* . *
  • About
  • Advertise
  • Privacy & Policy
  • Contact
Saturday, August 16, 2025
Earth-News
  • Home
  • Business
  • Entertainment
    ‘The Rainmaker’ Premiere: Milo Callaghan Breaks Down Rudy Baylor’s ‘Misguided Valor’ – The Laconia Daily Sun

    Inside ‘The Rainmaker’ Premiere: Milo Callaghan Uncovers the Real Story Behind Rudy Baylor’s Misguided Valor

    Suicide Squad Member Gets New Origin in Absolute Flash – yahoo.com

    Suicide Squad Member Unveiled with Exciting New Origin in Absolute Flash

    I’ll miss the chaos of ‘And Just like That…’ (and Che Diaz too) – yahoo.com

    Why I’ll Truly Miss the Wild Ride of ‘And Just Like That…’ (and Che Diaz!)

    Webtoon Entertainment Stages Recovery With Disney’s Stamp of Approval – The Wall Street Journal

    Webtoon Entertainment Soars to New Heights with Disney’s Stamp of Approval

    Georgia Tech Launches Arts, Entertainment, and Creative Technologies Degree – Georgia Tech News Center

    Georgia Tech Unveils Exciting New Degree in Arts, Entertainment, and Creative Technologies

    John Davison departs from IGN Entertainment – GamesIndustry.biz

    John Davison Steps Down from IGN Entertainment Leadership

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Vermont famers say new technology is changing the state’s agriculture industry – News Channel 3-12

    Vermont Farmers Embrace New Technology Transforming the State’s Agriculture Industry

    Verb Technology Reports Revenue Growth Amidst Strategic Expansions – TipRanks

    Verb Technology Soars with Impressive Revenue Growth Driven by Strategic Expansions

    Midwest Technology Summit held in Fargo – WDAY Radio

    Midwest Technology Summit held in Fargo – WDAY Radio

    K1 Semiconductor Joins Chicago Quantum Exchange To Advance Wafer Technology. – Quantum Zeitgeist

    K1 Semiconductor Partners with Chicago Quantum Exchange to Revolutionize Wafer Technology

    Indirect tax transformation: Navigating change, embracing technology – Thomson Reuters tax and accounting

    Revolutionizing Indirect Tax: Embracing Technology to Navigate Change

    California’s wildfire moonshot: How new technology will defeat advancing flames – Los Angeles Times

    California’s Wildfire Revolution: How Cutting-Edge Technology Is Poised to Stop Raging Flames

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
  • Home
  • Business
  • Entertainment
    ‘The Rainmaker’ Premiere: Milo Callaghan Breaks Down Rudy Baylor’s ‘Misguided Valor’ – The Laconia Daily Sun

    Inside ‘The Rainmaker’ Premiere: Milo Callaghan Uncovers the Real Story Behind Rudy Baylor’s Misguided Valor

    Suicide Squad Member Gets New Origin in Absolute Flash – yahoo.com

    Suicide Squad Member Unveiled with Exciting New Origin in Absolute Flash

    I’ll miss the chaos of ‘And Just like That…’ (and Che Diaz too) – yahoo.com

    Why I’ll Truly Miss the Wild Ride of ‘And Just Like That…’ (and Che Diaz!)

    Webtoon Entertainment Stages Recovery With Disney’s Stamp of Approval – The Wall Street Journal

    Webtoon Entertainment Soars to New Heights with Disney’s Stamp of Approval

    Georgia Tech Launches Arts, Entertainment, and Creative Technologies Degree – Georgia Tech News Center

    Georgia Tech Unveils Exciting New Degree in Arts, Entertainment, and Creative Technologies

    John Davison departs from IGN Entertainment – GamesIndustry.biz

    John Davison Steps Down from IGN Entertainment Leadership

  • General
  • Health
  • News

    Cracking the Code: Why China’s Economic Challenges Aren’t Shaking Markets, Unlike America’s” – Bloomberg

    Trump’s Narrow Window to Spread the Truth About Harris

    Trump’s Narrow Window to Spread the Truth About Harris

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    Israel-Gaza war live updates: Hamas leader Ismail Haniyeh assassinated in Iran, group says

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    PAP Boss to Niger Delta Youths, Stay Away from the Protest

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Court Restricts Protests In Lagos To Freedom, Peace Park

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Fans React to Jazz Jennings’ Inspiring Weight Loss Journey

    Trending Tags

    • Trump Inauguration
    • United Stated
    • White House
    • Market Stories
    • Election Results
  • Science
  • Sports
  • Technology
    Vermont famers say new technology is changing the state’s agriculture industry – News Channel 3-12

    Vermont Farmers Embrace New Technology Transforming the State’s Agriculture Industry

