Before you go away for Xmas: You've patched that critical Perforce Server hole, right?
ID: aade5153-e510-57d4-8fdc-93b435067c0b
STIX ID: report--aade5153-e510-57d4-8fdc-93b435067c0b
Feed Name: The Register (Security)
Microsoft disclosed four vulnerabilities in Perforce Helix Core Server, with CVE-2023-45849 being a critical unauthenticated remote code execution flaw that can run commands as LocalSystem; Perforce patched the issues (update to 2023.1/2513900 or later) and both Microsoft and Perforce recommend mitigations such as VPN/IP allow-lists, TLS client validation, logging, and network segmentation. Microsoft reported no observed exploitation in the wild but warned that an attacker could fully compromise systems, insert backdoors, exfiltrate source code, and pivot to other infrastructure if systems remain unpatched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
