian Tour – yahoo.com

    Pendulum Announces Thrilling Homecoming Tour Across Australia in 2026

    ITV Studios Launches New Entertainment Label – Global Bulletin – IMDb

    ITV Studios Unveils Exciting New Entertainment Label

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Tri-Counties Bank marks 50 years of growth with focus on technology and personal service – thebusinessjournal.com

    Tri-Counties Bank Celebrates 50 Years of Growth Driven by Technology and Personal Service

    AI will reshape internet, create jobs in West Virginia says High Technology Foundation’s Estep – WV News

    How AI Is Set to Transform the Internet and Boost Job Growth in West Virginia

    Industry partner provides Ferris State Plastics Engineering Technology students with state-of-the-art equipment to gain in-demand skills – Ferris State University

    Industry Partner Equips Ferris State Plastics Engineering Students with Cutting-Edge Technology to Boost In-Demand Skills

    Health Technology Ecosystem – Centers for Medicare & Medicaid Services | CMS (.gov)

    Discover the Future of Health Technology: Innovations Revolutionizing Patient Care

    Coherent Joins LLNL’s STARFIRE Diode Technology Working Group to Advance Inertial Fusion Energy – GlobeNewswire

    Coherent Partners with LLNL’s STARFIRE Team to Drive Breakthroughs in Inertial Fusion Energy

    Gene Associated With Deadly Heart Disease in Golden Retrievers Identified – Technology Networks

    Breakthrough Discovery Uncovers Gene Behind Deadly Heart Disease in Golden Retrievers

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Microsoft addresses Office vulnerability attacked by Russian spooks in latest update

August 9, 2023
in Technology
Microsoft addresses Office vulnerability attacked by Russian spooks in latest update
Share on FacebookShare on Twitter

Gina Sanders – stock.adobe.com

Microsoft has issued fixes for over 70 vulnerabilities in its August Patch Tuesday drop, including remedies for CVE-2023-36884, which was disclosed without a fix in July and has been the subject of Kremlin-backed cyber attacks

Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 09 Aug 2023 15:15

Amid the ongoing Black Hat USA and DEF CON cyber jamborees, Microsoft has addressed a little over 70 vulnerabilities in its August Patch Tuesday update, including two zero-days already being exploited, more than 20 remote code execution (RCE) flaws, and six critical bugs.

Of the two zero-days fixes, the first comes in the form of a Defense in Depth Update for Microsoft Office, tagged as ADV23003.

This is a set of mitigations that supposedly breaks the exploit chain used by threat actors to target CVE-2023-36884, an RCE vuln in Microsoft Office which was disclosed in the July update without a fix, and is known to have been exploited by a threat actor linked to Russian intelligence agencies.

Separately, patches for the multiple products affected by this vulnerability are now available and should be applied.

Chris Goett, vice-president of security products at Ivanti, explained the significance of the ADV23303 release. “Microsoft updated the affected products listed in CVE-2023-36884 removing the Office products originally listed in the CVE,” he said.

“The Office products listed in ADV230003 are not directly vulnerable, but can be used in an attack chain to exploit CVE-2023-36884. Microsoft has clarified the changes in the Office updates were a Defense in Depth measure.

“Microsoft recommends applying the Office updates discussed in the advisory in addition to the August Windows OS updates,” he added.

The second zero-day is tracked as CVE-2023-38180, a denial of service vulnerability in .NET and Visual Studio. It is considered to be of low complexity and requires no special privileges or user interaction to exploit.

Nikolas Cemerikic, cyber security engineer at Immersive Labs, explained the scope of the vulnerability.

“A denial of service (DoS) attack involves overrunning it with an excessive volume of requests, which exhausts its available resources, such as processing power, memory, or network bandwidth. Consequently, the application becomes incapable of fulfilling legitimate user requests, limiting its normal functionality,” he said.

“If an attacker, who was suitably positioned on the network exploited this vulnerability, it would cause the Visual Studio application or applications on the same system, which are dependent on the .NET framework to become unavailable.

“Although the attacker would need to be on the same network as the target system, this vulnerability specifically does not require the attacker to have acquired user privileges,” added Cemerikic.

“According to the CVE details code maturity has reached proof-of-concept and it is confirmed to be exploited in the wild,” Ivanti’s Goettl told Computer Weekly in emailed comments.

“The CVE is only rated as Important and the CVSS v3.1 score is 7.5, but taking a risk-based approach this should be treated as a higher priority this month.”

The six critical vulnerabilities this month are all RCE flaws, three within Microsoft Message Queuing – CVE-2023-35385, CVE-2023-36910 and CVE-2023-36911; two within Microsoft Teams – CVE-2023-29328 and CVE-2023-29330; and one within Microsoft Outlook – CVE-2023-36895.

