Production Server

You might also like

Download as xlsx, pdf, or txt
Download as xlsx, pdf, or txt
You are on page 1of 23

Plugin Plugin Name

179664 Security Updates for Microsoft .NET Framework (August 2023)


181375 Security Updates for Microsoft .NET Framework (September 2023)
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)

CH121461 - VA Fix Remediation


SOM Remarks
Please check with App vedor to Asses and confirm later SOM team will check and which are applicable we will fix
Please check with App vedor to Asses and confirm later SOM team will check and which are applicable we will fix
Please check with App vedor to Asses and confirm later SOM team will check and which are applicable we will fix
Please check with App vedor to Asses and confirm later SOM team will check and which are applicable we will fix
Microsoft
has
Microsoft
released
has
security
released
updates
security
Severity IP Address Hostname Port Exploit Fr Patch PublVuln Publi CVE Solution
for
updates
Medium 10.18.195.51 NUHAIOAVPDBS01 445 Aug 8, 202Aug 8, 202CVE-2023- Microsoft
Microsoft
for
.NET
Medium 10.18.195.51 NUHAIOAVPDBS01 445 Sep 12, 20 Sep 12, 20 CVE-2023- Microsoft
Microsoft
Framewor
.NET
Medium 10.18.193.51 NUHAIOAVPAPP01 445 Aug 8, 202Aug 8, 202CVE-2023- k.Framewor
Medium 10.18.193.51 NUHAIOAVPAPP01 445 Sep 12, 20 Sep 12, 20 CVE-2023- k.
without
where
parser Remote
an ader.dll
patched.
deployme
acan valid
unsandbo not been
version
has not : Remarks
nts lead patched.
Remote
code
xed
to 4.8.4550.
been
remote version : Action (State the
without
signing
parser 0 Remote
patched. Party dependan
code
acan valid 14.8.4614
lead version
certificate
execution .0 Should
Remote: (Provide cy of
code
.. (CVE-
to 4.8.4550.
beShould
remote version: : Named treatmen
Descriptio
signing
2023-
code Plugin
0 OutTarget Date
4.8.4654.
14.8.4614
(CVE- beShould : Personnel t plan, eg.
certificate
36873)
execution 0
.0 25 Feb 2024 ITMOof/ System Related
Procuring
.2023-
(CVE-
.36788)
14.8.4667
be :
Should Impleme a new SSL
2023- .0 25 Feb 2024 ITMO / System Related
(CVE- 4.8.4654.
be : nter) Certificat
36873)
2023- 0
14.8.4667 25 Feb 2024 ITMO / Systeme) Related
36788) .0 25 Feb 2024 ITMO / System Related
Plugin
183055
183055
183055
Plugin Name
Microsoft Edge (Chromium) < 118.0.2088.46 Multiple Vulnerabilities
Microsoft Edge (Chromium) < 118.0.2088.46 Multiple Vulnerabilities
Microsoft Edge (Chromium) < 118.0.2088.46 Multiple Vulnerabilities
SOM Remarks Severity IP Address Hostname Port Exploit Fr Patch Publ
SOM team will remediate Medium 10.18.193.56 NUHAIOCVPAPP01 445 Oct 13, 20
SOM team will remediate Medium 10.18.193.58 NUHAIOCVPAPP03 445 Oct 13, 20
SOM team will remediate High 10.18.193.58 NUHAIOCVPAPP03 445 Oct 13, 20

