Microsoft Says Windows Not Impacted by regreSSHion as Second OpenSSH Bug Is Found

July 15, 2024 at 07:24AM OpenSSH recently faced a second remote code execution vulnerability, named regreSSHion. Discovered by Qualys and Openwall founder Alexander Peslyak, the bug impacts OpenSSH servers and a race condition in the ‘privsep’ child process. Another flaw, tracked as CVE-2024-6409, was also found, with impacted Linux distributions releasing advisories and patches. Windows … Read more

Why Do CVE Scores Need Real-World Context to Prioritize?

October 25, 2023 at 03:11PM The CVSS severity rating lacks real-world context, making it difficult for companies to prioritize fixes. Many vulnerabilities are harder to exploit than indicated by their CVSS scores. Factors such as exploitability in default configurations and specific attack conditions should be considered. The upcoming CVSS 4.0 update does not fully address … Read more