Summary:
Research recently disclosed a series of critical vulnerabilities impacting various software and hardware products. One of the most notable discoveries was a memory corruption vulnerability (CVE-2023-36887) in Microsoft Edge's JavaScript implementation of the Adobe Acrobat PDF engine. This flaw affected versions 112.0.1722.58 and 114.0.1776.0 Canary. Attackers could exploit this vulnerability by enticing users into opening a specially crafted PDF, leading to type confusion and potential unauthorized memory writes. Fortunately, Microsoft promptly addressed this issue with a patch released on July 13. Furthermore, revealed multiple vulnerabilities in the Milesight UR32L router and MilesightVPN products. Despite Cisco's adherence to the vulnerability disclosure policy, which grants a 90-day window for vendors to respond and fix the issues, Milesight failed to provide an official fix.[/subscribe_to_unlock_form]
Summary:
Research recently disclosed a series of critical vulnerabilities impacting various software and hardware products. One of the most notable discoveries was a memory corruption vulnerability (CVE-2023-36887) in Microsoft Edge's JavaScript implementation of the Adobe Acrobat PDF engine. This flaw affected versions 112.0.1722.58 and 114.0.1776.0 Canary. Attackers could exploit this vulnerability by enticing users into opening a specially crafted PDF, leading to type confusion and potential unauthorized memory writes. Fortunately, Microsoft promptly addressed this issue with a patch released on July 13. Furthermore, revealed multiple vulnerabilities in the Milesight UR32L router and MilesightVPN products. Despite Cisco's adherence to the vulnerability disclosure policy, which grants a 90-day window for vendors to respond and fix the issues, Milesight failed to provide an official fix.[emaillocker id="1283"]
Additionally, researchers uncovered heap buffer overflow vulnerabilities in the Diagon text translator. Diagon, which translates Markdown into various formats, such as latex, planar graph, and tables, contained two flaws (CVE-2023-31194 and CVE-2023-27390) that could result in heap-based buffer overflow conditions. Exploiting these vulnerabilities involved tricking users into opening specially crafted Markdown files, leading to improper array index validation and even remote code execution.
Recommendations:
We strongly recommend you apply vendor released an update patch in Microsoft edge.
References:
The following reports contain further technical details:
https://blog.talosintelligence.com/vulnerability-roundup-july-19-23/
[/emaillocker]