CH121461 - VA Fix Remediation


relied
instead version :
Installed
has
only on n
114.0.182 Remarks
Upgrade relied
instead version :
Installed
to the 3.51 Action (State the
Upgrade only on 114.0.182
relied
applicatio version
Fixed : Party dependan
Microsoft
to the
only 3.51
on 114.0.182
Edge n's self- version (Provide cy of
Microsoft applicatio
the
reported
Fixed
3.51
: Named treatmen
Vuln Publi CVE version
Solution n's
Edge self- version
Descriptio
applicatio Plugin
Fixed OutTarget Dat Personnel t plan, eg.
version
118.0.208 reported 118.0.208
Oct 10, 20 CVE-2023- version
Upgrade n's self- :version
8.46 or tonumber.
118.0.208 version 8.46
reported :118.0.208
### ITMO of/ System Related
Procuring
Oct 10, 20 CVE-2023- later. number. 8.46 ### Impleme
ITMO / a new
System SSL
Related
8.46 or version 118.0.208 nter) Certificat
Oct 10, 20 CVE-2023- later. number. 8.46 ### ITMO / System
e) Related
Plugin Plugin Name SOM Remarks Severity
180506 VMware Tools 10.3.x / 11.x / 12.x < 12.3.0 Auth SOM team will remediate Medium
181303 KB5030214: Windows 10 version 1809 / WindowsSOM team will remediate Medium
182865 KB5031361: Windows 10 version 1809 / WindowsSOM team will remediate Medium
182875 Curl 7.69 < 8.4.0 Heap Buffer Overflow SOM team will remediate Medium
180506 VMware Tools 10.3.x / 11.x / 12.x < 12.3.0 Auth SOM team will remediate Medium
181303 KB5030214: Windows 10 version 1809 / WindowsSOM team will remediate Medium
182865 KB5031361: Windows 10 version 1809 / WindowsSOM team will remediate Medium
182875 Curl 7.69 < 8.4.0 Heap Buffer Overflow SOM team will remediate Medium
180506 VMware Tools 10.3.x / 11.x / 12.x < 12.3.0 Auth SOM team will remediate Medium
181303 KB5030214: Windows 10 version 1809 / WindowsSOM team will remediate Medium
182865 KB5031361: Windows 10 version 1809 / WindowsSOM team will remediate Medium
182875 Curl 7.69 < 8.4.0 Heap Buffer Overflow SOM team will remediate Medium

