Severity Rating: HIGH

Software Affected
·         Windows 10 Version 1709 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1709 for ARM64-based Systems
·         Windows 10 Version 1803 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1803 for ARM64-based Systems
·         Windows 10 Version 1809 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1809 for ARM64-based Systems
·         Windows 10 Version 1903 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1903 for ARM64-based Systems
·         Windows 10 Version 1909 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 1909 for ARM64-based Systems
·         Windows 10 Version 2004 for 32-bit Systems and x64-based Systems
·         Windows 10 Version 2004 for ARM64-based Systems

Overview
Multiple vulnerabilities have been reported in Microsoft Windows which
could allow a remote attacker to execute arbitrary code on a targeted
system.

Description
These vulnerabilities exist in Microsoft Windows Codecs Library due to
improper handling of objects in memory. A remote attacker could exploit
this vulnerability by convincing the user to open a specially crafted image
file on an affected system.

Successful exploitation of these vulnerabilities could allow the attacker
to execute arbitrary code on the targeted system.

Solution
The affected systems are being updated automatically via Microsoft Store.
To receive the update immediately, users can check for updates with the
Microsoft Store App. For further information, refer to the FAQ sections at:


Vendor Information
Microsoft

References
ESET WeLiveSecurity

CyberSecurityHelp

CVE Name
CVE-2020-1425
CVE-2020-1457

Severity Rating: Medium

Software Affected
·         Samba 4.5.0 and later

Overview
Multiple vulnerabilities have been reported in samba which could allow a
remote attacker to cause denial of service conditions on a targeted system.

Description
1. NULL pointer dereference Vulnerability (CVE-2020-10730)

This vulnerability exists due to a NULL pointer dereference error in Samba
AD DC LDAP Server with ASQ, VLV and paged_results. A remote authenticated
user can pass specially crafted data to the application and perform a
denial of service (DoS) attack by triggering a NULL pointer dereference or
us-after-free error

Successful exploitation of this vulnerability could allow the allows a
remote user to perform a denial of service (DoS) attack.

2. Resource exhaustion Vulnerability (CVE-2020-10745)
This vulnerability exists due to application does not properly control
consumption of internal resources when processing NBT and DNS replies.  A
remote attacker can send a name in the reply to a NBT or DNS request and
consume excessive CPU resources, resulting in denial of service conditions.

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions on the targeted system.

3. Use-after-free Vulnerability (CVE-2020-10760)
This vulnerability exists due to a use-after-free error  in Samba AD DC
Global Catalog with paged_results and VLV. A remote user can send a
specially crafted request to the LDAP server, trigger a use-after-free
error and perform a denial of service attack

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions on the targeted system.

3. Input validation error Vulnerability (CVE-2020-14303)
This vulnerability exists due to insufficient validation of UDP packets
with 0 length data in Samba. A remote attacker can send a specially crafted
UDP packet to port 137/TCP and perform a denial of service (DoS) attack

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions on the targeted system.

Solution
Update to the latest versions as available at the following URL

Vendor Information
Samba

References
Samba

CVE Name
CVE-2020-10730
CVE-2020-10745
CVE-2020-10760
CVE-2020-14303

Severity Rating: HIGH

Software Affected

Sophos XG Firewall v17.5 MR12 and prior to.
Overview

A vulnerability have been reported in Sophos XG Firewall which could allow
an attacker to gain access of physical and virtual units configured with
the user portal.

Description

A Vulnerability exists in Sophos XG Firewall v17.xdue to a software bug
that could allow the attacker to gain access of physical and virtual units
configured with the user portal exposed on WAN. An attacker could exploit
this vulnerability by accessing the affected physical and virtual units.

Successful exploitation of this vulnerability could allow the attacker to
access of the vulnerable devices with the user portal. 

Best Practices:

Reset device administrator accounts
Reset passwords for all local user accounts
Disable User Portal access on the WAN unless necessary.