Dustin Childs of Trend Micro’s Zero Day Initiative said that the Microsoft Message Queueing bugs, of which there are several others less dramatic in their scope, were likely to see exploitation in short order as a number of PoCs are already circulating, while the Microsoft Teams vulnerabilities are worth paying attention to as both bear similarities to others that were demonstrated at the 2023 Pwn2Own event.

Also attracting attention this month are a series of six flaws in Microsoft Exchange Server, the most significant of which is CVE-2023-21709, an elevation of privilege (EoP) vulnerability. This is of low complexity and requires no special privileges or user interaction to exploit.

Tenable senior staff research engineer Satnam Narang said: “An unauthenticated attacker could exploit this vulnerability by conducting a brute-force attack against valid user accounts. Despite the high rating, the belief is that brute-force attacks won’t be successful against accounts with strong passwords. However, if weak passwords are in use, this would make brute-force attempts more successful.

“The remaining five vulnerabilities range from a spoofing flaw and multiple remote code execution bugs, though the most severe of the bunch also require credentials for a valid account,” he added.

Read more on Application security and coding requirements


Several Exchange Server flaws fixed on August Patch Tuesday

TomWalat

By: Tom Walat


Critical Adobe ColdFusion flaws chained in ongoing cyber attacks

AlexScroxton

By: Alex Scroxton


Russia-based actor exploited unpatched Office zero day

ArielleWaldman

By: Arielle Waldman


Microsoft users on high alert over dangerous RCE zero-day

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366547633/Microsoft-addresses-Office-vulnerability-attacked-by-Russian-spooks-in-latest-update

Tags: addressesMicrosofttechnology
Previous Post

Huawei a big storage hitter despite international troubles

Next Post

AI interview: Krystal Kauffman, lead organiser, Turkopticon

22 Timeless Money Maxims That Hold up in the Current Economy – Money Talks News

22 Timeless Money Maxims That Still Work in Today’s Economy

September 9, 2025
Jobs roundup: September 2025 | Blizzard Entertainment appoints Walter Kong SVP of live games/mobile development – GamesIndustry.biz

Blizzard Entertainment Names Walter Kong as SVP of Live Games and Mobile Development in September 2025 Jobs Update

September 9, 2025
State Health Care Spending Growth Trends Point to Need for Policy Action – Milbank Memorial Fund

Soaring State Health Care Costs Demand Immediate Policy Solutions

September 9, 2025
Fed rate cut optimism lifts stocks, as investors watch politics across continents – Reuters

Fed Rate Cut Hopes Boost Stocks Amid Global Political Watch

September 9, 2025
Pope Leo XIV: Caring for Creation is our vocation – Vatican News

Pope Leo XIV: Caring for Creation is our vocation – Vatican News

September 9, 2025
Ocean Sciences Meeting will convene in Glasgow Scotland, February 2026 – EurekAlert!

Get Ready for the Ocean Sciences Meeting Making Waves in Glasgow This February 2026!

September 9, 2025
The Christian Science Monitor | Grand Juries Usually Approve Indictments. In LA and DC, They’re Pushing Back. – Loyola Marymount University

Grand Juries Typically Approve Indictments-But in LA and DC, They’re Starting to Push Back

September 9, 2025
Lifestyle Communities Finalizes Ocean Grove Land Sale – TipRanks

Lifestyle Communities Finalizes Ocean Grove Land Sale – TipRanks

September 9, 2025
Tri-Counties Bank marks 50 years of growth with focus on technology and personal service – thebusinessjournal.com

Tri-Counties Bank Celebrates 50 Years of Growth Driven by Technology and Personal Service

September 9, 2025
Bears inform fans of plans to leave Soldier Field, finalize stadium in Arlington Heights for Super Bowl bid – CBS Sports

Bears inform fans of plans to leave Soldier Field, finalize stadium in Arlington Heights for Super Bowl bid – CBS Sports

September 9, 2025

Categories

Archives

September 2025
MTWTFSS
1234567
891011121314
15161718192021
22232425262728
2930 
« Aug    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (814)
  • Economy (832)
  • Entertainment (21,709)
  • General (16,936)
  • Health (9,874)
  • Lifestyle (845)
  • News (22,149)
  • People (834)
  • Politics (839)
  • Science (16,041)
  • Sports (21,331)
  • Technology (15,812)
  • World (813)

Recent News

22 Timeless Money Maxims That Hold up in the Current Economy – Money Talks News

22 Timeless Money Maxims That Still Work in Today’s Economy

September 9, 2025
Jobs roundup: September 2025 | Blizzard Entertainment appoints Walter Kong SVP of live games/mobile development – GamesIndustry.biz

Blizzard Entertainment Names Walter Kong as SVP of Live Games and Mobile Development in September 2025 Jobs Update

September 9, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version