Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

RSS FEEDS

Critical Vulnerability in VMWARE Cloud Foundation

Monday, 31 October, 2022

A significant remote code execution vulnerability is present in VMware Cloud Foundation Network Security Virtualization for vSphere (NSX-V) via the XStream open source library. Public exploit code has been made available for this issue, which is currently being used. The vulnerability is identified as CVE-2021-39144.Targeting an unauthenticated endpoint in NSX-V would allow an attacker to take advantage of this vulnerability and get root-level access to remote code execution.

 

Actively Exploited Vulnerability in Google Chrome

Monday, 31 October, 2022

Google has released emergency update to fix the actively exploited zero-day vulnerability in its Chrome web browser. The exploited vulnerability is tracked as CVE-2022-3723 and described as a type confusion flaw in the V8 JavaScript engine.

 

On the successful exploitation of the vulnerability, attacker can execute arbitrary code, install programs, view, change, or delete data; with other malicious activities.

 

 

Multiple Vulnerabilities in Google Chrome

Thursday, 27 October, 2022

Google this week announced the release of Chrome 107 to the stable channel, with patches for 14 vulnerabilities, including high – severity issues among which ten security issues were reported externally: three was reported as high – severity, six medium – severity, and one low – severity issue.

To exploit these flaws, a remote attacker needs to trick a user into accessing a specially crafted webpage in a vulnerable browser. Successful exploitation could allow the attacker to execute arbitrary code or cause a denial-of-service (DoS) condition on the affected system.

Remote Code Vulnerability in Zoom Applications

Thursday, 27 October, 2022

A High severity Remote Code Execution vulnerability has been identified in Zoom applications.

The vulnerability is related to Improper URL parsing. An attacker could send malicious Zoom meeting URL which may redirect the user to connect to an arbitrary network and do lateral movements for remote code execution through launching executables from arbitrary paths.

 

 

CVE/Vulnerability

Description

Vulnerabilities in Adobe Illustrator

Wednesday, 26 October, 2022

Updates released by Adobe for its Illustrator product patch two vulnerabilities that could lead to arbitrary code execution. According to Adobe, Illustrator 2021 and 2022 for Windows and macOS are affected by improper input validation and outof-bounds read vulnerabilities that could lead to malicious code execution.

 

 

 

CVE/Vulnerability

Description

Multiple Vulnerability in Apple iOS, iPadOS & macOS

Wednesday, 26 October, 2022

Apple has released security update to address Zero-Day flaw in iOS and iPadOS which has been actively exploited in the wild.

 

The vulnerability is identified as Out-of-bounds write issue in the kernel, which could be abused by rouge application to execute arbitrary code with the highest privileges.

 

Successfully exploitation of vulnerability could allow potential attackers to execute arbitrary code with kernel privileges, which can result in data corruption, application crashes, or code execution.

 

 

Multiple Exploitable Vulnerabilities Affecting Veeam Backup and Replication

Wednesday, 26 October, 2022

CloudSEK has discovered several critical and high – severity vulnerabilities affecting Veeam Backup & Replication which allow executing malicious code remotely without authentication.

 

Threat actors are actively advertising a fully weaponized tool for remote code execution to exploit these vulnerabilities.

 

 

CVE/Vulnerability

Description

CVSS 3.0 Base Score

Multiple Exploited Vulnerabilities in Oracle Linux

Monday, 24 October, 2022

Oracle Linux have released security patches which addressed multiple vulnerabilities in their various components. Advisory contains 89 patches out this 43 are remotely exploitable without any authentication. Attackers might could take advantage of these vulnerabilities for exploitation which could lead to remote code execution and lateral movements which could have an adversely impact on confidentiality, integrity of data and reputational loss.

 

Vulnerabilities in Cisco Identity Services Engine

Sunday, 23 October, 2022

Cisco alert, admins of Cisco Identity Services Engine solutions, about two vulnerabilities that could be exploited to read and delete files on an affected device and to execute arbitrary script or access sensitive information.

 

CVE-2022-20822 is a path traversal vulnerability in the web – based management interface of Cisco ISE that could be exploited by an authenticated, remote attacker.

 

PAN-OS - Authentication Bypass in Web

Monday, 17 October, 2022

Palo Alto Networks notifies about a high-severity authentication bypass vulnerability affecting the web interface of its PAN-OS 8.1 software. 

 

The security hole is tracked as CVE-2022-0030, According to the company, a network-based attacker with specific knowledge of the targeted firewall or Panorama appliance can impersonate an existing PAN-OS admin and perform privileged actions.

 

SAP Security Patch - October 2022

Sunday, 16 October, 2022

SAP released 15 new security notes on its October 2022 Security Patch Day, including two ‘hot news’ notes dealing with critical vulnerabilities. 

 

The most severe of these issues is CVE-2022-39802 (CVSS score of 9.9), which is described as a file path traversal in Manufacturing Execution. The bug impacts Work Instruction Viewer and Visual Test and Repair, two plugins for displaying work instructions and models.

 

Multiple Vulnerabilities in Adobe

Thursday, 13 October, 2022

Adobe has rolled out numerous security fixes addressing around seven adobe products. The roll out has targeted products which are Experience Manager, Adobe Bridge, Adobe InDesign, Adobe Photoshop, Adobe InCopy, Adobe Animate, Adobe Illustrator. 

 

These updates address critical and important vulnerabilities that could lead to arbitrary code execution and memory leak. 

 

  

CVE/Vulnerability

Microsoft Patch Tuesday- October 2022

Thursday, 13 October, 2022

Microsoft release patched for 84 CVEs, with 13 rated as critical and 71 rated as important.

 

The actively exploited zero-day vulnerability fixed today is tracked as “CVE-2022-41033” which is related to Windows COM+ Event System Service Elevation of Privilege. An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

 

Microsoft Patch Tuesday - September 2022

Tuesday, 20 September, 2022

Microsoft has released patches for 64 vulnerabilities with five (05) classified as critical among one is zero day which is exploitable.

 

 

September 2022 patch is addressing vulnerabilities in Microsoft windows and its component, Azure, .NET and .NET Framework, Microsoft Edge (Chromium based), MS Office and Windows Defender.

 

In September 2022 Microsoft has fixed problems of Privilege Elevation, Remote Code Execution and Denial of Service.

 

Privilege escalation in HP Support Assistant

Monday, 19 September, 2022

A new vulnerability has been identified and exploited in HP support assistance, a software tool that comes pre-installed on all HP devices.

 

Attacker can exploit this vulnerability by using the RAT tool and elevate their privileges by using DLL hijacking flaw on vulnerable systems and it triggers when user attempt to launch HP performance Tuneup from within HP support assistant.

 

 

CVE/Vulnerability

Description 

Subscribe to RSS FEEDS