Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

RSS FEEDS

Critical Vulnerabilities in Firefox, Firefox ESR, and Thunderbird

Sunday, 22 May, 2022

Mozilla has released critical security updates for Firefox, Firefox ESR, and Thunderbird, addressing critical vulnerabilities. Most severe of discovered vulnerabilities could allow remote code execution on successful exploitation. 

 

A remote attacker can persuade a victim to visit a specially constructed website, corrupt the methods of an Array object in JavaScript via prototype pollution, and run arbitrary JavaScript code in a privileged context, potentially allowing an attacker to compromise the system.

 

Multiple Critical Vulnerabilities in Adobe Products- May 2022

Tuesday, 17 May, 2022

Adobe has issued security update for May 2022, which address multiple critical and important vulnerabilities in its products.  It appears that none of Adobe's bugs fixed in this month are publicly known or under active attack. 

 

Adobe products that are patched in this month security update includes- FrameMaker document processor, the InCopy, InDesign suites, the Character Animator motion capture tool and the Adobe ColdFusion platform. 

 

Adobe has fixed problem of Out-of-bounds Write, Out-of-bounds Read, Use After Free and Cross-site Scripting.

 

Microsoft Patch Tuesday- May 2022

Tuesday, 17 May, 2022

Microsoft has released patches for 75 vulnerabilities with eight classified as critical including three zerodays and rest are classified as important. One of the zero-day vulnerability (CVE-2022-26925) have been actively exploited.  

 

In May 2022 Microsoft has fixed problems of Privilege Elevation, Security Feature Bypass, Remote Code Execution, Information Disclosure, Denial of Service and Spoofing Vulnerability.

 

Multiple Vulnerabilities in SonicWall SSLVPN SMA1000 Series

Tuesday, 17 May, 2022

SonicWall has published a patch for the SonicWall SMA 1000 Series to fix numerous vulnerabilities. An attacker could get unauthorized access to internal resources and potentially lead victims to malicious websites if the vulnerability is successfully exploited. 

 

 

CVE/Vulnerability

 Description 

Severity

CVE-2022-22282

Unauthenticated Access Control Bypass

Vulnerability in F5 Big IP under Attack

Sunday, 15 May, 2022

In the month of May 22, the F5 resolved a total of 43 vulnerabilities, the most serious of which is a critical vulnerability identified as CVE-2022-1388 (CVSS score of 9.8). Unauthenticated attackers with network access to the F5 BIG-IP system via the management port and/or self IP addresses can use the CVE-20221388 flaw to run arbitrary system commands, create or delete files, and disable services. In other words, the attacker can take complete control over the affected device. This weakness is being actively exploited.

 

Exploited Vulnerability in Apache Struts 2

Tuesday, 26 April, 2022

Apache Struts 2 is affected with a potential remote code execution vulnerability (CVE-2021-31805 OGNL Injection vulnerability), which has been disclosed and fixed by the Apache Software Foundation. The update was offered because the first patch, which was released in 2020, did not fully resolve the issue, according to an advisory S2-062 from Apache.

 

A remote attacker who exploits this flaw can run arbitrary code on the Apache Struts 2 server.

 

Oracle Critical Patch Updates (CPU) - Apr 2022

Thursday, 21 April, 2022

Oracle has released its Critical Patch Update (CPU) for the month of Apr 2022. This CPU contains 520 patches, fixes for 221 vulnerabilities including 77 critical patches, spanning 31 Oracle product families. 

 

Among the vulnerabilities addressed in this CPU, CVE-2022-22947 and CVE-2022-21431 are given highest CVSS3 scoring of 10. Both can be exploited without authentication through network access. Exploitation of CVE-2022-21431 could impact additional products. 

 

Zero-Day Vulnerability in Google Chrome

Sunday, 17 April, 2022

Google has released Chrome version 100.0.4896.127 to resolve a vulnerability for which a public exploit code already exists.  The security issue is described as a “Type Confusion bug” and is tagged as CVE-20221364. It is rated as high-severity.

 

The most common outcome of type confusion flaw is browser crashes when read or written memory does not match the bounds of the buffer. Attackers can also exploit the said vulnerability to execute arbitrary code. 

 

CVE/Vulnerability

Microsoft Patch Tuesday- Apr 2022

Thursday, 14 April, 2022

Microsoft has released patches for 128 vulnerabilities (excluding 26 Microsoft Edge vulnerabilities) with ten classified as critical including two zero-days and rest are classified as important. One of the zero-day vulnerability (CVE-2022-24521) has been actively exploited.  

 

In Apr 2022 Microsoft has fixed problems of Elevation of Privilege, Security Feature Bypass, Remote code execution (RCE), Information Disclosure, Denial of Service, and Spoofing Vulnerabilities.

