Skip to main content Skip to navigation

Homepage contents

Full-width image dimensions are 1170px x 300px.

hp-01-block

Security Alerts

2023-09-15-AdobeAcrobatAndReader-CVE-2023-26369

Risk Level - High.

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

2023-04-19 - Google Chrome - CVE-2023-2033

HIGH - Warwick CSIIRT have been notified that there is a zero-day vulnerability in Google Chrome prior to version 112.0.5615.121 which allows a remote threat actor to potentially exploit heap corruption via a crafted HTML page. Heap corruption is the circumstance under which misbehaving code corrupts the data heap. (The data heap is a block of memory that the OS sets aside for an application to hold its data in.) This can lead to a threat actor executing arbitrary code. The CVE identifier associated with this issue is CVE-2023-2033.

2023-04-18 - Vulnerability Notification - PaperCut MF/NG - ZDI-CAN-19226 / PO-1219

It is confirmed that under certain circumstances this allows for an unauthenticated attacker to potentially pull information about a user stored within Papercut MF or NG - including usernames, full names, email addresses, office/department info and any card numbers associated with the user. The attacker can also retrieve the hashed passwords for internal Papercut-created users only (note that this does not include any password hashes for users sync’d from directory sources such as Microsoft 365 / Google Workspace / Active Directory and others). This could be done remotely and without the need to log in. The Vendor does not have any evidence of this vulnerability being used against customers at this point.

hp-01-image

IT Services - Information Security


Contacts

Mail: CSIIRT@warwick.ac.uk
Phone: ext 73737 (Helpdesk)
PGP key
RFC 2350

hp-02-block

Service Description

The ITS Security Team provides a comprehensive IT Security service to The University of Warwick for users, groups and the many electronic systems.

Mail: CSIIRT@warwick.ac.uk
Phone: ext 73737 (Helpdesk)
PGP key
RFC 2350