    Verb Technology Reports Revenue Growth Amidst Strategic Expansions – TipRanks

    Verb Technology Soars with Impressive Revenue Growth Driven by Strategic Expansions

    Midwest Technology Summit held in Fargo – WDAY Radio

    Midwest Technology Summit held in Fargo – WDAY Radio

    K1 Semiconductor Joins Chicago Quantum Exchange To Advance Wafer Technology. – Quantum Zeitgeist

    K1 Semiconductor Partners with Chicago Quantum Exchange to Revolutionize Wafer Technology

    Indirect tax transformation: Navigating change, embracing technology – Thomson Reuters tax and accounting

    Revolutionizing Indirect Tax: Embracing Technology to Navigate Change

    California’s wildfire moonshot: How new technology will defeat advancing flames – Los Angeles Times

    California’s Wildfire Revolution: How Cutting-Edge Technology Is Poised to Stop Raging Flames

    Trending Tags

    • Nintendo Switch
    • CES 2017
    • Playstation 4 Pro
    • Mark Zuckerberg
No Result
View All Result
Earth-News
No Result
View All Result
Home Technology

Microsoft addresses Office vulnerability attacked by Russian spooks in latest update

August 9, 2023
in Technology
Microsoft addresses Office vulnerability attacked by Russian spooks in latest update
Share on FacebookShare on Twitter

Gina Sanders – stock.adobe.com

Microsoft has issued fixes for over 70 vulnerabilities in its August Patch Tuesday drop, including remedies for CVE-2023-36884, which was disclosed without a fix in July and has been the subject of Kremlin-backed cyber attacks

Alex Scroxton

By

Alex Scroxton,
Security Editor

Published: 09 Aug 2023 15:15

Amid the ongoing Black Hat USA and DEF CON cyber jamborees, Microsoft has addressed a little over 70 vulnerabilities in its August Patch Tuesday update, including two zero-days already being exploited, more than 20 remote code execution (RCE) flaws, and six critical bugs.

Of the two zero-days fixes, the first comes in the form of a Defense in Depth Update for Microsoft Office, tagged as ADV23003.

This is a set of mitigations that supposedly breaks the exploit chain used by threat actors to target CVE-2023-36884, an RCE vuln in Microsoft Office which was disclosed in the July update without a fix, and is known to have been exploited by a threat actor linked to Russian intelligence agencies.

Separately, patches for the multiple products affected by this vulnerability are now available and should be applied.

Chris Goett, vice-president of security products at Ivanti, explained the significance of the ADV23303 release. “Microsoft updated the affected products listed in CVE-2023-36884 removing the Office products originally listed in the CVE,” he said.

“The Office products listed in ADV230003 are not directly vulnerable, but can be used in an attack chain to exploit CVE-2023-36884. Microsoft has clarified the changes in the Office updates were a Defense in Depth measure.

“Microsoft recommends applying the Office updates discussed in the advisory in addition to the August Windows OS updates,” he added.

The second zero-day is tracked as CVE-2023-38180, a denial of service vulnerability in .NET and Visual Studio. It is considered to be of low complexity and requires no special privileges or user interaction to exploit.

Nikolas Cemerikic, cyber security engineer at Immersive Labs, explained the scope of the vulnerability.

“A denial of service (DoS) attack involves overrunning it with an excessive volume of requests, which exhausts its available resources, such as processing power, memory, or network bandwidth. Consequently, the application becomes incapable of fulfilling legitimate user requests, limiting its normal functionality,” he said.

“If an attacker, who was suitably positioned on the network exploited this vulnerability, it would cause the Visual Studio application or applications on the same system, which are dependent on the .NET framework to become unavailable.

“Although the attacker would need to be on the same network as the target system, this vulnerability specifically does not require the attacker to have acquired user privileges,” added Cemerikic.

“According to the CVE details code maturity has reached proof-of-concept and it is confirmed to be exploited in the wild,” Ivanti’s Goettl told Computer Weekly in emailed comments.

“The CVE is only rated as Important and the CVSS v3.1 score is 7.5, but taking a risk-based approach this should be treated as a higher priority this month.”

The six critical vulnerabilities this month are all RCE flaws, three within Microsoft Message Queuing – CVE-2023-35385, CVE-2023-36910 and CVE-2023-36911; two within Microsoft Teams – CVE-2023-29328 and CVE-2023-29330; and one within Microsoft Outlook – CVE-2023-36895.

Dustin Childs of Trend Micro’s Zero Day Initiative said that the Microsoft Message Queueing bugs, of which there are several others less dramatic in their scope, were likely to see exploitation in short order as a number of PoCs are already circulating, while the Microsoft Teams vulnerabilities are worth paying attention to as both bear similarities to others that were demonstrated at the 2023 Pwn2Own event.

