{"id":336,"date":"2024-08-19T06:00:51","date_gmt":"2024-08-19T06:00:51","guid":{"rendered":"https:\/\/danefenner.com\/?p=336"},"modified":"2024-08-19T06:00:51","modified_gmt":"2024-08-19T06:00:51","slug":"cybersecurity-updates-vulnerabilities-august-12-18-2024","status":"publish","type":"post","link":"https:\/\/danefenner.com\/?p=336","title":{"rendered":"Cybersecurity Updates: Vulnerabilities,\u00a0August 12-18, 2024"},"content":{"rendered":"\n<p><strong><mark style=\"background-color:#8ed1fc\" class=\"has-inline-color has-black-color\">Zero Day Vulnerabilities<\/mark><\/strong><\/p>\n\n\n\n<p><strong>Microsoft Office Spoofing Vulnerability | <a href=\"https:\/\/www.helpnetsecurity.com\/2024\/08\/12\/cve-2024-38200\/\" target=\"_blank\" rel=\"noreferrer noopener\">CVE-2024-38200<\/a><\/strong>: The vulnerability is exploitable remotely and requires no special privileges or user interaction to be triggered.<\/p>\n\n\n\n<p><strong><mark style=\"background-color:#f71818\" class=\"has-inline-color\">Critical Severity Vulnerabilities<\/mark><\/strong><\/p>\n\n\n\n<p><strong>Microsoft Project Remote Code Execution<\/strong> | <strong><a href=\"https:\/\/www.tenable.com\/cve\/CVE-2024-38189\">CVE-2024-38189<\/a><\/strong>: A critical vulnerability in Microsoft Project allows remote code execution via a malicious file. This flaw has a high CVSS score of 8.80, indicating a significant risk if exploited.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-layout-1 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p><mark style=\"background-color:#f78da7\" class=\"has-inline-color\"><strong>High Severity Vulnerabilities<\/strong> <\/mark><\/p>\n\n\n\n<p><strong>OpenSSH pre-authentication async signal safety issue | <a href=\"https:\/\/www.tenable.com\/cve\/CVE-2024-7589\">CVE-2024-7589<\/a><\/strong>: A signal handler in sshd(8) may call a logging function that is not async-signal-safe. The signal handler is invoked when a client does not authenticate within the LoginGraceTime seconds (120 by default). This signal handler executes in the context of the sshd(8)&#8217;s privileged code, which is not sandboxed and runs with full root privileges.<\/p>\n\n\n\n<p><strong>PostgreSQL Time-of-Check Time-of-Use (TOCTOU) Race Condition<\/strong> | <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-7348\">CVE-2024-7348<\/a><\/strong>: This vulnerability allows an object creator to execute arbitrary SQL functions during the pg_dump process by exploiting a race condition. It affects PostgreSQL versions before 16.4, 15.8, 14.13, 13.16, and 12.20.<\/p>\n\n\n\n<p><strong>Roundcube mod_css_styles Information Disclosure | <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-42010\">CVE-2024-42010<\/a><\/strong>: This vulnerability allows a remote attacker to obtain sensitive information. The insufficient filtering of CSS token sequences in rendered e-mail messages could potentially lead to information disclosure, compromising the confidentiality of user data within the Roundcube webmail system.<\/p>\n\n\n\n<p><strong>Scripting Engine Memory Corruption Vulnerability<\/strong> | <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-38178\">CVE-2024-38178<\/a><\/strong>: This vulnerability affects the scripting engine and allows remote code execution (RCE) due to improper handling of memory objects.<\/p>\n\n\n\n<p><\/p>\n\n\n\n<p><\/p>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<p><strong><mark style=\"background-color:#fcb900\" class=\"has-inline-color\">Medium Severity Vulnerabilities<\/mark><\/strong><\/p>\n\n\n\n<p><strong>389-ds-base: malformed user password hash may cause a denial of service | <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-5953\">CVE-2024-5953<\/a><\/strong>: A denial of service vulnerability was found in the 389-ds-base LDAP server. This issue may allow an authenticated user to cause a server denial of service while attempting to log in with a user with a malformed hash in their password.<\/p>\n\n\n\n<p><strong>Denial of Service in CLFS.sys | <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-6768\">CVE-2024-6768<\/a><\/strong>: A Denial of Service in CLFS.sys in Microsoft Windows 10, Windows 11, Windows Server 2016, Windows Server 2019, and Windows Server 2022 allows a malicious authenticated low-privilege user to cause a Blue Screen of Death via a forced call to the KeBugCheckEx function.<\/p>\n\n\n\n<p><strong>WebOb&#8217;s location header normalization during redirect leads to open redirect | <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-42353\">CVE-2024-42353<\/a><\/strong>: When WebOb normalizes the HTTP Location header to include the request hostname, it does so by parsing the URL that the user is to be redirected to with Python&#8217;s urlparse, and joining it to the base URL. `urlparse` however treats a `\/\/` at the start of a string as a URI without a scheme, and then treats the next part as the hostname. `urljoin` will then use that hostname from the second part as the hostname replacing the original one from the request. This vulnerability is patched in WebOb version 1.8.8.