πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.9K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-25237 β€Ό

An improper access control vulnerability in Trend Micro Apex One (on-prem) could allow an unauthenticated user to obtain information about the managing port used by agents.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0350 β€Ό

In ged, there is a possible system crash due to an improper input validation. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05342338.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0343 β€Ό

In kisd, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05449962.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25244 β€Ό

An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of configuration informaiton.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25227 β€Ό

Trend Micro Antivirus for Mac 2021 (Consumer) is vulnerable to a memory exhaustion vulnerability that could lead to disabling all the scanning functionality within the application. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability Γ’β‚¬β€œ i.e. the attacker must already have access to the target system (either legitimately or via another exploit).

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25241 β€Ό

A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a sweep.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25240 β€Ό

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain x64 agent hofitx information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25233 β€Ό

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific configuration download file.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0344 β€Ό

In mtkpower, there is a possible memory corruption due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05437558.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25229 β€Ό

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the database server.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0346 β€Ό

In vpu, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05371580.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25248 β€Ό

An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25246 β€Ό

An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0348 β€Ό

In vpu, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05349201.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25245 β€Ό

An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various pieces of settings informaiton.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25243 β€Ό

An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25236 β€Ό

A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-25239 β€Ό

An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-0345 β€Ό

In mobile_log_d, there is a possible escalation of privilege due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android; Versions: Android-11; Patch ID: ALPS05432974.

πŸ“– Read

via "National Vulnerability Database".
❌ Android Devices Prone to Botnet’s DDoS Onslaught ❌

A new DDoS botnet propagates via the Android Debug Bridge and uses Tor to hide its activity.

πŸ“– Read

via "Threat Post".
πŸ•΄ Microsoft Says It's Time to Attack Your Machine-Learning Models πŸ•΄

With access to some training data, Microsoft's red team recreated a machine-learning system and found sequences of requests that resulted in a denial-of-service.

πŸ“– Read

via "Dark Reading".