Also attracting attention this month are a series of six flaws in Microsoft Exchange Server, the most significant of which is CVE-2023-21709, an elevation of privilege (EoP) vulnerability. This is of low complexity and requires no special privileges or user interaction to exploit.

Tenable senior staff research engineer Satnam Narang said: “An unauthenticated attacker could exploit this vulnerability by conducting a brute-force attack against valid user accounts. Despite the high rating, the belief is that brute-force attacks won’t be successful against accounts with strong passwords. However, if weak passwords are in use, this would make brute-force attempts more successful.

“The remaining five vulnerabilities range from a spoofing flaw and multiple remote code execution bugs, though the most severe of the bunch also require credentials for a valid account,” he added.

Read more on Application security and coding requirements


Several Exchange Server flaws fixed on August Patch Tuesday

TomWalat

By: Tom Walat


Critical Adobe ColdFusion flaws chained in ongoing cyber attacks

AlexScroxton

By: Alex Scroxton


Russia-based actor exploited unpatched Office zero day

ArielleWaldman

By: Arielle Waldman


Microsoft users on high alert over dangerous RCE zero-day

AlexScroxton

By: Alex Scroxton

>>> Read full article>>>
Copyright for syndicated content belongs to the linked Source : Computer Weekly – https://www.computerweekly.com/news/366547633/Microsoft-addresses-Office-vulnerability-attacked-by-Russian-spooks-in-latest-update

Tags: addressesMicrosofttechnology
Previous Post

Huawei a big storage hitter despite international troubles

Next Post

AI interview: Krystal Kauffman, lead organiser, Turkopticon

Box, run, crash: China’s humanoid robot games show advances and limitations – The Guardian

Box, Run, Crash: Inside China’s Humanoid Robot Games Revealing Stunning Progress and Surprising Challenges

August 16, 2025
Customers look set to bear the tariff cost burden – Axios

Rising Tariff Costs: How They Impact Your Wallet and What You Can Do

August 16, 2025
‘The Rainmaker’ Premiere: Milo Callaghan Breaks Down Rudy Baylor’s ‘Misguided Valor’ – The Laconia Daily Sun

Inside ‘The Rainmaker’ Premiere: Milo Callaghan Uncovers the Real Story Behind Rudy Baylor’s Misguided Valor

August 16, 2025
NC state employee and teacher reps say health insurance increases will hurt worker retention – NC Newsline

Rising Health Insurance Costs Jeopardize Retention of State Employees and Teachers

August 16, 2025
DC police to share information with federal immigration officers – CNN

DC Police to Collaborate with Federal Immigration Officers in New Information Sharing Initiative

August 16, 2025
China’s Ecological Civilization Shaping a Sustainable Future – 中国科技网

China’s Ecological Civilization Shaping a Sustainable Future – 中国科技网

August 16, 2025
NVIDIA, National Science Foundation Support Ai2 Development of Open AI Models to Drive US Scientific Leadership – NVIDIA Blog

NVIDIA, National Science Foundation Support Ai2 Development of Open AI Models to Drive US Scientific Leadership – NVIDIA Blog

August 16, 2025
Boise State plans to build new science research building to help with capacity needs – KTVB

Boise State Unveils Plans for New Science Research Building to Boost Capacity

August 16, 2025
Why Some Physicians Still Lead With Lifestyle-First Obesity Care Despite the GLP-1 Revolution – Medscape

Why Many Physicians Still Champion Lifestyle-First Strategies in Obesity Care Despite the GLP-1 Revolution

August 16, 2025
Vermont famers say new technology is changing the state’s agriculture industry – News Channel 3-12

Vermont Farmers Embrace New Technology Transforming the State’s Agriculture Industry

August 16, 2025

Categories

Archives

August 2025
MTWTFSS
 123
45678910
11121314151617
18192021222324
25262728293031
« Jul    
Earth-News.info

The Earth News is an independent English-language daily published Website from all around the World News

Browse by Category

  • Business (20,132)
  • Ecology (773)
  • Economy (796)
  • Entertainment (21,673)
  • General (16,494)
  • Health (9,834)
  • Lifestyle (806)
  • News (22,149)
  • People (797)
  • Politics (803)
  • Science (16,008)
  • Sports (21,293)
  • Technology (15,775)
  • World (778)

Recent News

Box, run, crash: China’s humanoid robot games show advances and limitations – The Guardian

Box, Run, Crash: Inside China’s Humanoid Robot Games Revealing Stunning Progress and Surprising Challenges

August 16, 2025
Customers look set to bear the tariff cost burden – Axios

Rising Tariff Costs: How They Impact Your Wallet and What You Can Do

August 16, 2025
  • About
  • Advertise
  • Privacy & Policy
  • Contact

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

No Result
View All Result

© 2023 earth-news.info

Go to mobile version