Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

RSS FEEDS

High-Severity Vulnerabilities in vRealize Operations VMware

Monday, 30 August, 2021
VMware has released security patches to address a series of vulnerabilities in vRealize Operations, including four categorized as high severity. The most severe flaw is a broken access control 
vulnerability (CVE-2021-22025), which could allow an attacker to gain unauthenticated API access when successfully exploited.
 
 

Description

CVE

Cosmos DB Vulnerability in Microsoft Azure cloud

Monday, 30 August, 2021

A flaw in Microsoft’s Azure Cosmos DB database product left more than 3,300 Azure customers open to complete unrestricted access by attackers. The vulnerability was introduced in 2019 when Microsoft added a data visualization feature called Jupyter Notebook to Cosmos DB. The feature was turned on by default for all Cosmos DBs in February 2021.

The flaw was detected in a visualization tool called Jupyter Notebook, and has been available for years. This flaw was enabled by default in Cosmos starting in February.

Windows Print Spooler Remote Code Execution Vulnerability

Sunday, 15 August, 2021

CVE-2021-36958 is a remote code execution vulnerability exists when the Windows Print Spooler service improperly performs privileged file operations.

An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

Microsoft has not yet released patches to address this vulnerabilities.  Please refer the Recommendation section for information on how to protect system from this vulnerability.

Microsoft August 2021 Updates Fixes Critical and Zero-Day Vulnerabilities Actively Exploited

Thursday, 12 August, 2021

Microsoft has released patches for 44 vulnerabilities, with 7 classified as Critical and 37 as Important, including 3 Zero-days with one actively exploited in the wild.

The fix for three zero-day vulnerabilities include:

CVE-2021-36948 Windows Update Medic Service Elevation of Privilege Vulnerability

CVE-2021-36942 Windows LSA Spoofing Vulnerability

CVE-2021-36936 Windows Print Spooler Remote Code Execution Vulnerability

 

Multiple Routinely Exploited Vulnerabilities in Windows and Pulse Connect Secure

Monday, 2 August, 2021

Advisory coauthored by The U.S. Cybersecurity and Infrastructure Security Agency (CISA), the Australian Cyber Security Centre (ACSC), the United Kingdom’s National Cyber Security Centre (NCSC), and the U.S. Federal Bureau of Investigation (FBI) on the top 30 vulnerabilities—primarily Common Vulnerabilities and Exposures (CVEs)—routinely exploited by malicious cyber actors in 2020 and those being widely exploited thus far in 2021.

 

Windows Vulnerability "SeriousSAM" Exploited in the Wild

Monday, 26 July, 2021

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Account Manager (SAM) database.

 

An attacker could exploit this vulnerability (CVE-2021-36934) to gain elevated privileges. An attacker with low level privileges would need to take advantage of the incorrect permissions set on the SYSTEM and SAM hives.

 

Google Chrome Zero-Day Vulnerability Exploited in the Wild

Sunday, 18 July, 2021
Vulnerability related to Google Chrome has been exploited in a wild, threat actors have used both the Chrome and Windows exploits to gain a foothold in the targeted system, the stager module downloads and executes a more complex malware dropper from a remote server, We already had shared Windows related vulnerabilities in Microsoft July Update Fixes Multiple Zero-Days Exploited
 
Both  CVE-2021-21166 and CVE-2021-30551

Windows Print Spooler "PrintNightmare" Exploit

Thursday, 1 July, 2021
The vulnerability "PrintNightmare" CVE-2021-1675 affects the majority of the Windows operating systems including the latest server OS and desktop OS versions. A poof of concept (PoC) code is publicly available, however we have not observed active exploitations in the wild. The vulnerbability is High-risk due to the potential for Remote Code Execution (RCE) and utlize arbitrary code execution offset by the user interaction required.

Intel Security Updates for Multiple Products

Thursday, 10 June, 2021

Intel has released 29 advisories on the 8th of June to patch multiple products that addresses 73 vulnerabilities, of which 23 are high severity. Please follow the recommendation bellow to mitigate the vulnerabilities.

 

Among these security patches, Intel has addressed vulnerabilities related to local privilege escalations in the Intel Processor Firmware and network privilege escalation in Intel Security Library.

Microsoft June Update Fixes Multiple Zero-Days Exploited in the Wild

Wednesday, 9 June, 2021

Microsoft has released its June 2021 security update with 55 critical and important vulnerabilities in multiple products. A threat actor PuzzleMaker has been exploiting both CVE-2021-31955 and CVE-2021-31956 while utilizing unpatched Chrome (CVE-2021-21220).

 

 Six zero-day vulnerabilities are being actively exploited:

Subscribe to RSS FEEDS