CH121461 - VA Fix Remediation


IP Address Hostname Port Exploit Fr Patch PublVuln Publi CVE Solution
Upgrade
10.18.191.71 NUHAIODVPWEB01 445 Aug 31, 20Aug 31, 20CVE-2023- Apply
Upgrade
to to
Security
10.18.191.71 NUHAIODVPWEB01 445 Sep 12, 20 Sep 12, 20 CVE-2023- curl
ApplytoSecu
VMware
Update
version
10.18.191.71 NUHAIODVPWEB01 445 Oct 10, 20 Oct 10, 20 CVE-2023- Tools
5031361
8.4.0 or
version
10.18.191.71 NUHAIODVPWEB01 445 Oct 11, 20 Oct 11, 20 CVE-2023- later
12.3.0 or
10.18.193.71 NUHAIODVPAPP01 445 Aug 31, 20Aug 31, 20CVE-2023- Apply
later.
Security
10.18.193.71 NUHAIODVPAPP01 445 Sep 12, 20 Sep 12, 20 CVE-2023- Apply
UpdateSecu
10.18.193.71 NUHAIODVPAPP01 445 Oct 10, 20 Oct 10, 20 CVE-2023- 5031361
10.18.193.71 NUHAIODVPAPP01 445 Oct 11, 20 Oct 11, 20 CVE-2023- Upgrade cur
10.18.195.71 NUHAIODVPDBS01 445 Aug 31, 20Aug 31, 20CVE-2023- Upgrade to
10.18.195.71 NUHAIODVPDBS01 445 Sep 12, 20 Sep 12, 20 CVE-2023- Apply Secu
10.18.195.71 NUHAIODVPDBS01 445 Oct 10, 20 Oct 10, 20 CVE-2023- Apply Secu
10.18.195.71 NUHAIODVPDBS01 445 Oct 11, 20 Oct 11, 20 CVE-2023- Upgrade cur
Guest
buffer
relied
tested
Note
CVE- for Tools\
that : C:\
- C:\
:version
instead
has
has not
there.
Vulnerabil
not
Operation
instead patched.
of rollup
been
system32
Windows\ : C:\KBs :
only
this
2023-
relied
testedon
issue
Nessus for Installed
Path
Windows\
-
Program
8.0.1.0 Remote Remarks
ity (CVE-
instead
tested
s.
copying :
\patched.
for SysWOW
the
but
has has
not
38161)
only
this
Note
2023- on
issue version
system32
5030214
version
that Files\ : C:\
-Fixed :
: Action (State the
relied
these
just the
applicatio
instead
tested for Plugin
64\ Remote
ntoskrnl.e
12.2.5.43
Windows\
\ Party dependan
the
but
only has
Nessus
36434)
issues
Note on
that 10.0.1776
VMware\
version
but 5031361
version
xe- C:\
Output: has not :
resolved
n's self-
relied
these
Note that curl.exe
614
System32
ntoskrnl.e (Provide cy of
applicatio
instead
has
the
has not
Nessus 3.4737
VMware
:
been 8.4.0
10.0.1776
Path
address
reported
only
issues
Nessusonbut Installed
Fixed
\curl.exe
xe has not Named treatmen
n's
tested
Note for Windows\
self-
relied that
Descriptio
applicatio
instead
has not
there. Tools\
Plugin
3.4737- Should
patched.
version C:\
: C:\OutTarget
: Dat
version
the
has not
reported
only
this been
be
onfor Windows\
issue Installed
system32 :
Installed
Path Personnel t plan, eg.
Nessus
n's self-
relied
tested Program
8.0.1.0 Should
Remote
number.
applicatio
instead
tested
version
the
but hasfor : 12.3.0
version
patched.
\
10.0.1776
version : C:\: ::: ### ITMOof/ System Related
Procuring
has
this
Note not
that system32
reported
only on
issue be
version
Files\Fixed
n's self-
relied
these
number.
applicatio
instead
tested 8.0.1.0
3.4851 Remote
ntoskrnl.e
12.2.5.43
for \Windows\ ### Impleme
ITMO / a new
System SSL
Related
version
the
but onbut 10.0.1776
has
Nessus
reported
only
issues VMware\
version
xeFixed
version has not : nter) Certificat
n's self-
relied
these
number. 614
System32
ntoskrnl.e
3.4974 ### ITMO / System
applicatio
instead
has
version
the
has
reported
only
issuesonbut
3.4737
not :VMware 8.4.0
version
10.0.1776
been Fixed
\curl.exe
xe has not e) Related
n's self-
relied
tested
number. for
applicatio
instead Tools\
:versionShould
8.4.0
3.4737
patched. ### Application
version
the
has
only
this on been
reported
issue be Installed
:
Installed
Path
n's self-
relied
number.
applicatio Should
Remote
:10.0.1776
12.3.0
version ### ITMO / System Related
instead
version
the
but
only on version
has
reported be : C:\: :::
patched.
version
n's self-
relied
number.
applicatio
instead 8.0.1.0
3.4851Remote
12.2.5.43
Windows\ ### ITMO / System Related
version
the on 10.0.1776
reported
only Fixed :
version
n's self-
relied
number.
applicatio 614
System32
3.4974
3.4737 ### ITMO / System Related
version
the
reported
only version
on 10.0.1776 Fixed
\curl.exe
n's self-
number.
applicatio Should
:version
8.4.0
3.4737 ### Application
version
the
reported be Installed
:
n's self-
number.
applicatio Should
:10.0.1776
12.3.0 : ### ITMO / System Related
version version
reported
n's self- be
number. 8.0.1.0
3.4851
:
### ITMO / System Related
version
reported 10.0.1776 Fixed
number.
version 3.4974 version ### ITMO / System Related
number. : 8.4.0 ### Application
Plugin
179664
181375
179664
181375
179664
181375
179664
181375
179664
181375
Plugin Name
Security Updates for Microsoft .NET Framework (August 2023)
Security Updates for Microsoft .NET Framework (September 2023)
Security Updates for Microsoft .NET Framework (August 2023)
Security Updates for Microsoft .NET Framework (September 2023)
Security Updates for Microsoft .NET Framework (August 2023)
Security Updates for Microsoft .NET Framework (September 2023)
Security Updates for Microsoft .NET Framework (August 2023)
Security Updates for Microsoft .NET Framework (September 2023)
Security Updates for Microsoft .NET Framework (August 2023)
Security Updates for Microsoft .NET Framework (September 2023)

