Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

RSS FEEDS

Actively Exploited Vulnerability in Google Chrome

Sunday, 4 September, 2022

Google has released Chrome version 105.0.5195.102 for Mac, Linux and Windows. This update has been released to addresses the zero-day vulnerability that is exploited in the wild. The exploited vulnerability is tracked as CVE-2022-3075.

 

On the successful exploitation of this vulnerability, attacker can execute arbitrary code, install programs, view, change, or delete data; or create new accounts with full user rights.

 

CVE/Vulnerability

Exploited vulnerability in SAP Products

Thursday, 25 August, 2022

SAP has released patch to address the ‘request smuggling and request concatenation vulnerability’ in its multiple products. 

 

Any arbitrary data can be prepended to a victim's request by an unauthenticated attacker. By doing this, the attacker can run scripts pretending to be the victim or compromise intermediary web caches.

 

 A successful attack could result in a total breach of the system's availability, confidentiality, and integrity.

 

CISA and other researcher has confirmed exploitation this vulnerability in wild. 

 

Microsoft Patch Tuesday-August 2022

Thursday, 25 August, 2022

Microsoft has released patches for 121 vulnerabilities with seventeen (17) classified as critical, one hundred two (102) are classified as important, one moderate, and one Low. In this updates, Microsoft addressed the two zero-day vulnerabilities with one widely exploited. The actively exploited zero-day vulnerability is known as ‘DogWalk' and assigned CVE-2022-34713. The other zero-day vulnerability is tracked as 'CVE-2022-30134–Microsoft Exchange Information Disclosure Vulnerability', enables an attacker to read certain emails. Other than this, there is no known exploit.

 

Multiple Critical Vulnerabilities in Adobe Products-Aug 2022

Wednesday, 24 August, 2022

Adobe has issued security update for August 2022, which address multiple critical and important vulnerabilities in its products.  It appears that none of Adobe's bugs fixed in this month are publicly known or under active attack. 

 

Adobe products that are patched in this month security update includes- Adobe Commerce, Adobe Acrobat and Reader, Adobe Illustrator, Adobe Frame maker, and Adobe Premiere Elements. 

 

Adobe has fixed problem of - arbitrary code execution, privilege escalation, security feature bypass, and memory leak.

 

Actively Exploited Vulnerability in Google Chrome

Tuesday, 23 August, 2022

Google has released Chrome version 104.0.5112.101 for Mac, Linux and 104.0.5112.102/101 for Windows. This update addresses 11 security flaws with one zero-day that is exploited in the wild. The exploited vulnerability is tracked as CVE-2022-2856.

 

With this release, a number of fixes and improvements have been made. On the successful exploitation of these vulnerabilities, attacker can execute arbitrary code, install programs, view, change, or delete data; or create new accounts with full user rights.

 

Exploited vulnerabilities in Apple iOS, iPadOS and macOS

Tuesday, 23 August, 2022

Apple has released security updates for iPhones, iPads and Macs to fix the two code execution vulnerabilities that could allow attackers to covertly take control of devices.

 

The vulnerability CVE-2022-32893 may lead to arbitrary code execution by processing maliciously crafted web content. This vulnerability could be exploited by an attacker to gain access to a susceptible system by tricking a potential victim into visiting a specially designed malicious website.

 

Critical Vulnerabilities in VMware Products

Thursday, 4 August, 2022

VMware has released security update in multiple products including VMware Workspace ONE Access, VMware Identity Manager, VMware vRealize Automation, VMware Cloud Foundation, and vRealize Suite Lifecycle Manager to address the multiple critical and important vulnerabilities. 

 

Vulnerability CVE-2022-31656 is highly susceptible for exploitation.

 

For these various products, a remote attacker with access to the corresponding user interface might get administrator access without authentication if manage to exploit the vulnerability (CVE-2022-31656). 

 

Microsoft Patch Tuesday- July 2022

Tuesday, 19 July, 2022

Microsoft has released patches for 84 CVEs in its July 2022 Patch Tuesday with four rated as critical, 79 rated as important and one rated as unknown.

 

According to Microsoft CVE-2022-22047, an elevation of privilege vulnerability is been actively exploited by the attackers. Microsoft describe this as Windows Client Server Run-Time Subsystem (CSRSS) elevation of privilege. The flaw was assigned a CVSSv3 score of 7.8.

 

Please refer to “REFERENCES” to explore more about vulnerabilities included in “Table 1: Vulnerability details”.

