Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

RSS FEEDS

Critical Vulnerability in Adobe Commerce and Magento

Tuesday, 15 February, 2022

Adobe Commerce and Magento Open Source have both received security patches from Adobe. These updates fix a critical vulnerability identified as CVE-2022-24086. The successful exploitation could result in the execution of arbitrary code. According to Adobe, the flaw can be exploited without requiring authentication.

 

According to the vendor, the vulnerability has been exploited in the wild in a small number of attacks aimed against Adobe Commerce merchants.

 

Adobe Commerce 2.3.3 and lower are not affected.

 

A Zero Day Vulnerabilities in Apple iOS, iPadOS and macOS

Monday, 14 February, 2022

An urgent update has been released by Apple for iOS, iPadOS and macOS Monterey to patch a zero-day vulnerability.

  

The vulnerability has been tracked as CVE-2022-22620. Upon processing malicious web content on affected devices, attackers can execute arbitrary code.

 

As per Apple and other security researcher, there is high possibility of active exploitation of this vulnerability by threat actors.

 

CVE/Vulnerability

Description 

Multiple Critical Vulnerabilities in Adobe Products- Feb 2022

Thursday, 10 February, 2022

Adobe has issued security update for Feb 2022, which address multiple critical, important and moderate vulnerabilities in its products.  

 

Adobe products that are patched in this month security update includes- Adobe Premiere Rush, Illustrator, Photoshop, Adobe After Effects, and Creative Cloud Desktop Application.

 

Adobe has fixed problem of denial-of-service (DoS), arbitrary code execution, privilege escalation, and memory leaks.

 

CVE/Vulnerability

Google Chrome rolls out critical security update-Feb 2022

Sunday, 6 February, 2022

Google has released Chrome 98.0.4758.80/81/82 for windows and  98.0.4758.80 for mac and linux contains a number of fixes and improvements. This security update fixes 27 vulnerabilities, eight of which are rated as high risk and ten as medium. An attacker could exploit some of these vulnerabilities in order to execute arbitrary code on the target system with the same privileges that Chrome has.

 

CVE-2022-0452 and CVE-2022-0453 are two use-after-free vulnerabilities that affect safe browsing and reader mode, respectively.

 

Critical Vulnerability Found in WordPress Plugin for Elementor

Thursday, 3 February, 2022

There has been a discovery of a critical vulnerability in a WordPress plugin with over one million installations that could lead to the execution of arbitrary code on a compromised website.

 

The plugin is known as Essential Add-ons for “Elementor”, the plugin gives WordPress site owner/admin access to over 80 elements and extensions to design and customize pages and posts.

 

Remote Code Execution Vulnerability in SAMBA

Wednesday, 2 February, 2022

The Samba has patched a critical heap read-write vulnerability that allow remote attackers to execute arbitrary code as root on affected installations of Samba that use the VFS module vfs_fruit.

 

In vfs_fruit, the issue is caused by the default configuration of the fruit VFS module using fruit:metadata=netatalk or fruit:resource=file. When both options are set to a setting other than default values, the issue does not occur with the vfs_fruit module. In Samba server daemon (smbd), the flaw exists within the parsing of EA metadata during file opening.

 

Input Validation Vulnerability in SolarWinds Serv-U (CVE- 2021-35247)

Monday, 24 January, 2022

There is a new Serv-U vulnerability found by Microsoft, related to attacks being propagated via a previously undisclosed vulnerability in the SolarWinds Serv-U software. The vulnerability tracked as CVE2021-35247 is an input validation vulnerability that could allow attackers to build a query based on given input, and send it over the network without sanitation.

 

Serv-U, users can be authenticated against an internal LDAP server, such as a Windows domain controller or OpenLDAP serve.

 

Multiple Critical Vulnerabilities in Oracle Products- Jan 2022

Sunday, 23 January, 2022

Oracle has released its Critical Patch Update (CPU) for the month of January 2022. This CPU contains fixes for 266 CVEs in 497 security updates spanning 39 Oracle product families. 

 

Among the vulnerabilities addressed in this CPU, more than half can be remotely exploited without authentication. Additionally, it addresses CVE-2021-44228 and CVE-2021-45046 (an Apache Log4j related vulnerability) across multiple products. In various Oracle products, this update mitigates critical, high, medium and low severity vulnerabilities. 

 

An authentication bypass vulnerability (CVE-2021-44757) in ManageEngine Desktop Central

Wednesday, 19 January, 2022

The Desktop Central and Desktop Central MSP platforms of Zoho ManageEngine are affected by a new security flaw, tracked as CVE-2021-44757. 

 

It is described as an authentication bypass vulnerability, which could allow an attacker to execute unauthorized actions on the affected platform. If exploited, it could allow an attacker to read unauthorized data or write arbitrary data on the server.  

