[BESAdmin-Announcements] Content Modification: Updates for Kev Content published 2025-02-27

Announcements for BES Administrators besadmin-announcements at bigmail.bigfix.com
Thu Feb 27 09:10:02 PST 2025


Total New Fixlets:      2
Total Updated Fixlets:  243
Total Fixlets in Site:  2843
Total CVEs Covered:     819
Release Date:           2025-02-27

New Fixlets:
    36170    Craft CMS Code Injection Vulnerability - Any Operating System
    36180    Adobe ColdFusion Deserialization Vulnerability - Any Version
of Windows


Updated Fixlets:
    28160    Google Chromium WebRTC Heap Buffer Overflow Vulnerability -
Any Version of Linux
    32260    HTTP/2 Rapid Reset Attack Vulnerability - Windows 10
    34820    Microsoft Windows Task Scheduler Privilege Escalation
Vulnerability - Windows Server 2025
    21510    Microsoft Exchange Server Server-Side Request Forgery
Vulnerability - Exchange Server 2016
    13830    Microsoft Windows LSA Spoofing Vulnerability - Windows 11
    18440    Google Chromium V8 Memory Corruption Vulnerability - Any
Version of Linux
    31750    Google Chromium V8 Inappropriate Implementation Vulnerability
- Any Version of Linux
    17930    Synacor Zimbra Collaboration Suite (ZCS) Improper Restriction
of XML External Entity Reference - Any Version of Linux
    25100    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    6670    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows 10
    6160    Microsoft Active Directory Domain Services Privilege Escalation
Vulnerability - Windows 10
    31760    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    18450    Google Chromium Blink Use-After-Free Vulnerability - Any
Version of Linux
    20500    Google Chromium Network Service Use-After-Free Vulnerability -
Any Version of MacOS
    17940    Google Chrome Use-After-Free Vulnerability - Any Version of
Linux
    19990    Google Chromium V8 Integer Overflow Vulnerability - Any
Version of MacOS
    16410    Google Chrome WebAudio Use-After-Free Vulnerability - Any
Version of Windows
    31770    Google Chromium V8 Inappropriate Implementation Vulnerability
- Any Version of MacOS
    8220    Microsoft Active Directory Domain Services Privilege Escalation
Vulnerability - Windows Server 2016
    13850    Microsoft Active Directory Domain Services Privilege
Escalation Vulnerability - Windows 11
    28190    Google Chromium WebRTC Heap Buffer Overflow Vulnerability -
Any Version of MacOS
    18460    Google Chrome Blink Use-After-Free Vulnerability - Any Version
of Linux
    17440    Synacor Zimbra Collaboration Suite (ZCS) Command Injection
Vulnerability - Any Version of Linux
    31780    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    21540    Microsoft Exchange Server Remote Code Execution Vulnerability
- Exchange Server 2019
    20520    Google Chromium V8 Out-of-Bounds Read Vulnerability - Any
Version of MacOS
    17450    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    15920    Google Chromium Indexed DB API Use-After-Free Vulnerability -
Any Version of Windows
    18480    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    20530    Google Chromium GPU Heap Buffer Overflow Vulnerability - Any
Version of MacOS
    20540    Google Chromium V8 Incorrect Implementation Vulnerabililty -
Any Version of MacOS
    17980    Google Chromium Intents Insufficient Input Validation
Vulnerability - Any Version of Linux
    30270    PHP-CGI OS Command Injection Vulnerability - Any Version of
Windows
    20030    Google Chromium Portals Use-After-Free Vulnerability - Any
Version of MacOS
    19520    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    7230    Microsoft Active Directory Domain Services Privilege Escalation
Vulnerability - Windows Server 2019
    19010    Google Chromium V8 Out-of-Bounds Memory Vulnerability - Any
Version of Linux
    17480    Google Chromium V8 Heap Buffer Overflow Vulnerability - Any
Version of Linux
    19020    Google Chromium V8 Use-After-Free Vulnerability - Any Version
of Linux
    14930    WhatsApp Cross-Site Scripting Vulnerability - Any Version of
MacOS
    19540    Google Chromium V8 Heap Buffer Overflow Vulnerability - Any
Version of MacOS
    32340    HTTP/2 Rapid Reset Attack Vulnerability - Windows Server 2022
    5720    Microsoft Windows LSA Spoofing Vulnerability - Windows 10
