Top 5 Zero-day Vulnerabilities of January

1. CVE-2023-23560

Severity – Critical

In certain Lexmark products through 2023-01-12, SSRF can occur because of a lack of input validation..

More details : https://vi.strobes.co/cve/CVE-2023-23560

Zero day references:

  1. https://portswigger.net/daily-swig/researcher-drops-lexmark-rce-zero-day-rather-than-sell-vuln-for-peanuts

Patch references:

  1. https://publications.lexmark.com/publications/security-alerts/CVE-2023-23560.pdf
  2. https://support.lexmark.com/alerts/

2. CVE-2023-22952

Severity – High

In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.

More details : https://vi.strobes.co/cve/CVE-2023-22952

Zero day references:

  1. https://sugarclub.sugarcrm.com/explore/product-updates/b/sugar-sell-updates/posts/january-4-2023-critical-security-hotfix
  2. https://www.zero-day.cz/database/742

Patch references:

  1. https://www.cybersecurity-help.cz/vdb/SB2023011122
  2. https://support.sugarcrm.com/Resources/Security/sugarcrm-sa-2023-001/

3. CVE-2023-21674

Severity – High

Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability.

More details : https://vi.strobes.co/cve/CVE-2023-21674

Zeroday references: 

  1. https://www.zero-day.cz/database/741

Patch references:

  1. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022352
  2. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022346
  3. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022289
  4. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022297
  5. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022282
  6. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022303
  7. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022287
  8. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022291
  9. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5022286
  10. https://www.cybersecurity-help.cz/vdb/SB2023011042
  11. https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2023-21674

4. CVE-2022-44698

Severity – Medium

Windows SmartScreen Security Feature Bypass Vulnerability.

More details: https://vi.strobes.co/cve/CVE-2022-44698

Zero day references:

  1. https://www.zero-day.cz/database/738

Patch references:

  1. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5021235
  2. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5021233
  3. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5021234
  4. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5021249
  5. https://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB5021237
  6. https://www.cybersecurity-help.cz/vdb/SB2022121336
  7. https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2022-44698

5. CVE-2022-42856

Severity – High

More details :https://vi.strobes.co/cve/CVE-2022-42856

Zero day references:

  1. https://www.zero-day.cz/database/740

Patch references:

  1. https://www.cybersecurity-help.cz/vdb/SB2022121376
  2. https://support.apple.com/en-us/HT213531
  3. https://support.apple.com/en-us/HT213532
  4. https://support.apple.com/en-us/HT213537
  5. https://support.apple.com/en-us/HT213516
  6. https://support.apple.com/en-us/HT213535

Zero-Day Attack Prevention:

These exploits are unpredictable, zero-day protection is necessary. Here are some suggestions regarding how to safeguard your software and vulnerable programs from zero-day attacks.

  • Once the security patches are available, update all programs and software.
  • Web application software must be employed to secure the website. You are capable of precisely detecting attacks.
  • Install a security package for the internet. It often comprises default-deny protection, heuristic file analysis, smart anti-virus, and sandboxing techniques.
  • Operate on sites that are secured with Secure Socket Layer (SSL).
  • Go for multiple layer protection with Web application firewalls.
  • Protect the content of individual transmissions with the help of Virtual LANs.

Stay ahead of threats using Strobes:

Strobes will help you correlate data between vulnerability scans and vulnerability intelligence making sure to keep you updated whenever there is a zero-day in the wild. 

About The Author

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top