Microsoft Outlook Privilege Elevation Vulnerability (CVE-2023-23397)

CISA added a zero-day vulnerability affecting Microsoft Outlook that is actively exploited in the wild. Microsoft has released a patch for the vulnerability as part of their March 2023 Patch Tuesday.

Microsoft Outlook Privilege Elevation Vulnerability (CVE-2023-23397)2023-04-12T12:39:15-04:00

VMware Cloud Foundation remote code execution vulnerability via XStream (CVE-2021-39144)

CISA identified VMware products to the CVE-2021-39144 vulnerability in its Known Exploited Vulnerabilities (KEV) catalog following confirmation from VMware that this bug is being exploited since December 2022.

VMware Cloud Foundation remote code execution vulnerability via XStream (CVE-2021-39144)2023-04-04T11:30:07-04:00