    20570    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    10330    Microsoft Windows LSA Spoofing Vulnerability - Windows Server
2012
    17500    Synacor Zimbra Collaborate Suite (ZCS) Cross-Site Scripting
Vulnerability - Any Version of Linux
    18010    Google Chromium V8 Out-of-Bounds Write Vulnerability - Any
Version of Linux
    29790    GitLab Community and Enterprise Editions Improper Access
Control Vulnerability - Any Version of Linux
    16480    Google Chromium V8 Memory Corruption Vulnerability - Any
Version of Windows
    21600    Microsoft Exchange Server Server-Side Request Forgery
Vulnerability - Exchange Server 2019
    15970    Google Chrome Use-After-Free Vulnerability - Any Version of
Windows
    17000    Google Chromium V8 Out-of-Bounds Memory Vulnerability - Any
Version of Windows
    18540    Google Chromium Blink Use-After-Free Vulnerability - Any
Version of Linux
    15470    Google Chromium Race Condition Vulnerability - Any Version of
Windows
    22640    Google Chrome Skia Integer Overflow Vulnerability - Any
Version of Windows
    2670    Microsoft Windows LSA Spoofing Vulnerability - Windows 7 SP1
    17010    Google Chromium V8 Use-After-Free Vulnerability - Any Version
of Windows
    19570    Google Chromium V8 Out-of-Bounds Write Vulnerability - Any
Version of MacOS
    16500    Google Chromium Blink Use-After-Free Vulnerability - Any
Version of Windows
    18550    Synacor Zimbra Collaboration Suite (ZCS) Authentication Bypass
Vulnerability - Any Version of Linux
    18040    Google Chromium V8 Out-of-Bounds Write Vulnerability - Any
Version of Linux
    20090    Google Chromium Information Disclosure Vulnerability - Any
Version of MacOS
    16510    Google Chrome Blink Use-After-Free Vulnerability - Any Version
of Windows
    21630    Microsoft Exchange Server Remote Code Execution Vulnerability
- Exchange Server 2013
    20610    Google Chromium Animation Use-After-Free Vulnerability - Any
Version of MacOS
    20100    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    17540    Google Chromium V8 Out-of-Bounds Write Vulnerability - Any
Version of Linux
    16520    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    19080    Google Chrome FreeType Heap Buffer Overflow Vulnerability -
Any Version of Linux
    35980    Microsoft Windows Ancillary Function Driver for WinSock
Heap-Based Buffer Overflow Vulnerability - Windows Server 2025
    22670    PaperCut MF/NG Improper Access Control Vulnerability - Any
Version of Windows
    29840    Google Chromium Visuals Use-After-Free Vulnerability - Any
Version of Windows
    19600    Google Chromium Mojo Insufficient Data Validation
Vulnerability - Any Version of MacOS
    32400    HTTP/2 Rapid Reset Attack Vulnerability - Windows 11
    19090    Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload
Vulnerability - Any Version of Linux
    13460    Microsoft Windows LSA Spoofing Vulnerability - Windows Server
2022
    35990    Microsoft Windows Storage Link Following Vulnerability -
Windows Server 2025
    19610    TeamViewer Desktop Bypass Remote Login Vulnerability - Any
Version of MacOS
    16030    Google Chromium Intents Insufficient Input Validation
Vulnerability - Any Version of Windows
    18590    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    17570    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting
(XSS) Vulnerability - Any Version of Linux
    35490    Microsoft Windows Hyper-V NT Kernel Integration VSP Heap-based
Buffer Overflow Vulnerability - Windows Server 2025
    17060    Google Chrome FreeType Heap Buffer Overflow Vulnerability -
Any Version of Windows
    29860    Google Chromium Visuals Use-After-Free Vulnerability - Any
Version of Linux
    13480    Microsoft Active Directory Domain Services Privilege
Escalation Vulnerability - Windows Server 2022
    18090    Google Chromium V8 Integer Overflow Vulnerability - Any
Version of Linux
    35500    Microsoft Windows Hyper-V NT Kernel Integration VSP
Use-After-Free Vulnerability - Windows Server 2025
    19630    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    16560    Google Chromium Blink Use-After-Free Vulnerability - Any
Version of Windows
    21680    Microsoft Exchange Server Server-Side Request Forgery
Vulnerability - Exchange Server 2013
    14000    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows 11
    20150    Google Chromium V8 Memory Corruption Vulnerability - Any
Version of MacOS