CH121461 - VA Fix Remediation - Eswaran Krishnan


SOM remarks Severity IP Address Hostname Port
Please check with App vedor to Asses and confirmMedium
later SOM10.18.191.76
team will check
NUHEPEVPWEB01
and which are applicable
445 we will fix
Please check with App vedor to Asses and confirmMedium
later SOM10.18.191.76
team will check
NUHEPEVPWEB01
and which are applicable
445 we will fix
Please check with App vedor to Asses and confirmMedium
later SOM10.18.191.77
team will check
NUHEPEVPWEB02
and which are applicable
445 we will fix
Please check with App vedor to Asses and confirmMedium
later SOM10.18.191.77
team will check
NUHEPEVPWEB02
and which are applicable
445 we will fix
Please check with App vedor to Asses and confirmMedium
later SOM10.18.193.76
team will check
NUHEPEVPAPP01
and which are applicable
445 we will fix
Please check with App vedor to Asses and confirmMedium
later SOM10.18.193.76
team will check
NUHEPEVPAPP01
and which are applicable
445 we will fix
Please check with App vedor to Asses and confirmMedium
later SOM10.18.195.76
team will check
NUHEPEVPDBS01
and which are applicable
445 we will fix
Please check with App vedor to Asses and confirmMedium
later SOM10.18.195.76
team will check
NUHEPEVPDBS01
and which are applicable
445 we will fix
Please check with App vedor to Asses and confirmMedium
later SOM10.18.195.77
team will check
NUHEPEVPDBS02
and which are applicable
445 we will fix
Please check with App vedor to Asses and confirmMedium
later SOM10.18.195.77
team will check
NUHEPEVPDBS02
and which are applicable
445 we will fix
vulnerabil
without
where
unauthen
2023- an Microsoft.
Remote
ader.dll
k\
Windows\
parser
Microsoft attacker
deployme
WPF
ity - Awhere patched.
system.wi
XML Framewor
not
9\
NET\been
avulnerabil
unsandbo
ticated
36796)
can valid
sign version
has not :
v4.0.3031
Microsoft.
lead k\ Remote
ndows.for Remarks
has nts
parser
an
code
Microsoft remote
xed patched.
diasymre
Framewor
4.8.4550.
been
9\
NET\ Action (State the
released to
ClickOnce
ity
without
where
unauthen remote
in the version
ms.dll
an v4.0.3031
Remote
ader.dll
k\ :
has
has
Microsoft signing
parser
attacker
code
deployme
WPF - A 0
patched.
system.wi
Framewor
14.8.4644
not
XML 9\ been Party dependan
security
released aticated
unsandbo
certificate
can
vulnerabil valid
lead version
sign has not :
v4.0.3031
Should
Remote
ndows.for
k\ (Provide cy of
has
updates execution
nts
parser
code
xed
remote .0
patched.
diasymre
4.8.4550.
been
9\
security
released .where
to
ClickOnce
ity
.attacker
without (CVE-
remote
in the be
ms.dll:has
version
an v4.0.3031
Should
Remote
ader.dll : Named treatmen
Exploit Fr Patch PublVuln Publi CVE Solution
for
updates Descriptio
signing
parser
2023-
code Plugin
0
patched.OutTarget Dat
system.wi
4.8.4654.
14.8.4644
deployme
