Kategorie: Allgemein

CVE-2024-7344 Cert CC: CVE-2024-7344 Howyar Taiwan Secure Boot Bypass

In the CVE header, added the overall Severity and Impact information. This is an informational change only.

CVE-2024-43498 .NET and Visual Studio Remote Code Execution Vulnerability

Revised the Security Updates table to include PowerShell 7.5 installed on Windows, PowerShell 7.5 installed on Linux, and PowerShell 7.5 installed on MacOC because these versions of PowerShell 7 are affected by this vulnerability. See [https://github.com/PowerShell/Announcements/issues/74](https://github.com/PowerShell/Announcements/issues/74) for more information.

CVE-2025-21396 Microsoft Account Elevation of Privilege Vulnerability

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

CVE-2024-43499 .NET and Visual Studio Denial of Service Vulnerability

Revised the Security Updates table to include PowerShell 7.5 installed on Windows, PowerShell 7.5 installed on Linux, and PowerShell 7.5 installed on MacOC because these versions of PowerShell 7 are affected by this vulnerability. See [https://github.com/PowerShell/Announcements/issues/73](https://github.com/PowerShell/Announcements/issues/73) for more information.

CVE-2025-21215 Secure Boot Security Feature Bypass Vulnerability

In the Security Updates table, corrected the Impact to Security Feature Bypass. This is an informational change only.

CVE-2025-21237 Windows Telephony Service Remote Code Execution Vulnerability

Updated information to include CVSS scores. This is an informational change only.

CVE-2025-21415 Azure AI Face Service Elevation of Privilege Vulnerability

Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.

[UPDATE] [mittel] Red Hat Enterprise Linux: Schwachstelle ermöglicht Ausspaehen von Informationen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux ausnutzen, um Informationen auszuspähen.

[UPDATE] [hoch] VLC: mehrere Schwachstellen

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in VLC ausnutzen, um beliebigen Programmcode mit Benutzerrechten auszuführen, Informationen offenzulegen oder einen Denial of Service zu verursachen.

[UPDATE] [mittel] IBM WebSphere Application Server Liberty: Schwachstelle ermöglicht Denial of Service

Ein entfernter, anonymer Angreifer kann eine Schwachstelle in IBM WebSphere Application Server Liberty ausnutzen, um einen Denial of Service Angriff durchzuführen.