This weekly blog post is from via our unique intelligence collection pipelines. We are your eyes and ears online, including the Dark Web.
There are thousands of vulnerability discussions each week. SOS Intelligence gathers a list of the most discussed Common Vulnerabilities and Exposures (CVE) online for the previous week.
We make every effort to ensure the accuracy of the data presented. As this is an automated process some errors may creep in.
If you are feeling generous please do make us aware of anything you spot, feel free to follow us on Twitter @sosintel and DM us. Thank you!
1. CVE-2023-45866
Bluetooth HID Hosts in BlueZ may permit an unauthenticated Peripheral role HID Device to initiate and establish an encrypted connection, and accept HID keyboard reports, potentially permitting injection of HID messages when no user interaction has occurred in the Central role to authorize such access. An example affected package is bluez 5.64-0ubuntu1 in Ubuntu 22.04LTS. NOTE: in some cases, a CVE-2020-0556 mitigation would have already addressed this Bluetooth HID Hosts issue.
https://nvd.nist.gov/vuln/detail/CVE-2023-45866
2. CVE-2024-38112
Windows MSHTML Platform Spoofing Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-38112
3. CVE-2024-38021
Microsoft Outlook Remote Code Execution Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-38021
4. CVE-2024-38074
Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-38074
5. CVE-2024-38052
Kernel Streaming WOW Thunk Service Driver Elevation of Privilege Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-38052
6. CVE-2024-38080
Windows Hyper-V Elevation of Privilege Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-38080
7. CVE-2024-38140
Windows Reliable Multicast Transport Driver (RMCAST) Remote Code Execution Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-38140
8. CVE-2024-38199
Windows Line Printer Daemon (LPD) Service Remote Code Execution Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2024-38199
9. CVE-2022-44666
Windows Contacts Remote Code Execution Vulnerability
https://nvd.nist.gov/vuln/detail/CVE-2022-44666
10. CVE-2018-17144
Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.
https://nvd.nist.gov/vuln/detail/CVE-2018-17144