    17590    Google Chromium Mojo Insufficient Data Validation
Vulnerability - Any Version of Linux
    17080    Google Chromium V8 Use-After-Free Vulnerability - Any Version
of Windows
    29880    Google Chromium Visuals Use-After-Free Vulnerability - Any
Version of MacOS
    19130    Google Chromium V8 Use-After-Free Vulnerability - Any Version
of Linux
    35510    Microsoft Windows Hyper-V NT Kernel Integration VSP
Use-After-Free Vulnerability - Windows Server 2025
    16060    Google Chromium V8 Out-of-Bounds Write Vulnerability - Any
Version of Windows
    7870    Microsoft Windows LSA Spoofing Vulnerability - Windows Server
2016
    17600    TeamViewer Desktop Bypass Remote Login Vulnerability - Any
Version of Linux
    17090    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    16590    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    18130    Google Chromium Portals Use-After-Free Vulnerability - Any
Version of Linux
    20180    Google Chromium V8 Remote Code Execution Vulnerability - Any
Version of MacOS
    17620    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    19670    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    16090    Google Chromium V8 Out-of-Bounds Write Vulnerability - Any
Version of Windows
    17120    Google Chromium V8 Improper Input Validation Vulnerability -
Any Version of Windows
    18660    Google Chrome Media Prior to 81.0.4044.92 Use-After-Free
Vulnerability - Any Version of Linux
    15590    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    20200    Google Chrome WebAudio Use-After-Free Vulnerability - Any
Version of MacOS
    9960    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows Server 2012 R2
    19180    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    18670    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    20720    Google Chromium V8 Out-of-Bounds Memory Vulnerability - Any
Version of MacOS
    5360    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows Server 2008 SP2
    29940    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    19700    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    9460    Microsoft Active Directory Domain Services Privilege Escalation
Vulnerability - Windows Server 2012 R2
    15610    Google Chromium V8 Heap Buffer Overflow Vulnerability - Any
Version of Windows
    20730    Google Chromium V8 Use-After-Free Vulnerability - Any Version
of MacOS
    22780    Google Chrome Skia Integer Overflow Vulnerability - Any
Version of Linux
    29950    Google Chromium V8 Out-of-Bounds Memory Write Vulnerability -
Any Version of Windows
    16640    Google Chrome Media Prior to 81.0.4044.92 Use-After-Free
Vulnerability - Any Version of Windows
    26880    Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
- Any Version of Windows
    18690    Google Chromium PopupBlocker Security Bypass Vulnerability -
Any Version of Linux
    19200    Google Chromium V8 Improper Input Validation Vulnerability -
Any Version of Linux
    12550    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows Server 2008 R2 SP1
    2310    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows 8.1
    19720    Google Chromium WebGL Use-After-Free Vulnerability - Any
Version of MacOS
    17670    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    16140    Google Chromium V8 Integer Overflow Vulnerability - Any
Version of Windows
    18190    Google Chromium Information Disclosure Vulnerability - Any
Version of Linux
    6930    Microsoft Windows LSA Spoofing Vulnerability - Windows Server
2019
    16660    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    18200    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    17690    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    20260    Google Chromium V8 Memory Corruption Vulnerability - Any
Version of MacOS
    1830    Microsoft Active Directory Domain Services Privilege Escalation
Vulnerability - Windows 8.1
    16680    Google Chromium PopupBlocker Security Bypass Vulnerability -
Any Version of Windows
    15660    Google Chromium V8 Out-of-Bounds Write Vulnerability - Any
Version of Windows
    20270    Google Chromium Blink Use-After-Free Vulnerability - Any
Version of MacOS
    26930    Google Chromium libvpx Heap Buffer Overflow Vulnerability -
Any Version of Windows
    16180    Google Chromium Portals Use-After-Free Vulnerability - Any