WPF
security unsandbo
acan XML
(CVE-
valid not
9\
be been
: :
version Personnel t plan, eg.
Aug 8, 202Aug 8, 202CVE-2023- Microsoft
Microsoft
for certificate
36873)
execution
nts
parser lead has
sign .0
not
Should
Remote
ndows.for
0
patched.
diasymre ### ITMOof/ System Related
Procuring
updates xed
.NET .2023-
code
to (CVE-
ClickOnce remote 14.8.4667
4.8.4550.
been
be :has
version
ms.dll :
Sep 12, 20 Sep 12, 20 CVE-2023- Microsoft
Microsoft
for
Framewor
.where
without
36788)
signing
parser
2023-
code
deployme
an .0
0 Should
Remote
ader.dll
patched.
4.8.4654.
14.8.4644
not been ### Impleme
ITMO / a new
System SSL
Related
.NET
Microsoft acan
unsandbo(CVE-
valid
certificate
lead be : :
version
hasRemote
not
Should nter) Certificat
Aug 8, 202Aug 8, 202CVE-2023- k.Framewor 36873)
execution
nts
2023-
code
xed 0
.0
patched.
14.8.4667
4.8.4550. ### ITMO / System
e) Related
.NET .without
to
. remote been
(CVE- beRemote
: :
version
Should
Sep 12, 20 Sep 12, 20 CVE-2023- k.
Framewor parser 36788)
signing
2023-
code .0
0
patched.
4.8.4654.
14.8.4644 ### ITMO / System Related
acan (CVE-
valid
certificate
lead beRemote
: :
version
Should
Aug 8, 202Aug 8, 202CVE-2023- k. 36873)
execution
2023- 0
.0
14.8.4667 ### ITMO / System Related
.code
to(CVE- 4.8.4550.
remote be : :
version
Sep 12, 20 Sep 12, 20 CVE-2023- Microsoft .signing 36788)
2023-
code .0
0 Should
4.8.4654. ### ITMO / System Related
(CVE- 14.8.4644
certificate beShould
:
Aug 8, 202Aug 8, 202CVE-2023- Microsoft execution 36873)
2023- 0
.0
14.8.4667 ### ITMO / System Related
.. (CVE- beShould
:
Sep 12, 20 Sep 12, 20 CVE-2023- Microsoft 36788) 2023- .0 ### ITMO / System Related
(CVE- 4.8.4654.
be :
Aug 8, 202Aug 8, 202CVE-2023- Microsoft 36873) 2023- 0
14.8.4667 ### ITMO / System Related
Sep 12, 20 Sep 12, 20 CVE-2023- Microsoft 36788) .0 ### ITMO / System Related
stem Related
stem Related
stem Related
stem Related
stem Related
stem Related
stem Related
stem Related
stem Related
stem Related
Plugin Plugin Name
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)
183055 Microsoft Edge (Chromium) < 118.0.2088.46 Multiple Vulnerabilities
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)
183055 Microsoft Edge (Chromium) < 118.0.2088.46 Multiple Vulnerabilities
SOM Remarks Severity IP Address Hostname Port Exploit Fr Patch Publ
Please check with App vedor to AssMedium 10.18.195.61 NUHETLVPDBS01 445 Aug 8, 202
Please check with App vedor to AssMedium 10.18.195.61 NUHETLVPDBS01 445 Sep 12, 20
SOM team will remediate Medium 10.18.195.61 NUHETLVPDBS01 445 Oct 13, 20
Please check with App vedor to AssMedium 10.18.195.62 NUHETLVPDBS02 445 Aug 8, 202
Please check with App vedor to AssMedium 10.18.195.62 NUHETLVPDBS02 445 Sep 12, 20
SOM team will remediate Medium 10.18.195.62 NUHETLVPDBS02 445 Oct 13, 20

