πŸ›‘ Cybersecurity & Privacy πŸ›‘ - News
25.8K subscribers
89.2K links
πŸ—ž The finest daily news on cybersecurity and privacy.

πŸ”” Daily releases.

πŸ’» Is your online life secure?

πŸ“© lalilolalo.dev@gmail.com
Download Telegram
β€Ό CVE-2023-21732 β€Ό

Microsoft ODBC Driver Remote Code Execution Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21776 β€Ό

Windows Kernel Information Disclosure Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21760 β€Ό

Windows Print Spooler Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21678, CVE-2023-21765.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21739 β€Ό

Windows Bluetooth Driver Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21771 β€Ό

Windows Local Session Manager (LSM) Elevation of Privilege Vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21735 β€Ό

Microsoft Office Remote Code Execution Vulnerability. This CVE ID is unique from CVE-2023-21734.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-38393 β€Ό

A denial of service vulnerability exists in the cfg_server cm_processConnDiagPktList opcode of Asus RT-AX82U 3.0.0.4.386_49674-ge182230 router's configuration service. A specially-crafted network packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-21730 β€Ό

Microsoft Cryptographic Services Elevation of Privilege Vulnerability. This CVE ID is unique from CVE-2023-21551, CVE-2023-21561.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-36441 β€Ό

An issue was discovered in Zebra Enterprise Home Screen 4.1.19. The Gboard used by different applications can be used to launch and use several other applications that are restricted by the admin.

πŸ“– Read

via "National Vulnerability Database".
⚠ Popular JWT cloud security library patches β€œremote” code execution hole ⚠

It's remotely triggerable, but attackers would already have pretty deep network access if they could "prime" your server for compromise.

πŸ“– Read

via "Naked Security".
πŸ‘Ž1
β™ŸοΈ Microsoft Patch Tuesday, January 2023 Edition β™ŸοΈ

Microsoft today released updates to fix nearly 100 security flaws in its Windows operating systems and other software. Highlights from the first Patch Tuesday of 2023 include a zero-day vulnerability in Windows, printer software flaws reported by the U.S. National Security Agency, and a critical Microsoft SharePoint Server bug that allows a remote, unauthenticated attacker to make an anonymous connection.

πŸ“– Read

via "Krebs on Security".
⚠ Microsoft Patch Tuesday: One 0-day; Win 7 and 8.1 get last-ever patches ⚠

Get 'em while they're hot. And get 'em for the very last time, if you still have Windows 7 or 8.1...

πŸ“– Read

via "Naked Security".
β€Ό CVE-2022-48252 β€Ό

The jokob-sk/Pi.Alert fork (before 22.12.20) of Pi.Alert allows Remote Code Execution via nmap_scan.php (scan parameter) OS Command Injection.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43391 β€Ό

A buffer overflow vulnerability in the parameter of the CGI program in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43393 β€Ό

An improper check for unusual or exceptional conditions in the HTTP request processing function of Zyxel GS1920-24v2 firmware prior to V4.70(ABMH.8)C0, which could allow an unauthenticated attacker to corrupt the contents of the memory and result in a denial-of-service (DoS) condition on a vulnerable device.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43392 β€Ό

A buffer overflow vulnerability in the parameter of web server in Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to cause denial-of-service (DoS) conditions by sending a crafted authorization request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-0553 β€Ό

There is no check to see if slot 0 is being uploaded from the device to the host. When using encrypted images this means the unencrypted firmware can be retrieved easily.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2021-3966 β€Ό

usb device bluetooth class includes a buffer overflow related to implementation of net_buf_add_mem.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22947 β€Ό

** DISPUTED ** Insecure folder permissions in the Windows installation path of Shibboleth Service Provider (SP) before 3.4.1 allow an unprivileged local attacker to escalate privileges to SYSTEM via DLL planting in the service executable's folder. This occurs because the installation goes under C:\opt (rather than C:\Program Files) by default. NOTE: the vendor disputes the significance of this report, stating that "We consider the ACLs a best effort thing" and "it was a documentation mistake."

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2022-43390 β€Ό

A command injection vulnerability in the CGI program of Zyxel NR7101 firmware prior to V1.15(ACCC.3)C0, which could allow an authenticated attacker to execute some OS commands on a vulnerable device by sending a crafted HTTP request.

πŸ“– Read

via "National Vulnerability Database".
β€Ό CVE-2023-22959 β€Ό

WebChess through 0.9.0 and 1.0.0.rc2 allows SQL injection: mainmenu.php, chess.php, and opponentspassword.php (txtFirstName, txtLastName).

πŸ“– Read

via "National Vulnerability Database".