Version of Windows
    18740    Google Chromium Network Service Use-After-Free Vulnerability -
Any Version of Linux
    20790    Google Chrome FreeType Heap Buffer Overflow Vulnerability -
Any Version of MacOS
    20280    Google Chrome Blink Use-After-Free Vulnerability - Any Version
of MacOS
    17210    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    30010    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    26430    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting
(XSS) Vulnerability - Any Version of Linux
    20290    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    17730    Google Chromium WebGL Use-After-Free Vulnerability - Any
Version of Linux
    32070    Kingsoft WPS Office Path Traversal Vulnerability - Any Version
of Windows
    18760    Google Chromium V8 Out-of-Bounds Read Vulnerability - Any
Version of Linux
    15690    Google Chromium Mojo Insufficient Data Validation
Vulnerability - Any Version of Windows
    35150    Microsoft Windows Common Log File System (CLFS) Driver
Heap-Based Buffer Overflow Vulnerability - Windows Server 2025
    9040    Microsoft Windows LSA Spoofing Vulnerability - Windows Server
2012 R2
    26960    Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
- Any Version of Linux
    13650    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows Server 2022
    28500    Google Chromium V8 Out-of-Bounds Memory Access Vulnerability -
Any Version of Windows
    20820    Google Chromium V8 Use-After-Free Vulnerability - Any Version
of MacOS
    27990    Google Skia Integer Overflow Vulnerability - Any Version of
Windows
    30550    Microsoft Windows LSA Spoofing Vulnerability - Windows Server
2008 R2
    19800    Google Chromium Indexed DB API Use-After-Free Vulnerability -
Any Version of MacOS
    17750    GitLab Community and Enterprise Editions Remote Code Execution
Vulnerability - Any Version of Linux
    30040    Google Chromium V8 Out-of-Bounds Memory Write Vulnerability -
Any Version of Linux
    18780    Google Chromium GPU Heap Buffer Overflow Vulnerability - Any
Version of Linux
    28510    Google Chromium V8 Out-of-Bounds Memory Access Vulnerability -
Any Version of Linux
    20320    Google Chromium Blink Use-After-Free Vulnerability - Any
Version of MacOS
    22880    Google Chrome Skia Integer Overflow Vulnerability - Any
Version of MacOS
    14180    Microsoft Defender Remote Code Execution Vulnerability - Any
Version of Windows
    18790    Google Chromium V8 Incorrect Implementation Vulnerabililty -
Any Version of Linux
    15720    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    20840    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    18280    Google Chromium V8 Memory Corruption Vulnerability - Any
Version of Linux
    28010    Google Skia Integer Overflow Vulnerability - Any Version of
Linux
    30060    Google Chromium V8 Out-of-Bounds Memory Write Vulnerability -
Any Version of MacOS
    4460    Microsoft Windows LSA Spoofing Vulnerability - Windows Server
2008 SP2
    17260    Google Chromium Race Condition Vulnerability - Any Version of
Linux
    26990    Google Chromium libvpx Heap Buffer Overflow Vulnerability -
Any Version of Linux
    16240    Google Chromium Information Disclosure Vulnerability - Any
Version of Windows
    28530    Google Chromium V8 Out-of-Bounds Memory Access Vulnerability -
Any Version of MacOS
    30070    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    32120    HTTP/2 Rapid Reset Attack Vulnerability - Any Version of
Windows
    16760    Google Chromium Network Service Use-After-Free Vulnerability -
Any Version of Windows
    16250    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    20860    Google Chromium V8 Improper Input Validation Vulnerability -
Any Version of MacOS
    33660    Synacor Zimbra Collaboration Suite (ZCS) Command Execution
Vulnerability - Any Version of Linux
    20350    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    22910    PaperCut MF/NG Improper Access Control Vulnerability - Any
Version of MacOS
    14210    Microsoft Malware Protection Engine Improper Restriction of
Operations Vulnerability - Any Version of Windows
    16770    Google Chromium V8 Out-of-Bounds Read Vulnerability - Any
Version of Windows
    19330    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    28040    Google Skia Integer Overflow Vulnerability - Any Version of