 

Unauthenticated Remote Code Execution Vulnerability in ManageEngine ADAudit Plus

Sunday, 3 July, 2022
A remote code execution (RCE) vulnerability is discovered in Manage Engine ADAudit Plus. ADAudit Plus is a Windows auditing, security and compliance solution from Zoho used by large enterprises to monitor changes, real time risk alerting and compliance reporting for the Active Directory (AD) environment.
 
Due to a serious flaw identified as CVE-2022-28219, attackers are able to access domain administrator accounts and steal confidential information.

Multiple Critical Vulnerabilities in Adobe Products-June 2022

Tuesday, 21 June, 2022

Adobe has issued security update for June 2022, which address multiple critical and important vulnerabilities in its products. It appears that none of Adobe's bugs fixed in this month are publicly known or under active attack. Adobe products that are patched in this month security update includes- Adobe Animate, Adobe Bridge, Adobe Illustrator, Adobe InCopy, Adobe InDesign, and RoboHelp Server. Adobe has fixed problem of Out-of-bounds Read, Out-of-bounds Write, Improper Input Validation, Use After Free, Heap-based Buffer Overflow, and Improper Authorization.

Vulnerability in Citrix Application Delivery Management

Tuesday, 21 June, 2022

There have been multiple security vulnerabilities found in Citrix ADM. Citrix ADM is a web-based management tool for Citrix implementations. An unauthenticated attacker might reset the administrator password using the most serious of these flaws. The vulnerability, CVE-2022-27511 could allow a remote, unauthenticated user to take control of the system. This could result in the administrator password being reset on the next device reboot, allowing an attacker with SSH access to logon to the device using the default administrator credentials after it has rebooted.

Microsoft Patch Tuesday-June 2022

Wednesday, 15 June, 2022

Microsoft has released patches for 55 vulnerabilities with three classified as critical, one moderate, and rest are classified as important.  In this updates, Microsoft addressed the widely exploited Windows Follina MSDT zero-day vulnerability (CVE-2022-30190) made public in May 22. Other than this, there is no known exploit. 

 

In June 2022 Microsoft has fixed problems of Privilege Elevation, Security Feature Bypass, Remote Code Execution, Information Disclosure, Denial of Service, Out-of-bounds memory access and Spoofing Vulnerability.

 

Actively Exploited Vulnerability in Confluence Server and Data Center

Sunday, 5 June, 2022

A flaw in Atlassian Confluence Server and Data Centre has been uncovered, which might allow an unauthenticated user to run arbitrary code.

 

If this vulnerability is successfully exploited, remote code execution could be possible in the context of the account that runs the Confluence Server or Data Centre service. An attacker could see, alter, or remove data depending on the privileges associated with the account. 

 

This Vulnerability is tagged as CVE-2022-26134, and it is classified Critical.

 

Multiple Vulnerabilities in Firefox, Firefox ESR, and Thunderbird

Thursday, 2 June, 2022

Mozilla has released critical security updates for Firefox, Firefox ESR, and Thunderbird, addressing multiple vulnerabilities. Most severe of discovered vulnerabilities could allow remote code execution on successful exploitation. 

 

Other discovered vulnerabilities, may allow attacker to install applications, edit or delete data, or create new accounts with full user rights.

 

There are currently no report of exploitation of these vulnerabilities.

 

Exploited Vulnerability in Microsoft Support Diagnostic Tool (MSDT)

Wednesday, 1 June, 2022

Microsoft Support Diagnostic Tool (MSDT) has been found to have a vulnerability that might allow arbitrary code execution. MSDT gathers data from Windows and Windows Server hosts and sends it to Microsoft Support.

 

MSDT can be accessed via the URL protocol from a calling application such as Word, allowing an attacker to execute arbitrary code with the user's rights.

 

Critical Vulnerability in Oracle E-Business Suite

Wednesday, 25 May, 2022

Oracle has issued an out-of-band security alert advisory for Oracle E-Business Suite (EBS) to address a security vulnerability involving information exposure.

This vulnerability can be remotely exploited over network without requiring a username and password. If this flaw is effectively exploited, personally identifiable information could be exposed (PII) or complete access to all Oracle E-Business Suite accessible data.

 

Critical Vulnerabilities in VMware Products

Sunday, 22 May, 2022

VMware has released security update for- VMware Workspace ONE Access, VMware Identity Manager, VMware vRealize Automation, VMware Cloud Foundation, and vRealize Suite Lifecycle Manager to address the critical vulnerabilities. 

 

These vulnerabilities are highly susceptible for exploitation.

 

For these various products, a remote attacker with access to the corresponding user interface might get administrator access without authentication if manage to exploit vulnerability CVE-2022-22972. 

 

Subscribe to RSS FEEDS