Tag: remote-code-execution
-
SolarWinds patches critical RCE vulnerability in its Web Help Desk
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/solarwinds-patches-critical-rce-vulnerability-in-its-web-help-desk
-
Zero-Click Exploit Concerns Drive Urgent Patching of Windows TCP/IP Flaw
Security experts are ratcheting up the urgency for Windows admins to patch a wormable, pre-auth remote code execution vulnerability in the Windows TCP… First seen on securityweek.com Jump to article: www.securityweek.com/zero-click-exploit-concerns-drive-urgent-patching-of-windows-tcp-ip-flaw/
-
Critical RCE bug in SolarWinds Web Help Desk fixed (CVE-2024-28986)
SolarWinds has fixed a critical vulnerability (CVE-2024-28986) in its Web Help Desk (WHD) solution that may allow attackers to run commands on the hos… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/08/15/cve-2024-28986/
-
Microsoft urges customers to fix zero-click Windows RCE in the TCP/IP stack
Microsoft addressed a critical zero-click Windows remote code execution (RCE) in the TCP/IP stack that impacts all systems with IPv6 enabled. Microsof… First seen on securityaffairs.com Jump to article: securityaffairs.com/167117/hacking/windows-rce-tcp-ip.html
-
Zero-click Windows TCP/IP RCE impacts all systems with IPv6 enabled, patch now
Microsoft warned customers this Tuesday to patch a critical TCP/IP remote code execution (RCE) vulnerability with an increased likelihood of exploitat… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/zero-click-windows-tcp-ip-rce-impacts-all-systems-with-ipv6-enabled-patch-now/
-
SolarWinds addressed a critical RCE in all Web Help Desk versions
SolarWinds addressed a critical remote code execution vulnerability in its Web Help Desk solutionfor customer support. SolarWinds fixed a critical vul… First seen on securityaffairs.com Jump to article: securityaffairs.com/167031/security/solarwinds-addressed-rce-whd.html
-
CVE-2024-38063: An In-Depth Look at the Critical Remote Code Execution Vulnerability
In a recent security advisory, Microsoft disclosed a high-severity vulnerability identified as CVE-2024-38063. This critical Remote Code Execution (RC… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/cve-2024-38063-an-in-depth-look-at-the-critical-remote-code-execution-vulnerability/
-
SolarWinds Issues Hotfix for Critical Web Help Desk Vulnerability
SolarWinds has released a hotfix for a critical Java deserialization remote code execution vulnerability in Web Help Desk. The post SolarWinds Issues … First seen on securityweek.com Jump to article: www.securityweek.com/solarwinds-issues-hotfix-for-critical-web-help-desk-vulnerability/
-
SolarWinds fixes critical RCE bug affecting all Web Help Desk versions
A critical vulnerability in SolarWinds’ Web Help Desk solution for customer support could be exploited to achieve remote code execution, the American … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/solarwinds-fixes-critical-rce-bug-affecting-all-web-help-desk-versions/
-
New Zero-Day Flaw in Apache OFBiz ERP Allows Remote Code Execution
A new zero-day pre-authentication remote code execution vulnerability has been disclosed in the Apache OFBiz open-source enterprise resource planning … First seen on thehackernews.com Jump to article: thehackernews.com/2024/08/new-zero-day-flaw-in-apache-ofbiz-erp.html
-
0-Click Outlook RCE Vulnerability Triggered When Email is Clicked Technical Analysis
NetSPI discovered that Microsoft Outlook is vulnerable to authenticated remote code execution (CVE-2024-21378) due to improper validation of synchroni… First seen on gbhackers.com Jump to article: gbhackers.com/0-click-outlook-rce-vulnerability/
-
A FreeBSD flaw could allow remote code execution, patch it now!
