-
CVE-2021-22045 – VMware ESXi,VMware Workstation and VMware Fusion contains a heap-overflow vulnerability in CD-ROM device emulation (4th Jan 2022)
Preface: You cannot connect to a virtual machine’s CD/DVD-ROM device with the Administrator role. By default setting, the Administrator role does not have permission to access a virtual machine’s CD/DVD-ROM device. Background: Most of the files stored on a VMFS volume, though, are large files – virtual disk files, swap files, installation image files. VMFS…
-
CVE-2021-1918 : Improper handling of resource allocation in virtual machines can lead to information exposure in Snapdragon. NVD Published Date 3rd JAN, 2022
Preface: The specifics vulnerability (CVE-2021-1918) has notified customer on 06/07/2021. But vendor security advisory was released on 6th December, 2022. Finally, US-CERT release the details on 3rd Jan, 2021. As a researcher or end user, it is not an issue. Background: Snapdragon is a suite of system on a chip (SoC) semiconductor products for mobile…
-
Go programming language design limitation – CVE-2021-44717 (NVD Published Date 1st Jan 2022)
Preface: Golang is useful for carrying out programming for scalable servers and large software systems. The Golang programming language was built to fill in the gaps of C++ and Java that Google came across while working with its servers and distributed systems. Not limited to Google, well-known cloud businesses such as Dropbox, Terraform, Kubernetes, and…
-
About CVE-2021-43876 Microsoft SharePoint Elevation of Privilege Vulnerability NVD Published – 29-12-2021
Preface: Maybe users who use SharePoint have similar feelings to me. Although SharePoint user permissions are complicated. In addition, the details of the vulnerability also give users a complex feeling! Background: CVE-2021-43976 was published 30th Dec, 2021. However, the vulnerability details has been released by Microsoft on 16th Nov, 2021. Perhaps, official details not described…
-
Apache status updates – 29th Dec 2021
Preface: Traditional, there is service ID account installed in web server side since it require connecting to DB server and update the data into database. Background: Apache log4j vulnerability wide spread in digital world. Additionally, industry area also involved to this design flaw. Enterprise industrial manufacturer Siemens published security advisory that Apache Log4j Vulnerability (CVE-2021-44832)…
-
About CVE-2021-43858 (27th Dec, 2021)
Preface: The main advantage of object storage is that you can group devices into large storage pools, and distribute those pools across multiple locations. Background: Object storage is a technology that manages data as objects. All data is stored in one large repository which may be distributed across multiple physical storage devices, instead of being…
-
About CVE-2021-23175 on NVIDIA GeForce Experience (21-12-2021)
Preface: When the Gamer PC is invaded by an attacker. The inherent risk is not limited to the local PC itself. From a technical point of view, the victim site will be transformed into a weapon to attack other peers. Background: GeForce Experience is the companion application to your GeForce graphics card. It keeps your…
-
Wish you a Merry Christmas and Happy New Year – 2021
-
CVE-2021-39306 – A stack buffer overflow was discovered on Realtek RTL8195AM device before 2.0.10 (22nd Dec, 2021)
Preface: In 2021, there are more than 10 billion active IoT devices.WiFi connection is part of the IoT device.It cannot lack this feature. Background: The Realtek RTL8195AM is a highly integrated single-chip with a low-power-consumption mechanism ideal for IoT (Internet of Things) applications. It combines an ARM®Cortex™-M3 MCU, WLAN MAC, a 1T1R capable WLAN baseband…
-
About Amega: Amega 3.0 will reach its end of life at the end of December 2021. So, it do not plan to release a patch (21st Dec, 2021)
Preface: CVE Numbering Authorities (CNAs) release published vulnerability details for MesaLabs Amega version 3.0 on 12/21/2021. Perhaps the criticality of the design flaw will be impacted whole world including Hospitals, Blood Banks, Pharmaceutical, Laboratories,… As a matter of fact, the related details has been released on HIPAA report on June this year. Background: AmegaView Environmental…