MacOS
    19850    Google Chrome Use-After-Free Vulnerability - Any Version of
MacOS
    18830    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    15760    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    18320    Google Chromium V8 Remote Code Execution Vulnerability - Any
Version of Linux
    16790    Google Chromium GPU Heap Buffer Overflow Vulnerability - Any
Version of Windows
    28570    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    7580    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows Server 2019
    32670    Apple Multiple Products WebKit Type Confusion Vulnerability -
Ubuntu
    16800    Google Chromium V8 Incorrect Implementation Vulnerabililty -
Any Version of Windows
    27040    Google Chromium WebP Heap-Based Buffer Overflow Vulnerability
- Any Version of MacOS
    1440    Microsoft Windows LSA Spoofing Vulnerability - Windows 8.1
    18850    Google Chromium Animation Use-After-Free Vulnerability - Any
Version of Linux
    15780    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    28580    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    28590    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    18350    Google Chrome WebAudio Use-After-Free Vulnerability - Any
Version of Linux
    20400    Google Chrome Media Prior to 81.0.4044.92 Use-After-Free
Vulnerability - Any Version of MacOS
    16830    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    19390    Google Chromium Race Condition Vulnerability - Any Version of
MacOS
    16320    Google Chromium V8 Memory Corruption Vulnerability - Any
Version of Windows
    32190    HTTP/2 Rapid Reset Attack Vulnerability - Windows Server 2016
    15810    Google Chromium WebGL Use-After-Free Vulnerability - Any
Version of Windows
    20420    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    19910    Google Chromium Intents Insufficient Input Validation
Vulnerability - Any Version of MacOS
    27080    Google Chromium libvpx Heap Buffer Overflow Vulnerability -
Any Version of MacOS
    3530    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows 7 SP1
    21450    Microsoft Exchange Server Remote Code Execution Vulnerability
- Exchange Server 2016
    25040    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    30160    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
    16850    Google Chromium Animation Use-After-Free Vulnerability - Any
Version of Windows
    19920    Google Chromium V8 Out-of-Bounds Write Vulnerability - Any
Version of MacOS
    18900    Synacor Zimbra Collaboration Suite (ZCS) Arbitrary File Upload
Vulnerability - Any Version of Linux
    20440    Google Chromium PopupBlocker Security Bypass Vulnerability -
Any Version of MacOS
    17880    Google Chromium Indexed DB API Use-After-Free Vulnerability -
Any Version of Linux
    32220    HTTP/2 Rapid Reset Attack Vulnerability - Windows Server 2019
    8670    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows Server 2016
    18400    Synacor Zimbra Collaboration Suite (ZCS) Cross-Site Scripting
(XSS) Vulnerability - Any Version of Linux
    28130    Google Chromium WebRTC Heap Buffer Overflow Vulnerability -
Any Version of Windows
    19940    Google Chromium V8 Out-of-Bounds Write Vulnerability - Any
Version of MacOS
    25060    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    30180    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Linux
    16360    Trihedral VTScada (formerly VTS) Denial-of-Service
Vulnerability - Any Version of Windows
    11240    Microsoft Windows User Profile Service Privilege Escalation
Vulnerability - Windows Server 2012
    20970    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    16370    Google Chromium V8 Remote Code Execution Vulnerability - Any
Version of Windows
    31730    Google Chromium V8 Inappropriate Implementation Vulnerability
- Any Version of Windows
    30200    Google Chromium V8 Type Confusion Vulnerability - Any Version
of MacOS
    34810    Microsoft Windows NTLMv2 Hash Disclosure Spoofing
Vulnerability - Windows Server 2025
    31740    Google Chromium V8 Type Confusion Vulnerability - Any Version
of Windows
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://bigmail.bigfix.com/pipermail/besadmin-announcements/attachments/20250227/b326bef7/attachment.html>


More information about the Besadmin-announcements mailing list