s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

CVE-1999-1137 low

📛 Threat Title

CVE-1999-1137

Category: vulnerability Published: Source updated: First seen: Last updated: Source: NVD Recent CVEs

Description

The permissions for the /dev/audio device on Solaris 2.2 and earlier, and SunOS 4.1.x, allow any local user to read from the device, which could be used by an attacker to monitor conversations happening near a machine that has a microphone.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (5)

Remediations (10)

  • web:attack.mitre.org

    This mitigation can be implemented through the following measures: Regular Operating System Updates Implementation: Apply the latest Windows security updates monthly using WSUS (Windows Server Update Services) or a similar patch management solution. Configure systems to check for updates automatically and schedule reboots during maintenance ...

  • web:blog.qualys.com

    Key Takeaways RedSun is a critical zero-day vulnerability in Microsoft Defender that allows low-privileged users to gain SYSTEM access No patch is currently available, leaving all Defender-enabled Windows systems potentially exposed Qualys VMDR detects affected assets instantly (QID 92382) TruRisk™ Eliminate enables immediate mitigation , removing exploitability without waiting for a fix ...

  • web:cybersecuritynews.com

    Microsoft released an out-of-band hotpatch update on March 13, 2026, addressing serious security vulnerabilities in Windows 11 versions 24H2 and 25H2.

  • web:nvd.nist.gov

    Vulnerabilities All vulnerabilities in the NVD have been assigned a CVE identifier and thus, abide by the definition below. CVE defines a vulnerability as: "A weakness in the computational logic (e.g., code) found in software and hardware components that, when exploited, results in a negative impact to confidentiality, integrity, or availability. Mitigation of the vulnerabilities in this ...

  • web:portal.msrc.microsoft.com

    The Security Update Guide provides information on the latest Microsoft security updates, helping users understand and address potential vulnerabilities effectively.

  • web:translate.google.com

    Google's service, offered free of charge, instantly translates words, phrases, and web pages between English and over 100 other languages.

  • web:web.whatsapp.com

    Log in to WhatsApp Web for simple, reliable and private messaging on your desktop. Send and receive messages and files with ease, all for free.

  • web:www.cisa.gov

    Updated October 29, 2025: CISA has updated this Alert to include revised information on vulnerable product identification, potential threat activity detections, and additional resources. Microsoft released an update to address a critical remote code execution vulnerability impacting Windows Server Update Service (WSUS) in Windows Server (2012, 2016, 2019, 2022, and 2025), CVE -2025-59287

  • web:www.digitaltrends.com

    Microsoft has released another emergency Windows 11 update after a January patch triggered widespread app crashes, Outlook failures, and cloud sync issues, forcing the company into rare back to ...

  • web:www.zdnet.com

    ZDNET Microsoft's Patch Tuesday rollout for February is a big one, not simply in size but in scope. Rolled out on February 11, the latest updates not only add a few new features but squash several ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.