CH121461 - VA Fix Remediation


Remarks
Action (State the
Party dependan
(Provide cy of
Named treatmen
Vuln Publi CVE Solution Descriptio Plugin OutTarget Dat
Personnel t plan, eg.
Aug 8, 202CVE-2023- Microsoft The MicrosoftPlugin
.NET Framework
25-Feb-24installation
ITMO of/ on the remote host is missing a security update. It
Procuring
Output:
Sep 12, 20 CVE-2023- Microsoft The Microsoft
Plugin
.NET Framework System
Impleme
25-Feb-24installation
ITMO / aonnew
theSSL
remote host is missing a security update. It
- A remoteOutput:
code execution vulnerability
Related
nter)
System inCertificat
applications running on IIS using their parent appl
Oct 10, 20 CVE-2023- Upgrade toThe versionPlugin
of Microsoft25-Feb-24
Edge installed
ITMO /on the remote Windows host is prior to 118.0.2088.46
- MultipleOutput:
vulnerabilities in DiaSymReader.dll
Related
System e) where parsing an corrupted PDB can result in r
- A Microsoft
Aug 8, 202CVE-2023- Microsoft The spoofing vulnerability
Plugin
.NET Framework where
25-Feb-24 an unauthenticated
installation
ITMO / on the remoteremotehostattacker
is missingcanasign ClickOnce
security update.dep
It
- Use afterOutput:
free in Site Isolation Related
in Google Chrome prior to 118.0.5993.70 allowed a remote a
System
- A Microsoft
Sep 12, 20 CVE-2023- Microsoft The vulnerability
Plugin
.NETin Framework
the WPF XML
25-Feb-24 parser
/ where
installation
ITMO on thean remote
unsandboxed
host is parser
missingcan lead to remote
a security update.coIt
- (CVE-2023-36788)
A remoteOutput:
code execution vulnerability
Related
System in applications running on IIS using their parent appl
- Use
Oct 10, 20 CVE-2023- Upgrade toThe afterPlugin
version free in Cast
of Microsoft inEdge
Google
25-Feb-24 Chrome
installed
ITMO /on prior to 118.0.5993.70
the remote Windows host allowed a remote
is prior attacker w
to 118.0.2088.46
- MultipleOutput:
vulnerabilities in DiaSymReader.dll
Related where parsing an corrupted PDB can result in r
- A spoofing vulnerability whereSysteman unauthenticated remote attacker can sign ClickOnce dep
Heapafter
- Use buffer
freeoverflow in PDF inRelated
in Site Isolation inGoogle
GoogleChrome
Chromeprior priortoto118.0.5993.70
118.0.5993.70allowed
alloweda aremote
remoteatta
- A vulnerability in the WPF XML parser where an unsandboxed parser can lead to remote co
- (CVE-2023-36788)
Inappropriate
Use implementation
after free in Cast in GoogleinChrome
DevTools
priorin Google Chrome prior
to 118.0.5993.70 to 118.0.5993.70
allowed allowe
a remote attacker w
Use after
- Heap free
buffer in Blink in
overflow History
PDF ininGoogle
GoogleChrome
Chromeprior
priortoto118.0.5993.70
118.0.5993.70allowed
allowedaaremote
remoteatt
a

Installer ininGoogle
- Inappropriate implementation in DevTools GoogleChrome
Chromeprior
priortoto118.0.5993.70
118.0.5993.70allowed
allowe
- Inappropriate implementation
Use after free in Blink History ininGoogle
AutofillChrome
in Google Chrome
prior prior to 118.0.5993.70
to 118.0.5993.70 alloweda
allowed a remote
Extensions
- Inappropriate implementation in Installer API in Google
in Google ChromeChrome
prior toprior to 118.0.5993.70
118.0.5993.70 a
allowed
Downloads
- Inappropriate implementation in Autofill in Google
in Google Chrome
Chrome priorprior to 118.0.5993.70
to 118.0.5993.70 allow
allowed
Intents in Google
- Inappropriate implementation in Extensions ChromeChrome
API in Google prior toprior
118.0.5993.70 alloweda
to 118.0.5993.70
Navigation in
- Inappropriate implementation in Downloads in Google
Google Chrome
Chrome prior
prior to
to 118.0.5993.70
118.0.5993.70 allow
allow
Autofill in Google Chrome prior to 118.0.5993.70 allowed
- Inappropriate implementation in Intents
Input in Google
- Inappropriate implementation in Navigation Chrome
in Google prior to
Chrome 118.0.5993.70
prior allowed
to 118.0.5993.70 a
allow
Fullscreen
- Inappropriate implementation in Autofill in Google
in Google Chrome
Chrome prior
prior to 118.0.5993.70
to 118.0.5993.70 allow
allowed
Note that Nessusimplementation
- Inappropriate has not tested for these in
in Input issues butChrome
Google has instead
priorrelied only on the application
to 118.0.5993.70 allowed a

- Inappropriate implementation in Fullscreen in Google Chrome prior to 118.0.5993.70 allow

Note that Nessus has not tested for these issues but has instead relied only on the application
Plugin Plugin Name
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)
179664 Security Updates for Microsoft .NET Framework (August 2023)
181375 Security Updates for Microsoft .NET Framework (September 2023)