<\/p>\n\n\n\n<p><strong>1Password macOS Local Information Disclosure<\/strong> | <strong><a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2024-42219\">CVE-2024-42219<\/a><\/strong>: A vulnerability in 1Password for macOS allows local attackers to exfiltrate vault items due to insufficient validation in XPC inter-process communication.<\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Zero Day Vulnerabilities Microsoft Office Spoofing Vulnerability | CVE-2024-38200: The vulnerability is exploitable remotely and requires no special privileges or user interaction to be triggered. Critical Severity Vulnerabilities Microsoft Project Remote Code Execution | CVE-2024-38189: A critical vulnerability in Microsoft Project allows remote code execution via a malicious file. This flaw has a high CVSS [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":339,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"ngg_post_thumbnail":0,"footnotes":""},"categories":[1],"tags":[6,25,18,26],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v23.2 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Cybersecurity Updates: Vulnerabilities,\u00a0August 12-18, 2024 - Dane Fenner<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/danefenner.com\/?p=336\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Cybersecurity Updates: Vulnerabilities,\u00a0August 12-18, 2024 - Dane Fenner\" \/>\n<meta property=\"og:description\" content=\"Zero Day Vulnerabilities Microsoft Office Spoofing Vulnerability | CVE-2024-38200: The vulnerability is exploitable remotely and requires no special privileges or user interaction to be triggered. Critical Severity Vulnerabilities Microsoft Project Remote Code Execution | CVE-2024-38189: A critical vulnerability in Microsoft Project allows remote code execution via a malicious file. This flaw has a high CVSS [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/danefenner.com\/?p=336\" \/>\n<meta property=\"og:site_name\" content=\"Dane Fenner\" \/>\n<meta property=\"article:published_time\" content=\"2024-08-19T06:00:51+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/danefenner.com\/wp-content\/uploads\/2024\/08\/Black-and-Violet-Dark-Professional-Real-Estate-Weekly-Team-Updates-Presentation-1-1.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1200\" \/>\n\t<meta property=\"og:image:height\" content=\"675\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Maria Yap\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Maria Yap\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/danefenner.com\/?p=336\",\"url\":\"https:\/\/danefenner.com\/?p=336\",\"name\":\"Cybersecurity Updates: Vulnerabilities,\u00a0August 12-18, 2024 - Dane Fenner\",\"isPartOf\":{\"@id\":\"https:\/\/danefenner.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/danefenner.com\/?p=336#primaryimage\"},\"image\":{\"@id\":\"https:\/\/danefenner.com\/?p=336#primaryimage\"},\"thumbnailUrl\":\"https:\/\/danefenner.com\/wp-content\/uploads\/2024\/08\/Black-and-Violet-Dark-Professional-Real-Estate-Weekly-Team-Updates-Presentation-1-1.jpg\",\"datePublished\":\"2024-08-19T06:00:51+00:00\",\"dateModified\":\"2024-08-19T06:00:51+00:00\",\"author\":{\"@id\":\"https:\/\/danefenner.com\/#\/schema\/person\/f79cd022251218532e74bcb12983a882\"},\"breadcrumb\":{\"@id\":\"https:\/\/danefenner.com\/?p=336#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/danefenner.com\/?p=336\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/danefenner.com\/?p=336#primaryimage\",\"url\":\"https:\/\/danefenner.com\/wp-content\/uploads\/2024\/08\/Black-and-Violet-Dark-Professional-Real-Estate-Weekly-Team-Updates-Presentation-1-1.jpg\",\"contentUrl\":\"https:\/\/danefenner.com\/wp-content\/uploads\/2024\/08\/Black-and-Violet-Dark-Professional-Real-Estate-Weekly-Team-Updates-Presentation-1-1.jpg\",\"width\":1200,\"height\":675},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/danefenner.com\/?p=336#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/danefenner.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Cybersecurity Updates: Vulnerabilities,\u00a0August 12-18, 2024\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/danefenner.com\/#website\",\"url\":\"https:\/\/danefenner.com\/\",\"name\":\"Dane Fenner\",\"description\":\"\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/danefenner.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/danefenner.com\/#\/schema\/person\/f79cd022251218532e74bcb12983a882\",\"name\":\"Maria Yap\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/danefenner.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/9c6ec2a4c531e381d8e429104aaee3d0?