CVE-2023-42724
published 2023-12-04CVE-2023-42724: In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution…
PriorityP415medium4.4CVSS 3.1
AVLACLPRHUINSUCNINAH
EPSS
0.13%
3.3th percentile
In gpu driver, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of service with System execution privileges needed
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| android | — | — | |
| unisoc_technologies_co_ltd | sc9863a_t310_t606_t612_t616_t610_t618_t760_t770_t820_s8000 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Top resources for Cybersecurity Awareness Month
blogs_talos·2023-10-12·CVSS 7.5
[HIGH] Top resources for Cybersecurity Awareness Month
Welcome to this week’s edition of the Threat Source newsletter.
I didn’t feel like I wanted to write anything special or witty this week given the current events in Israel and the Gaza Strip, but I will certainly advocate for any assistance readers would like to provide to the various organizations and helpers who are trying to do some good for Israeli and Palestinian civilians right now.
And since it’s still Cybersecurity Awareness Month, I also wanted to provide some links to various resources, blog posts and podcasts that I’ve found particularly helpful this month and I think you will, too.
- Countering the Rise of Ransomware (Cisco YouTube)
- Talos APJC Threat Update: How attackers are using AI
- The New Normal: How XDR is Tackling Social Engineering in Today’s World (Cisco Secure b
Talos
Top resources for Cybersecurity Awareness Month
blogs_talos·2023-10-12·CVSS 7.5
[HIGH] Top resources for Cybersecurity Awareness Month
## Top resources for Cybersecurity Awareness Month
Welcome to this week’s edition of the Threat Source newsletter.
I didn’t feel like I wanted to write anything special or witty this week given the current events in Israel and the Gaza Strip, but I will certainly advocate for any assistance readers would like to provide to the various organizations and helpers who are trying to do some good for Israeli and Palestinian civilians right now .
And since it’s still Cybersecurity Awareness Month, I also wanted to provide some links to various resources, blog posts and podcasts that I’ve found particularly helpful this month and I think you will, too.
Countering the Rise of Ransomware (Cisco YouTube)
Talos APJC Threat Update: How attackers are using AI
The New Normal: How XDR is Tackling So
Krebs
Patch Tuesday, October 2023 Edition
blogs_krebs·2023-10-10·CVSS 4.4
CVE-2023-42724 [MEDIUM] Patch Tuesday, October 2023 Edition
Microsoft today issued security updates for more than 100 newly-discovered vulnerabilities in its Windows operating system and related software, including four flaws that are already being exploited. In addition, Apple recently released emergency updates to quash a pair of zero-day bugs in iOS.
Apple last week shipped emergency updates in iOS 17.0.3 and iPadOS 17.0.3 in response to active attacks. The patch fixes CVE-2023-42724, which attackers have been using in targeted attacks to elevate their access on a local device.
Apple said it also patched CVE-2023-5217, which is not listed as a zero-day bug. However, as Bleeping Computer pointed out, this flaw is caused by a weakness in the open-source “libvpx” video codec library, which was previously patched as a zero-day flaw by Google in th
Krebs
Patch Tuesday, October 2023 Edition
blogs_krebs·2023-10-10·CVSS 4.4
CVE-2023-42724 [MEDIUM] Patch Tuesday, October 2023 Edition
Microsoft today issued security updates for more than 100 newly-discovered vulnerabilities in its Windows operating system and related software, including four flaws that are already being exploited. In addition, Apple recently released emergency updates to quash a pair of zero-day bugs in iOS .
Apple last week shipped emergency updates in iOS 17.0.3 and iPadOS 17.0.3 in response to active attacks. The patch fixes CVE-2023-42724 , which attackers have been using in targeted attacks to elevate their access on a local device.
Apple said it also patched CVE-2023-5217 , which is not listed as a zero-day bug. However, as Bleeping Computer pointed out , this flaw is caused by a weakness in the open-source “ libvpx ” video codec library, which was previously patched as a zero-day flaw by Google
2023-12-04
Published