Tag: remote-code-execution
-
Critical MSMQ RCE Bug Opens Microsoft Servers to Complete Takeover
First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/critical-msmq-rce-bug-microsoft-servers-complete-takeover
-
Critical Code Execution Vulnerabilities Patched in VMware vCenter Server
Serious vulnerabilities that can allow remote code execution and privilege escalation have been patched in VMware vCenter Server. The post vulnerabili… First seen on securityweek.com Jump to article: www.securityweek.com/critical-code-execution-vulnerabilities-patched-in-vmware-vcenter-server/
-
New PHP Vulnerability Exposes Windows Servers to Remote Code Execution
Details have emerged about a new critical security flaw impacting PHP that could be exploited to achieve remote code execution under certain circumsta… First seen on thehackernews.com Jump to article: thehackernews.com/2024/06/new-php-vulnerability-exposes-windows.html
-
Critical Outlook RCE Vulnerability Exploits Preview Pane Patch Now!
ritical vulnerability (CVE-2024-30103) in Microsoft Outlook allows attackers to execute malicious code simply by opening an email. This zero-click exp… First seen on hackread.com Jump to article: hackread.com/outlook-rce-vulnerability-exploits-preview-pane/
-
PHP Updates Urged Over Critical Vuln That Could Lead To RCE
First seen on packetstormsecurity.com Jump to article: packetstormsecurity.com/news/view/35979/PHP-Updates-Urged-Over-Critical-Vuln-That-Could-Lead-To-RCE.html
-
Ivanti EPM SQL Injection Flaw Let Attackers Execute Remote Code
In May 24, 2024, Zero-Day Initiative released a security advisory for Ivanti EPM which was associated with SQL injection Remote code execution vulnera… First seen on gbhackers.com Jump to article: gbhackers.com/ivanti-epm-sql-injection-rce-vulnerability/
-
256,000+ Publicly Exposed Windows Servers Vulnerable to MSMQ RCE Flaw
Cybersecurity watchdog Shadowserver has identified 256,000+ publicly exposed servers vulnerable to a critical Remote Code Execution (RCE) flaw in Micr… First seen on gbhackers.com Jump to article: gbhackers.com/256000-windows-servers-msmq-rce-flaw/
-
Microsoft fixes RCE vulnerabilities in MSMQ, Outlook (CVE-2024-30080, CVE-2024-30103)
June 2024 Patch Tuesday is here and Microsoft has delivered fixes for a critical MSMQ flaw (CVE-2024-30080) and a RCE vulnerability in Microsoft Outlo… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/11/cve-2024-30080-cve-2024-30103/
-
Microsoft Urges Windows Admins to Patch Microsoft Message Queuing RCE Flaw
Microsoft has disclosed two Critical remote code execution vulnerabilities in MSMQ (Microsoft Message Queuing) and the Windows Wi-Fi Driver. The CVE f… First seen on gbhackers.com Jump to article: gbhackers.com/microsoft-message-queuing-rce-flaw/
-
Microsoft June 2024 Patch Tuesday fixes 51 flaws, 18 RCEs
Today is Microsoft’s June 2024 Patch Tuesday, which includes security updates for 51 flaws, eighteen remote code execution flaws, and one publicly dis… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/microsoft/microsoft-june-2024-patch-tuesday-fixes-51-flaws-18-rces/
-
CVE-2024-29824 Deep Dive: Ivanti EPM SQL Injection Remote Code Execution Vulnerability
Introduction Ivanti Endpoint Manager (EPM) is an enterprise endpoint management solution that allows for centralized management of devices within an o… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/cve-2024-29824-deep-dive-ivanti-epm-sql-injection-remote-code-execution-vulnerability/
-
TellYouThePass ransomware exploits recent PHP RCE flaw to breach servers
The TellYouThePass ransomware gang has been exploiting the recently patched CVE-2024-4577 remote code execution vulnerability in PHP to deliver webshe… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/tellyouthepass-ransomware-exploits-recent-php-rce-flaw-to-breach-servers/
-
Patch Tuesday: Remote Code Execution Flaw in Microsoft Message Queuing
Tags: cvss, exploit, flaw, malicious, microsoft, remote-code-execution, update, vulnerability, windowsThe Windows vulnerability carries a CVSS severity score of 9.8/10 and can be exploited by via specially crafted malicious MSMQ packets. The post ows v… First seen on securityweek.com Jump to article: www.securityweek.com/patch-tuesday-remote-code-execution-flaw-in-microsoft-message-queuing/
-
PHP addressed critical RCE flaw potentially impacting millions of servers
A new PHP for Windows remote code execution (RCE) flaw affects version 5.x and earlier versions, potentially impacting millions of servers worldwide. … First seen on securityaffairs.com Jump to article: securityaffairs.com/164302/breaking-news/php-critical-rce.html
-
Week in review: Atlassian Confluence RCE PoC, new Kali Linux, Patch Tuesday forecast
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: High-risk Atlassian Confluence RCE fixed, PoC availa… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/09/week-in-review-atlassian-confluence-rce-poc-new-kali-linux-patch-tuesday-forecast/