CH121461 - VA Fix Remediation


SOM Remarks Severity IP Address Hostname
Please check with App vedor to Asses and confirm later SOMedium 10.18.191.91 NUHREDVPWEB01
Please check with App vedor to Asses and confirm later SOMedium 10.18.191.91 NUHREDVPWEB01
Please check with App vedor to Asses and confirm later SOMedium 10.18.191.92 NUHREDVPWEB02
Please check with App vedor to Asses and confirm later SOMedium 10.18.191.92 NUHREDVPWEB02
Please check with App vedor to Asses and confirm later SOMedium 10.18.191.93 NUHREDVPWEB03
Please check with App vedor to Asses and confirm later SOMedium 10.18.191.93 NUHREDVPWEB03
Please check with App vedor to Asses and confirm later SOMedium 10.18.193.91 NUHREDVPAPP01
Please check with App vedor to Asses and confirm later SOMedium 10.18.193.91 NUHREDVPAPP01
Please check with App vedor to Asses and confirm later SOMedium 10.18.195.91 NUHREDVPDBS01
Please check with App vedor to Asses and confirm later SOMedium 10.18.195.91 NUHREDVPDBS01
Please check with App vedor to Asses and confirm later SOMedium 10.18.195.92 NUHREDVPDBS02
Please check with App vedor to Asses and confirm later SOMedium 10.18.195.92 NUHREDVPDBS02
Please check with App vedor to Asses and confirm later SOMedium 10.18.195.93 NUHREDVPDBS03
Please check with App vedor to Asses and confirm later SOMedium 10.18.195.93 NUHREDVPDBS03
vulnerabil
released 2023-
without
where
unauthen
2023- Microsoft.
5029925
an k\- Remote
ader.dll
Windows\
parser
attacker - Awhere patched.
system.wi
Framewor
XML C:\
security 36793,
deployme
WPF
ity
36794
avulnerabil
unsandbo
ticated
36796)
36899)
can valid
sign
eNET\
not
9\
has been
version
not :
v4.0.3031
Microsoft.
5028953
lead Windows\
Remote
ndows.for
k\
spoofing
CVE-
nts
parser
an
CVE- -
patched.
diasymre
Framewor
C:\
updates remote
code
xed
to
ClickOnce
ity
vulnerabil remote
in the 4.8.4550.
been
9\
NET\
version
ms.dll
v4.0.3031:
has
Microsoft. Action
for 2023-
without
where
unauthen
2023-
signing an 5029925
k\ Remote
ader.dll
Windows\
0
parser
attacker
code
deployme
WPF
ity - A patched.
system.wi
Framewor
C:\
14.8.4644
not
XML NET\
where 9\ been Party
Microsoft 36794
a36796)
unsandbo
ticated
certificate
can
vulnerabil
spoofing
execution
nts
parser
valid
lead
sign version
has not :
v4.0.3031
Microsoft.
Should
Remote
ndows.for
k\
Windows\
.0
patched.
diasymre (Provide
an
CVE-
code
xed
remote Framewor
C:\
4.8.4550.
been
9\
NET\
.NET .vulnerabil
to
ClickOnce
ity
.2023-
without
where (CVE-
remote
in the be
ms.dll:has
version
an v4.0.3031 :
Microsoft.
Should
Remote
ader.dll Named
Port Exploit Fr Patch PublVuln Publi CVE Solution unauthen
Descriptio
signing
parser
attacker - A k\
Windows\
Plugin
0
patched.OutTarget Dat
system.wi
Framewor
Framewor ity 2023-
code
deployme
WPF
avulnerabil
unsandbo XML
where
(CVE-
valid 4.8.4654.
14.8.4644
not
9\
NET\
be been
: :
version
has not Personnel
ticated
36796)
certificate
can sign v4.0.3031
lead Microsoft.
Should
Remote
ndows.for
k\
445 Aug 8, 202Aug 8, 202CVE-2023- k. 36873)
execution
nts
parser
an
2023-
code 0
.0
patched.
diasymre
Framewor
14.8.4667
4.8.4550. ### ITMO of/ System Related
.xed
remote
to
.ClickOnce
ity
without
where (CVE-
remote
in the
an
been
9\
NET\
be
ms.dll:has
version
v4.0.3031
Should
Remote
ader.dll : Impleme
445 Sep 12, 20 Sep 12, 20 CVE-2023- Microsoft unauthen