Solution

Apply appropriate updates as mentioned in: 
- -vulnerability-in-user-portal


Vendor Information

SOPHOS 
- -vulnerability-in-user-portal

References

SOPHOS 
- -vulnerability-in-user-portal

CVE Name
CVE-2020-15069

Severity Rating: HIGH

Software Affected

Wireshark versions 3.2.0 to 3.2.4
Overview

A vulnerability has been reported in Wireshark which could allow a remote
attacker to cause denial of service conditions on a targeted system.

Description
This vulnerability exists in Wireshark due to an error in file
packet-gvcp.c which may cause an infinite loop. A remote attacker could
exploit this vulnerability by injecting a malformed packet onto the wire or
by convincing the user to read a malformed packet trace file. 

Successful exploitation of this vulnerability could allow the attacker to
cause denial of service conditions on the targeted system due to excessive
consumption of CPU resources.

Solution
Upgrade to Wireshark version 3.2.5 .
Vendor Information

Wireshark

References

CyberSecurityHelp

CVE Name
CVE-2020-15466

Severity Rating: HIGH

Component Affected
250 Series Smart Switches
350 Series Managed Switches
350X Series Stackable Managed Switches
550X Series Stackable Managed Switches
Small Business 200 Series Smart Switches
Small Business 300 Series Managed Switches
Small Business 500 Series Stackable Managed Switches

Overview
A vulnerability has been reported in session management interface of Cisco
Small Business Smart and Managed Switches which could allow an
unauthenticated, remote attacker to gain unauthorized access to the
management interface.

Description
This vulnerability exists in session management for the web-based interface
of Cisco Small Business Smart and Managed Switches due to the use of weak
entropy generation for session identifier values that could allow the
attacker to access the switches¿ management interfaces. An
unauthenticated, remote attacker could exploit this vulnerability to
determine a current session identifier through brute force and reuse that
session identifier to take over an ongoing session. 

Successful exploitation of this vulnerability could allow the attacker to
access the switches management interfaces with administrative privileges.

Solution
Apply appropriate updates as mentioned in: 

Vendor Information
Cisco

References

Cisco

CVE Name
CVE-2020-3297

Severity Rating: HIGH

Systems Affected

F5 BIG-IP (LTM, AAM, AFM, Analytics, APM, ASM, DNS, FPS, GTM, Link
Controller, PEM) versions:

15.x versions 15.1.0 and 15.0.0
14.x versions 14.1.0 through 14.1.2
13.x versions 13.1.0 through 13.1.3
12.x versions 12.1.0 through 12.1.5
11.x versions 11.6.1 through 11.6.5

Overview
A vulnerability has been reported in F5 BIG-IP products which could allow
an unauthenticated remote attacker to execute arbitrary code on a targeted
system.

Description
This vulnerability exits in multiple BIG-IP products due to a flaw in
undisclosed pages of Traffic Management User Interface (TMUI), also
referred to as the Configuration utility. An unauthenticated remote
attacker could exploit this vulnerability by sending a special crafted web
request to the affected system.

Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code on the targeted system and may result in complete
system compromise. 

Note: This vulnerability has been reported to being actively exploited in
the wild.

Solution
Update to the fixed versions as mentioned in the F5 advisory

Vendor Information
F5 Networks 

References
nccgroup

CISecurity
https://www.cisecurity.org/advisory/a-vulnerability-in-f5-big-ip-traffic-management-user-interface-could-allow-for-remote-code-execution_2020-090/

CVE Name
CVE-2020-5902

Severity Rating: Medium

Systems Affected:
·         Adobe Flash Player

Overview
Adobe has announced that they will stop distributing and updating Flash
Player from 31 December 2020 ("EOL Date").

Description
As previously announced in 2017, Adobe will be ending support for Adobe
Flash Player from 31 December 2020. After this date, Adobe not be issuing
any updates or security patches for Flash Player.

In addition, they will be removing previous Flash Player versions from
their website and Flash-based content will be blocked from running.

Recommendation
·         Developers and organizations whose websites use Flash Player are
advised to migrate to alternative technologies before 31 December 2020.
·         Downloading Flash Player from third party websites should be
avoided as these versions may contain malware.

Vendor Information

Adobe

References

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top