πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2021-34579 β€Ό

In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web server can download and therefore read mGuard configuration profiles (Ò€œATV profilesҀ�). Such configuration profiles may contain sensitive information, e.g. private keys associated with IPsec VPN connections.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0031 β€Ό

A local privilege escalation (PE) vulnerability in the Palo Alto Networks Cortex XSOAR engine software running on a Linux operating system allows a local attacker with shell access to the engine to execute programs with elevated privileges.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-25932 β€Ό

The firmware of InHand Networks InRouter302 V3.5.45 introduces fixes for TALOS-2022-1472 and TALOS-2022-1474. The fixes are incomplete. An attacker can still perform, respectively, a privilege escalation and an information disclosure vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41055 β€Ό

Windows Human Interface Device Information Disclosure Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26392 β€Ό

Insufficient verification of missing size check in 'LoadModule' may lead to an out-of-bounds write potentially allowing an attacker with privileges to gain code execution of the OS/kernel by loading a malicious TA.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-46852 β€Ό

The memory management module has the logic bypass vulnerability. Successful exploitation of this vulnerability may affect data confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26393 β€Ό

Insufficient memory cleanup in the AMD Secure Processor (ASP) Trusted Execution Environment (TEE) may allow an authenticated attacker with privileges to generate a valid signed TA and potentially poison the contents of the process memory with attacker controlled data resulting in a loss of confidentiality.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41116 β€Ό

Windows Point-to-Point Tunneling Protocol Denial of Service Vulnerability. This CVE ID is unique from CVE-2022-41090.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41064 β€Ό

.NET Framework Information Disclosure Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41060 β€Ό

Microsoft Word Information Disclosure Vulnerability. This CVE ID is unique from CVE-2022-41103.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41105 β€Ό

Microsoft Excel Information Disclosure Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2020-12930 β€Ό

Improper parameters handling in AMD Secure Processor (ASP) drivers may allow a privileged attacker to elevate their privileges potentially leading to loss of integrity.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38023 β€Ό

Netlogon RPC Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41114 β€Ό

Windows Bind Filter Driver Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31687 β€Ό

VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-26360 β€Ό

An attacker with local access to the system can make unauthorized modifications of the security configuration of the SOC registers. This could allow potential corruption of AMD secure processorÒ€ℒs encrypted memory contents which may lead to arbitrary code execution in ASP.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-31688 β€Ό

VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41054 β€Ό

Windows Resilient File System (ReFS) Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-39879 β€Ό

Improper authorization vulnerability in?CallBGProvider prior to SMR Nov-2022 Release 1 allows local attacker to grant permission for accessing information with phone uid.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-41048 β€Ό

Microsoft ODBC Driver Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2022-41047.

πŸ“– Read

via "National Vulnerability Database".
πŸ‘1
β€Ό CVE-2022-41085 β€Ό

Azure CycleCloud Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".