FreeBSD Project maintainers addressed a high-severity flaw in OpenSSH that could allow remote code execution with elevated privileges. The maintainers… First seen on securityaffairs.com Jump to article: securityaffairs.com/166941/security/freebsd-openssh-flaw.html
-
RCE likely with exploitation of several now-addressed Google Quick Share bugs
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/rce-likely-with-exploitation-of-several-now-addressed-google-quick-share-bugs
-
FreeBSD releases new patch for regreSSHion-related RCE flaw
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/freebsd-releases-new-patch-for-regresshion-related-rce-flaw
-
RCE, privilege escalation likely with chained OpenVPN flaws
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/rce-privilege-escalation-likely-with-chained-openvpn-flaws
-
BlackHat 2024: Remote Code Execution-Angriff auf M365 Copilot per E-Mail
Nettes Thema zum Sonntag: Microsoft drückt ja seinen Copilot in Microsoft 365 auf die Anwenderschaft. Da kann jeder Mann und jede Frau etwas in AI mac… First seen on borncity.com Jump to article: www.borncity.com/blog/2024/08/11/blackhat-2024-remote-code-execution-angriff-auf-m365-copilot-per-e-mail/
-
Microsoft found OpenVPN bugs that can be chained to achieve RCE and LPE
Microsoft found four bugs in OpenVPN that could be chained to achieve remote code execution and local privilege escalation. During the Black Hat USA 2… First seen on securityaffairs.com Jump to article: securityaffairs.com/166912/hacking/openvpn-rce-lpe.html
-
Microsoft Warns of OpenVPN Vulnerabilities, Potential for Exploit Chains
The vulnerabilities, patched in OpenVPN 2.6.10, expose users on the Windows platform to remote code execution attacks. The post Microsoft Warns of Ope… First seen on securityweek.com Jump to article: www.securityweek.com/microsoft-warns-of-openvpn-vulnerabilities-potential-for-exploit-chains/
-
Several Vulnerabilities Found in Google’s Quick Share Data Transfer Utility
SafeBreach identified 10 vulnerabilities in Google Quick Share and devised a remote code execution chain targeting the file sharing utility for Window… First seen on securityweek.com Jump to article: www.securityweek.com/several-vulnerabilities-found-in-googles-quick-share-data-transfer-utility/
-
CVE-2024-38856: Pre-Auth RCE Vulnerability in Apache OFBiz
IntroductionOn August 5, 2024, researchers at SonicWall discovered a zero-day security flaw in Apache OFBiz tracked as CVE-2024-38856. The vulnerabili… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/cve-2024-38856-pre-auth-rce-vulnerability-in-apache-ofbiz/
-
Critical Apache OfBiz Vulnerability Allows Preauth RCE
The enterprise resource planning platform bug CVE-2024-38856 has a vulnerability-severity score of 9.8 out of 10 on the CVSS scale and offers a wide a… First seen on darkreading.com Jump to article: www.darkreading.com/application-security/critical-apache-ofbiz-vulnerability-allows-preauth-rce
-
Five zero-days impacts EoL Cisco Small Business IP Phones. Replace them with newer models asap!
Cisco warns of critical remote code execution zero-day vulnerabilities impacting end-of-life Small Business SPA 300 and SPA 500 series IP phones. Cisc… First seen on securityaffairs.com Jump to article: securityaffairs.com/166811/uncategorized/zero-days-eof-small-business-ip-phones.html
-
QuickShell: Sharing Is Caring about an RCE Attack Chain on Quick Share
See how a SafeBreach Labs researcher bypassed the anti-tampering mechanism of a leading EDR to execute malicious code within one of the EDR’s own proc… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/08/quickshell-sharing-is-caring-about-an-rce-attack-chain-on-quick-share/
-
Cisco warns of critical RCE zero-days in end of life IP phones
Cisco is warning of multiple critical remote code execution zero-days in the web-based management interface of the end-of-life Small Business SPA 300 … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisco-warns-of-critical-rce-zero-days-in-end-of-life-ip-phones/
-
Critical Jenkins Vulnerabilities Expose Servers To RCE Attack
Jenkins, an open source automation server, has been found to have two security issues, one of which is a critical flaw that, if exploited, might lead … First seen on gbhackers.com Jump to article: gbhackers.com/critical-jenkins-vulnerabilities/
-
CISA warns about actively exploited Apache OFBiz RCE flaw
Tags: apache, attack, cisa, cybersecurity, exploit, flaw, infrastructure, rce, remote-code-execution, vulnerabilityThe U.S. Cybersecurity & Infrastructure Security Agency is warning of two vulnerabilities exploited in attacks, including a path traversal impacting A… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/cisa-warns-about-actively-exploited-apache-ofbiz-rce-flaw/
-
RCE possible with critical Apache OFBiz zero-day
First seen on scmagazine.com Jump to article: www.scmagazine.com/brief/rce-possible-with-critical-apache-ofbiz-zero-day
-
Critical Progress WhatsUp RCE flaw now under active exploitation
Threat actors are actively attempting to exploit a recently fixed Progress WhatsUp Gold remote code execution vulnerability on exposed servers for in… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/critical-progress-whatsup-rce-flaw-now-under-active-exploitation/
-
Critical ServiceNow Vulnerability Exposes Organizations to Remote Code Execution Attacks
A critical vulnerability in ServiceNow has captured the attention of cybersecurity professionals and organizations across various sectors. This issue,… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/servicenow-vulnerability/

