Palo Alto Networks Unit 42 Vulnerability Research December 2016 Disclosures
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2016-7263 | Microsoft Excel for Mac 2011 and Excel 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a craf Microsoft Excel for Mac 2011 and Excel 2016 for Mac allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted document, aka "Microsoft Office Memory Corruption Vulnerability." NVD description · AI analysis pending | 7.8 | 19% |
| — | ||
| CVE-2016-7639 +1 in the same advisory: …7642 | An issue was discovered in certain Apple products. An issue was discovered in certain Apple products. iOS before 10.2 is affected. Safari before 10.0.2 is affected. iCloud before 6.1 is affected. iTunes before 12.5.4 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site. NVD description · AI analysis pending | 8.8 | 2% |
| — | ||
| CVE-2016-7871 | Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the Worker class. Adobe Flash Player versions 23.0.0.207 and earlier, 11.2.202.644 and earlier have an exploitable memory corruption vulnerability in the Worker class. Successful exploitation could lead to arbitrary code execution. NVD description · AI analysis pending | 8.8 | 7% |
| — |
Full article176 words · extracted from unit42.paloaltonetworks.com · click to collapse
As part of Unit 42’s ongoing threat research, we can now disclose that Palo Alto Networks Unit 42 researchers have reported six vulnerabilities that have been fixed by Apple, Adobe and Microsoft.
This includes two vulnerabilities in Apple WebKit and impacts iCloud for Windows, Safari, iTunes for Windows, tvOS and iOS.
- CVE-2016-7639: Tongbo Luo
- CVE-2016-7642: Tongbo Luo
This includes three code execution vulnerabilities affecting Adobe Flash (APSB16-39).
- CVE-2016-7873: Tao Yan
- CVE-2016-7874: Tao Yan
- CVE-2016-7871: Tao Yan
And this includes one memory corruption vulnerability affecting Microsoft Office for the Mac (MS16-148):
- CVE-2016-7263: Jin Chen
For current customers with a Threat Prevention subscription, Palo Alto Networks has also released IPS signatures providing proactive protection from these vulnerabilities.
Palo Alto Networks is a regular contributor to vulnerability research in Microsoft, Adobe, Apple, Google Android and other ecosystems. By proactively identifying these vulnerabilities, developing protections for our customers, and sharing the information with the security community, we are removing weapons used by attackers to threaten users, and compromise enterprise, government, and service provider networks.
Text extracted automatically; images, tables and formatting may be missing. Original: https://unit42.paloaltonetworks.com/unit42-palo-alto-networks-unit-42-vulnerability-research-december-2016-disclosures/