Determining Importance with Objective Vulnerability Scoring

The holiday season is upon us, and nearly every day, my wife asks me what I want for Christmas. As a pop culture geek with interests in most fandoms, I have dozens of items that I could ask for, but the ultimate question is what do I really want to ask… Continue reading Determining Importance with Objective Vulnerability Scoring

VERT Threat Alert: November 2017 Patch Tuesday Analysis

Today’s VERT Alert addresses the Microsoft November 2017 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-752 on Wednesday, November 15th. In-The-Wild & Disclosed CVEs CVE-2017-8700 A Cross Origin Resource Sharing bypass could allow information disclosure in ASP.NET Core. Microsoft has rated this as a 2 on the […]… Read More

The post VERT Threat Alert: November 2017 Patch Tuesday Analysis appeared first on The State of Security.

The post VERT Threat Alert: November 2017 Patch Tuesday Analysis appeared first on Security Boulevard.

Continue reading VERT Threat Alert: November 2017 Patch Tuesday Analysis

VERT Threat Alert: August 2017 Patch Tuesday Analysis

Today’s VERT Alert addresses the Microsoft August 2017 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-737 on Wednesday, August 9th. In-The-Wild & Disclosed CVEs CVE-2017-8627 The first publicly disclosed vulnerability this month is a denial of service in the Windows Subsystem for Linux. Given that this is […]… Read More

The post VERT Threat Alert: August 2017 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: August 2017 Patch Tuesday Analysis

VERT Threat Alert: July 2017 Patch Tuesday Analysis

Today’s VERT Alert addresses the Microsoft July 2017 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-733 on Wednesday, July 12th. In-The-Wild & Disclosed CVEs CVE-2017-8584 In a Patch Tuesday first, we have a HoloLens code execution vulnerability. This vulnerability impacts Windows 10 and Server 2016 and could […]… Read More

The post VERT Threat Alert: July 2017 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: July 2017 Patch Tuesday Analysis

VERT Threat Alert: June 2017 Patch Tuesday Analysis

Today’s VERT Alert addresses the Microsoft June 2017 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-729 on Wednesday, June 14th. In-The-Wild & Disclosed CVEs CVE-2017-8543 According to Microsoft’s Security Guidance, they are aware of in-the-wild exploitation against CVE-2017-8543, a code execution vulnerability in the Windows Search service. […]… Read More

The post VERT Threat Alert: June 2017 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: June 2017 Patch Tuesday Analysis

VERT Threat Alert: May 2017 Patch Tuesday Analysis

Today’s VERT Alert addresses the Microsoft May 2017 Security Updates. VERT is actively working on coverage for these vulnerabilities and expects to ship ASPL-724 on Wednesday, May 10th. In-The-Wild & Disclosed CVEs CVE-2017-0290 Also known as Microsoft Security Advisory 4022344, this is a code execution in the Microsoft Malware Protection Engine that occurs when scanning […]… Read More

The post VERT Threat Alert: May 2017 Patch Tuesday Analysis appeared first on The State of Security.

Continue reading VERT Threat Alert: May 2017 Patch Tuesday Analysis