36788)
signing
parser k\
.0
0
patched. ### ITMO / System Related
Microsoft attacker
2023-
code
adeployme
WPF
unsandbo
ticated (CVE-
valid
system.wi
- A XML Framewor
4.8.4654.
14.8.4644
not
9\
be been
: :
version
has not
v4.0.3031 nter)
445 Aug 8, 202Aug 8, 202CVE-2023- has
Microsoft certificate
can
vulnerabil
36873)
execution
nts lead
sign 0
.0 Should
Remote
ndows.for
k\
patched. ### ITMO / System Related
Microsoft parser 2023-
code
xed
remote
.where
to (CVE-
ClickOnce
ity remote
in the
diasymre
14.8.4667
4.8.4550.
been
9\
be
ms.dll:has
version
v4.0.3031:
445 released
Sep 12, 20 Sep 12, 20 CVE-2023- has
Microsoft .
without
36788)
signing
parser
attacker an .0
0 Should
Remote
ader.dll
patched. ### ITMO / System Related
Microsoft
security 2023-
code
deployme
WPF
acan
unsandbo XML system.wi
(CVE-
valid 4.8.4654.
14.8.4644
not
9\
be been
: :
version
has not
445 released
Aug 8, 202Aug 8, 202CVE-2023- has
Microsoft certificate
36873)
execution
nts
parser lead
sign 0
.0 Should
Remote
ndows.for
patched.
diasymre ### ITMO / System Related
updates
Microsoft
security .xed 2023-
code
to (CVE-
ClickOnce remote 14.8.4667
4.8.4550.
been
be :has
version
ms.dll :
445 Sep 12, 20 Sep 12, 20 CVE-2023- released
Microsoft
for
has .
without
where
36788)
signing an .0
0 Should
Remote
ader.dll ### ITMO / System Related
Microsoft parser
updates
security 2023-
code
adeployme(CVE-
valid
unsandbo
patched.
4.8.4654.
14.8.4644
not
be been
: :
version
hasRemote
not
445 Microsoft
released
Aug 8, 202Aug 8, 202CVE-2023- has
Microsoft
for certificate
can
36873)
execution
nts lead 0
.0 Should
patched. ### ITMO / System Related
updates
Microsoft
.NET
security 2023-
code
xed
.without
to (CVE- 14.8.4667
4.8.4550.
remote been
beRemote
: :
version
445 Microsoft
released
Sep 12, 20 Sep 12, 20 CVE-2023- has
Microsoft
for .
36788)
signing
parser .0
0 Should
patched. ### ITMO / System Related
Framewor
updates
.NET
security 2023-
code
acan (CVE-
valid 4.8.4654.
14.8.4644
beRemote
: :
version
445 Microsoft
released
Aug 8, 202Aug 8, 202CVE-2023- for
k. certificate
36873) lead
execution 0
.0 Should ### ITMO / System Related
Framewor
updates
security .code
.NET 2023-
(CVE- 14.8.4667
4.8.4550.
remote be : :
445 Sep 12, 20 Sep 12, 20 CVE-2023- Microsoft
k.
for .to
36788)
signing
version
.0
0 Should ### ITMO / System Related
Framewor
updates
.NET 2023-
code 4.8.4654.
(CVE- 14.8.4644
beShould
:
445 Microsoft
Aug 8, 202Aug 8, 202CVE-2023- for
k. certificate
36873)
execution 0
.0 ### ITMO / System Related
Framewor
.NET 2023-
.. (CVE- 14.8.4667
beShould
:
445 Microsoft
Sep 12, 20 Sep 12, 20 CVE-2023- k. 36788) .0 ### ITMO / System Related
Framewor
.NET 2023-
(CVE- 4.8.4654.
be :
445 Aug 8, 202Aug 8, 202CVE-2023- k.Framewor 36873) 2023- 0
14.8.4667 ### ITMO / System Related
445 Sep 12, 20 Sep 12, 20 CVE-2023- k. 36788) .0 ### ITMO / System Related
Remarks
(State the
dependan
cy of
treatmen
t plan, eg.
ITMO / System Related
Procuring
a new
ITMO / System SSL
Related
Certificat
ITMO / System
e) Related
ITMO / System Related
ITMO / System Related
ITMO / System Related
ITMO / System Related
ITMO / System Related
ITMO / System Related
ITMO / System Related
ITMO / System Related
ITMO / System Related
ITMO / System Related
ITMO / System Related

You might also like