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/9c6ec2a4c531e381d8e429104aaee3d0?s=96&d=mm&r=g\",\"caption\":\"Maria Yap\"},\"sameAs\":[\"http:\/\/mavenbymaria.com\"],\"url\":\"https:\/\/danefenner.com\/?author=2\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Cybersecurity Updates: Vulnerabilities,\u00a0August 12-18, 2024 - Dane Fenner","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/danefenner.com\/?p=336","og_locale":"en_US","og_type":"article","og_title":"Cybersecurity Updates: Vulnerabilities,\u00a0August 12-18, 2024 - Dane Fenner","og_description":"Zero Day Vulnerabilities Microsoft Office Spoofing Vulnerability | CVE-2024-38200: The vulnerability is exploitable remotely and requires no special privileges or user interaction to be triggered. Critical Severity Vulnerabilities Microsoft Project Remote Code Execution | CVE-2024-38189: A critical vulnerability in Microsoft Project allows remote code execution via a malicious file. This flaw has a high CVSS [&hellip;]","og_url":"https:\/\/danefenner.com\/?p=336","og_site_name":"Dane Fenner","article_published_time":"2024-08-19T06:00:51+00:00","og_image":[{"width":1200,"height":675,"url":"https:\/\/danefenner.com\/wp-content\/uploads\/2024\/08\/Black-and-Violet-Dark-Professional-Real-Estate-Weekly-Team-Updates-Presentation-1-1.jpg","type":"image\/jpeg"}],"author":"Maria Yap","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Maria Yap","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/danefenner.com\/?p=336","url":"https:\/\/danefenner.com\/?p=336","name":"Cybersecurity Updates: Vulnerabilities,\u00a0August 12-18, 2024 - Dane Fenner","isPartOf":{"@id":"https:\/\/danefenner.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/danefenner.com\/?p=336#primaryimage"},"image":{"@id":"https:\/\/danefenner.com\/?p=336#primaryimage"},"thumbnailUrl":"https:\/\/danefenner.com\/wp-content\/uploads\/2024\/08\/Black-and-Violet-Dark-Professional-Real-Estate-Weekly-Team-Updates-Presentation-1-1.jpg","datePublished":"2024-08-19T06:00:51+00:00","dateModified":"2024-08-19T06:00:51+00:00","author":{"@id":"https:\/\/danefenner.com\/#\/schema\/person\/f79cd022251218532e74bcb12983a882"},"breadcrumb":{"@id":"https:\/\/danefenner.com\/?p=336#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/danefenner.com\/?p=336"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/danefenner.com\/?p=336#primaryimage","url":"https:\/\/danefenner.com\/wp-content\/uploads\/2024\/08\/Black-and-Violet-Dark-Professional-Real-Estate-Weekly-Team-Updates-Presentation-1-1.jpg","contentUrl":"https:\/\/danefenner.com\/wp-content\/uploads\/2024\/08\/Black-and-Violet-Dark-Professional-Real-Estate-Weekly-Team-Updates-Presentation-1-1.jpg","width":1200,"height":675},{"@type":"BreadcrumbList","@id":"https:\/\/danefenner.com\/?p=336#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/danefenner.com\/"},{"@type":"ListItem","position":2,"name":"Cybersecurity Updates: Vulnerabilities,\u00a0August 12-18, 2024"}]},{"@type":"WebSite","@id":"https:\/\/danefenner.com\/#website","url":"https:\/\/danefenner.com\/","name":"Dane Fenner","description":"","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/danefenner.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/danefenner.com\/#\/schema\/person\/f79cd022251218532e74bcb12983a882","name":"Maria Yap","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/danefenner.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/9c6ec2a4c531e381d8e429104aaee3d0?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/9c6ec2a4c531e381d8e429104aaee3d0?s=96&d=mm&r=g","caption":"Maria Yap"},"sameAs":["http:\/\/mavenbymaria.com"],"url":"https:\/\/danefenner.com\/?author=2"}]}},"_links":{"self":[{"href":"https:\/\/danefenner.com\/index.php?rest_route=\/wp\/v2\/posts\/336"}],"collection":[{"href":"https:\/\/danefenner.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/danefenner.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/danefenner.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/danefenner.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=336"}],"version-history":[{"count":1,"href":"https:\/\/danefenner.com\/index.php?rest_route=\/wp\/v2\/posts\/336\/revisions"}],"predecessor-version":[{"id":338,"href":"https:\/\/danefenner.com\/index.php?rest_route=\/wp\/v2\/posts\/336\/revisions\/338"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/danefenner.com\/index.php?rest_route=\/wp\/v2\/media\/339"}],"wp:attachment":[{"href":"https:\/\/danefenner.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=336"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/danefenner.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=336"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/danefenner.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=336"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}