 

Multiple Critical Vulnerabilities in Adobe Products- Apr 2022

Thursday, 14 April, 2022

Adobe has issued security update for Apr 2022, which address multiple critical, important and moderate vulnerabilities in its products.  It appears that none of Adobe's bugs fixed in this month are publicly known or under active attack. 

 

Adobe products that are patched in this month security update includes- Adobe Acrobat and Reader, Adobe Photoshop, Adobe After Effects and Adobe Commerce. 

 

Adobe has fixed problem of arbitrary code execution, memory leak, security feature bypass and privilege escalation.

 

Multiple Critical Vulnerability in VMware Products

Tuesday, 12 April, 2022

VMware has released security update for- VMware Workspace ONE Access, VMware Identity Manager, VMware vRealize Automation, VMware Cloud Foundation, vRealize Suite Lifecycle Manager, and VMware Horizon Client for Linux to address the multiple critical vulnerabilities.

 

These security flaws could result in a variety of negative effects, including remote code execution, authentication bypass, cross site request forgery, privilege escalation to root, and information disclosure.

 

RCE (Spring4Shell) Vulnerability in VMware Products

Thursday, 7 April, 2022

Security updates have been released for the Spring4Shell remote code execution vulnerability, which affects several VMware cloud computing and virtualization products. This problem is caused by a critical vulnerability in the Spring Core Java framework, tracked as CVE-2022-22965.

 

Vulnerability is publicly disclosed, actively exploited, and can be used to attack affected products without authentication. 

 

Multiple Vulnerabilities in Firefox, Firefox ESR, and Thunderbird

Thursday, 7 April, 2022

Mozilla has released critical security updates for Firefox, Firefox ESR, and Thunderbird, addressing multiple vulnerabilities. Most severe of discovered vulnerabilities could allow remote code execution on successful exploitation. 

 

Other discovered vulnerabilities, may allow attacker to install applications, edit or delete data, or create new accounts with full user rights.

 

CVE/Vulnerability

               Description 

Multiple Vulnerabilities in Apple iOS, iPad OS and macOS

Sunday, 3 April, 2022

Apple has released iOS 15.4.1, iPad OS 15.4.1 and macOS Monterey 12.3.1. This release address an outof-bounds write and an out-of-bounds read issue. In this version, enhanced bounds checking and improved input validation are used to fix both of the previously described concerns.

 

Out-of-bounds write issues might allow an application to run arbitrary code with kernel privileges, while out-of-bounds read issues could expose kernel memory.

 

 According to Apple, this vulnerability may have been actively exploited.

 

Google has Published Chrome Version 100

Thursday, 31 March, 2022

Google has released Chrome version 100.0.4896.60. Which, among other things, addresses 28 security flaws. None of the 28 vulnerabilities have been classified as critical, although nine have been classified as having a high severity.

 

With this release, a number of fixes and improvements have been made, including the safety check, enhanced safe browsing, and the ability to control how websites access your location and device.

 

Critical Vulnerabilities in Adobe Products- March 2022

Thursday, 10 March, 2022

Adobe has issued security update for March 2022, which address critical and important vulnerabilities in its products. This month update is comparatively quite small in compare to last few months.

 

It appears that none of Adobe's bugs fixed this month are publicly known or under active attack. 

 

Products that are patched in this month security update includes- Adobe Photoshop, Adobe Illustrator 2022, and Adobe After Effects. 

Problem of memory leak and arbitrary code execution has been fixed in this month update.

 

Microsoft Patch Tuesday- March 2022

Thursday, 10 March, 2022

Microsoft has released patches for 71 vulnerabilities (excluding 21 Microsoft Edge vulnerabilities) with three classified as critical and rest sixty eight are classified as important including three zero-days. Fortunately, none of these (zero-days) vulnerabilities have been actively exploited. Though, public exploit code for two of them (CVE-2022-21990 and CVE-2022-24459) is available.

 

Multiple Security Vulnerabilities in VMware Products

Thursday, 17 February, 2022

VMware has released a critical security update for its ESXi, Fusion, Workstation products, and VMware Cloud Foundation versions to address the multiple vulnerabilities. Attackers could gain access to workloads inside virtual environments by exploiting the vulnerability.

 

These security flaws could result in a variety of negative effects, including command execution, escalate privilege, misuse the service settingsd as a high-privileged user and denial-of-service attacks.

 

Actively exploited zero-day vulnerability in Google Chrome

Wednesday, 16 February, 2022

A Google Chrome update has been released that includes eleven security fixes, one of which has reportedly been exploited in the wild.

 

Actively exploited vulnerability has been assigned the number CVE-2022-0609, as a use-after-free flaw in Chrome's Animation component. This type of issue can cause a wide range of problems, from data corruption to arbitrary code execution on affected computers. The browser's security sandbox can likewise be bypassed using such weaknesses.

 

Subscribe to RSS FEEDS