 

This vulnerability has been fixed on January 17, 2022, and the mitigation is available in the latest versions of Desktop Central and Desktop Central MSP.

 

Multiple Critical Vulnerabilities in Adobe Products- Jan 2022

Thursday, 13 January, 2022

Adobe has issued security update for Jan 2022, which address multiple critical, important and moderate vulnerabilities in its products.  

 

Adobe products that are patched in this month security update includes- Adobe Acrobat Reader, Adobe Illustrator, Adobe Bridge, Adobe InCopy, and Adobe InDesign. 

 

Adobe has fixed problem of cross-site scripting (XSS), arbitrary code execution, application denial of service, security feature bypass, privilege escalation and memory leak.

 

Microsoft Patch Tuesday- Jan 2022

Wednesday, 12 January, 2022

Microsoft has released patches for 97 vulnerabilities with nine classified as critical, eighty eight classified as important including six zero-days. Fortunately, none of these (zero-days) vulnerabilities have been actively exploited. Though, public exploit code for two of them (CVE-2022-21919 and CVE-2022-21836) is available.

 

In Jan 2022 Microsoft has fixed problems of Privilege escalation, Remote Code Execution, Cross-site scripting (XSS), Security Feature Bypass, Information Disclosure, Denial of Service, and Spoofing Vulnerabilities. 

 

Remote Code Execution Vulnerability (CVE-2021-44832) Found in Apache Log4j

Thursday, 30 December, 2021

A new remote code execution (RCE) vulnerability has been discovered in Apache log4j 2.17.0, tracked as CVE-2021-44832, this vulnerability is rated "Moderate" in severity.

The vulnerability stems from the lack of additional controls on JDNI access in log4j2. By making use of JDBC Appender with a data source referencing a JNDI URI, an attacker with access to logging configuration file can build a malicious configuration which execute remote code on affected system. 

 

CVE/Vulnerability

Multiple Vulnerabilities in Apache Server

Tuesday, 28 December, 2021

A new version of Apache web server (2.4.52) has been released by The Apache Software Foundation to address the Critical and High vulnerabilities, one of which could lead to remote code execution.

 

It is possible to cause a buffer overflow when parsing multipart content in mod_lua of affected Apache HTTP Server via a carefully crafted request body (r:parsebody() called from Lua scripts) by exploiting vulnerability (CVE-2021-44790).

 

New Critical Vulnerability (CVE-2021-45105) found in Apache Log4j2

Monday, 27 December, 2021

A new vulnerability, identified as CVE-2021-45105 has been discovered in Apache Log4j 2. Its severity is critical in nature with high probability of being exploited by attacker. This issue lies in the “StrSubstitutor” class due to improper validation of user supplied data, which can lead to resource exhaustion.

 

A remote attacker can use this vulnerability to cause a denial-of-service attack on affected installations of Apache Log4j. Exploitation of this vulnerability does not require authentication.

 

 

Multiple Critical Vulnerabilities in Adobe Products- December 2021

Monday, 27 December, 2021

Adobe has issued security update for December 2021, which address 60 vulnerabilities in 11 products, with 28 classified as Critical.  

 

Some notable products that are patched in December security update includes- Adobe Audition, Lightroom, Media Encoder, Premiere Pro, Prelude, Dimension, After Effects, Photoshop, Connect, Experience Manager, and Premiere Rush. 

 

Adobe has fixed problem of cross-site scripting (XSS), arbitrary code execution, remote code execution, and privilege escalation. 

 

 

 

Microsoft Patch Tuesday- December 2021

Thursday, 16 December, 2021

 

Microsoft has released patches for 67 vulnerabilities with seven classified as critical, sixty classified as important including a Zero-day being actively exploited in the wild. Zero-day vulnerability (CVE-202143890) was exploited in the wild to spread Emotet, Trickbot, and other malware through fake applications.

 

In December 2021 Microsoft has fixed problems of Privilege escalation, Remote Code Execution, Denial of Service, and Spoofing Vulnerabilities. 

 

Google Chrome rolls out critical security update-December 2021

Thursday, 16 December, 2021

Google has released Chrome version 96.0.4664.110 for Windows, Mac, and Linux. This security update fixes five vulnerabilities, four of which are rated as high risk and one as critical. One of these vulnerability (CVE-2021-4102) is reportedly being exploited in the wild.

 

CVE-2021-4102 affects Chrome's JavaScript engine, allowing attackers to inject and execute malicious code on the targeted computer. The other four vulnerabilities fixed in this release are- CVE-2021-4098, CVE-2021-4099, CVE-2021-4100, and CVE-2021-4101.

 

Subscribe to RSS FEEDS