-
PHP updates urged over critical vulnerability that could lead to RCE
First seen on scmagazine.com Jump to article: www.scmagazine.com/news/php-updates-urged-over-critical-vulnerability-that-could-lead-to-rce
-
PHP Patches Critical Remote Code Execution Vulnerability
PHP has released patches for CVE-2024-4577, a critical vulnerability that could lead to arbitrary code execution on remote servers. The post released … First seen on securityweek.com Jump to article: www.securityweek.com/php-patches-critical-remote-code-execution-vulnerability/
-
Alleged RCE Vulnerability Threatens Subdomains of Italian Ministry of Defence
A threat actor known as spr1ngtr4p has purportedly advertised a Remote Code Execution (RCE) vulnerability affecting a subdomain of Italy’s Ministry of… First seen on thecyberexpress.com Jump to article: thecyberexpress.com/rce-vulnerability-italian-ministry-of-defence/
-
Understanding the RCE Vulnerabilities in WordPress Plugins
Imagine handing over the controls of your website to someone you don’t trust that’s the risk of RCE vulnerabilities in WordPress. Attackers can modi… First seen on securityboulevard.com Jump to article: securityboulevard.com/2024/06/understanding-the-rce-vulnerabilities-in-wordpress-plugins/
-
Critical PHP Vulnerability Threatens Windows Servers
Remote Code Execution Exploit Found; Patch Now Available. A critical remote code execution vulnerability in PHP for Windows, affecting all releases si… First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/critical-php-vulnerability-threatens-windows-servers-a-25460
-
PHP fixes critical RCE flaw impacting all versions for Windows
A new PHP for Windows remote code execution (RCE) vulnerability has been disclosed, impacting all releases since version 5.x, potentially impacting a … First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/php-fixes-critical-rce-flaw-impacting-all-versions-for-windows/
-
Chinese Hackers Exploit Old ThinkPHP Vulnerabilities in New Attacks
Akamai warns that a Chinese threat actor is exploiting years-old remote code execution vulnerabilities in ThinkPHP in new attacks. The post arns that … First seen on securityweek.com Jump to article: www.securityweek.com/chinese-hackers-exploit-old-thinkphp-vulnerabilities-in-new-attacks/
-
Zyxel addressed three RCEs in endlife NAS devices
Zyxel Networks released an emergency security update to address critical vulnerabilities in end-of-life NAS devices. Zyxel Networks released an emerge… First seen on securityaffairs.com Jump to article: securityaffairs.com/164150/security/zyxel-rce-eof-nas-devices.html
-
TP-Link Gaming Router Vulnerability Exposes Users to Remote Code Attacks
A maximum-severity security flaw has been disclosed in the TP-Link Archer C5400X gaming router that could lead to remote code execution on susceptible… First seen on thehackernews.com Jump to article: thehackernews.com/2024/05/tp-link-gaming-router-vulnerability.html
-
Exploit for Fortinet Critical RCE Bug Allows SIEM Root Access
First seen on darkreading.com Jump to article: www.darkreading.com/vulnerabilities-threats/exploit-fortinet-critical-rce-bug-siem-root-access
-
Details of Atlassian Confluence RCE Vulnerability Disclosed
SonicWall has shared technical details on a recently addressed high-severity remote code execution flaw in Confluence. The post l has shared technical… First seen on securityweek.com Jump to article: www.securityweek.com/details-of-atlassian-confluence-rce-vulnerability-disclosed/
-
PoC for Progress Telerik RCE chain released (CVE-2024-4358, CVE-2024-1800)
Security researchers have published a proof-of-concept (PoC) exploit that chains together two vulnerabilities (CVE-2024-4358, CVE-2024-1800) to achiev… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/04/cve-2024-4358-cve-2024-1800-poc/
-
Zyxel issues emergency RCE patch for endlife NAS devices
Zyxel Networks has released an emergency security update to address three critical vulnerabilities impacting older NAS devices that have reached end-o… First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/zyxel-issues-emergency-rce-patch-for-end-of-life-nas-devices/
-
High-risk Atlassian Confluence RCE fixed, PoC available (CVE-2024-21683)
If you’re self-hosting an Atlassian Confluence Server or Data Center installation, you should upgrade to the latest available version to fix a high-se… First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2024/06/03/cve-2024-21683-poc/
-
Zyxel NAS Devices Vulnerability Let Attackers Execute Code Remotely
Zyxel has released patches addressing critical command injection and remote code execution vulnerabilities in two of its NAS products, NAS326 and NAS5… First seen on gbhackers.com Jump to article: gbhackers.com/zyxel-nas-devices-vulnerability/

