Windows 10: F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers

Discus and support F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers in Windows 10 Software and Apps to solve the problem; Hello Experts,We have few windows server 2012/2016 servers, we have a vulnerability scanning tool which scans all the servers for vulnerabilities, when... Discussion in 'Windows 10 Software and Apps' started by Black_Adam, Mar 20, 2023.

  1. F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers


    Hello Experts,We have few windows server 2012/2016 servers, we have a vulnerability scanning tool which scans all the servers for vulnerabilities, when we scan the servers it detect the F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers. Though, this is for F5 appliances, do we have any solution for MS servers available so that this can be remediated?Thank you

    :)
     
    Black_Adam, Mar 20, 2023
    #1
  2. TD47 Win User

    SQLITE vulnerability CVE-2018-20346, CVE-2018-20505, CVE-2018-20506

    There is a reported vulnerability in older versions of SQLITE:

    See 21th Dec 2018 CVE ID has been assigned as CVE-2018-20346, CVE-2018-20505, CVE-2018-20506

    https://blade.tencent.com/magellan/index_en.html

    and

    Crash Chrome 70 with the SQLite Magellan bug

    However, I see that the Windows Update Installer Patch Cache uses sqlite.dll version 15.7.20033 (dated 2015):

    C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744CAF070E41400\15.7.20033\sqlite.dll

    Since this is 3 years old, does anyone know if this is vulnerable?
     
  3. Recommended way to fix vulnerabilities and CVE in Microsoft Windows Server 2019 Standard Evaluation

    Hello Folks,

    I am using Microsoft Windows Server 2019 Standard Evaluation .

    Recently, scanned this server and found the following vulnerabilities:

    Critical count : 4

    High count : 5

    Medium count : 9

    But the catch here is that in each critical count vulnerability there are multiple CVE
    F5 BIG-IP TLS Vulnerability Ticketbleed  CVE-2016-9244 vulnerability in windows servers 44cd268b-f6c1-443d-90c5-7c0e73c7d76c?upload=true.png


    So, inspite of having 4 crititical vulnerability , I have 190 CVE vulnerability.

    What is the recommended way to fix all these vulnerabilities?

    Am I supposed to resolve each CVE separately or is there any other method .

    Note: I am using Microsoft Catalog Update. It makes one package update manually. But I am facing an issue over there.


    F5 BIG-IP TLS Vulnerability Ticketbleed  CVE-2016-9244 vulnerability in windows servers a3df5dd9-24ff-4e87-bf1f-606d6cd0b9c6?upload=true.png


    Please help me to resolve these issues.

    Thanks.
     
    Vikash Kumar Chaudhary, Mar 21, 2023
    #3
  4. Yukikaze Win User

    F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers

    WPA2 Vulnerability Found

    A small update with regards to the Microsoft fix. The fix itself is sufficient to solve the issue on Windows, even if your WiFi device has no driver update, with one caveat:

    Does this security update fully address these vulnerabilities on Microsoft Platforms, or do I need to perform any additional steps to be fully protected?
    The provided security updates address the reported vulnerabilities; however, when affected Windows based systems enter a connected standby mode in low power situations, the vulnerable functionality may be offloaded to installed Wi-Fi hardware. To fully address potential vulnerabilities, you are also encouraged to contact your Wi-Fi hardware vendor to obtain updated device drivers. For a listing of affected vendors with links to their documentation, review the ICASI Multi-Vendor Vulnerability Disclosure statement here: ICASI integrates into FIRST PSIRT SIG bolstering the incident response and security team industry

    Source: Security Update Guide - Microsoft Security Response Center
     
    Yukikaze, Mar 21, 2023
    #4
Thema:

F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers

Loading...
  1. F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers - Similar Threads - BIG TLS Vulnerability

  2. CVE-2023-49210 Critical Vulnerability OpenSSL

    in Windows 10 Gaming
    CVE-2023-49210 Critical Vulnerability OpenSSL: CVE-2023-49210 Critical Vulnerability OpenSSL-Hi Team about this vulnerability detected by Defender, there are a lot of applications detected in this and as per remediation step need to upgrade those. But this is not possible at the moment, Can we fix it or is it a thing...
  3. CVE-2023-49210 Critical Vulnerability OpenSSL

    in AntiVirus, Firewalls and System Security
    CVE-2023-49210 Critical Vulnerability OpenSSL: CVE-2023-49210 Critical Vulnerability OpenSSL-Hi Team about this vulnerability detected by Defender, there are a lot of applications detected in this and as per remediation step need to upgrade those. But this is not possible at the moment, Can we fix it or is it a thing...
  4. CVE-2023-38545 cURL vulnerability

    in Windows 10 Gaming
    CVE-2023-38545 cURL vulnerability: Hello!I have a lot of workstations affected by this that are being classified as vulnerable by Tenable. All of these have cURL onboard pre-installed on the machines. I see this means we have to wait for Microsoft to release an update. Can someone please provide any idea as to...
  5. CVE-2023-38545 cURL vulnerability

    in Windows 10 Software and Apps
    CVE-2023-38545 cURL vulnerability: Hello!I have a lot of workstations affected by this that are being classified as vulnerable by Tenable. All of these have cURL onboard pre-installed on the machines. I see this means we have to wait for Microsoft to release an update. Can someone please provide any idea as to...
  6. F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers

    in Windows 10 Gaming
    F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers: Hello Experts,We have few windows server 2012/2016 servers, we have a vulnerability scanning tool which scans all the servers for vulnerabilities, when we scan the servers it detect the F5 BIG-IP TLS Vulnerability Ticketbleed CVE-2016-9244 vulnerability in windows servers....
  7. Recommended way to fix vulnerabilities and CVE in Microsoft Windows Server 2019 Standard...

    in Windows 10 Gaming
    Recommended way to fix vulnerabilities and CVE in Microsoft Windows Server 2019 Standard...: Hello Folks,I am using Microsoft Windows Server 2019 Standard Evaluation .Recently, scanned this server and found the following vulnerabilities:Critical count : 4High count : 5Medium count : 9But the catch here is that in each critical count vulnerability there are multiple...
  8. Recommended way to fix vulnerabilities and CVE in Microsoft Windows Server 2019 Standard...

    in Windows 10 Software and Apps
    Recommended way to fix vulnerabilities and CVE in Microsoft Windows Server 2019 Standard...: Hello Folks,I am using Microsoft Windows Server 2019 Standard Evaluation .Recently, scanned this server and found the following vulnerabilities:Critical count : 4High count : 5Medium count : 9But the catch here is that in each critical count vulnerability there are multiple...
  9. Vulnerability CVE-2021-36934

    in Windows 10 BSOD Crashes and Debugging
    Vulnerability CVE-2021-36934: I saw in the press that an additional vulnerability of Windows 10, known as CVE-2021-36934, can be remedied at list until a Microsoft patch is available by running as administrator Win 10 Powershell and then typing: icacls $env:windir\system32\config\*.*...
  10. CVE-2020-0601 Windows CryptoAPI Spoofing Vulnerability Security Vulnerability Published:...

    in Windows 10 Installation and Upgrade
    CVE-2020-0601 Windows CryptoAPI Spoofing Vulnerability Security Vulnerability Published:...: Having Windows 10 for some time now, I'm sure along with others, Microsoft continues seemingly monthly, at minimum to post update WARNINGS. WHY is such a company continually putting out updates for their customers with Windows 10 when they themselves don't take the proper...