-
CVE-2021-1075 – To protect your system, download and install this software update – 26th Apr 2021
Preface: Graphics card not detected in Device Manager, BIOS – It’s possible that your graphics card isn’t properly connected, or this is usually caused by incompatible drivers. Background: The DxgkDdiEscape function shares information with the user-mode display driver. This can be called directly from the user mode and accepts arbitrary data that is parsed and…
-
MySQL for Windows is vulnerable to privilege escalation due to OPENSSLDIR location – 25th Apr 2021
Preface: Similar design concepts rely on OpenSSL, and it is not news to encounter vulnerabilities. This time it was just a “Old wine in new bottles“. Background: MySQL source build on WINDOWS using Mingw. therefore it find themselves looking at sub-directories of ‘C:/usr/local’, which may be world writable, which enables untrusted users to modify OpenSSL’s…
-
Security Focus – CVE-2021-2200: Oracle Applications Framework Homepage component vulnerability. 21st Apr 2021
Background: OA Framework is based on J2EE technology called BC4J (Business Components for Java) The OA Framework is a Model-view-controller (MVC) framework built using J2EE (Java 2 Platform, Enterprise Edition) technologies. Vulnerability details: According to CVE-2021-2200, the vulnerability occurs on the homepage. For the benefit of the customer, Oracle will not announce the root cause…
-
VMware announcement – guest1 and guest2 user accounts design weakness (CVE-2021-21981) – 20th Apr, 2021
Preface: From a security perspective, what is the difference between configuration errors and vulnerabilities? Perhaps the potential impact are the same if it is involves privileges control function. Product background: NSX-T Data Center supports cloud-native applications, bare metal workloads, multi-hypervisor environments, public clouds, and multiple clouds. NSX-T aim to protect applications with workload-level micro-segmentation and…
-
The design weakness of DNS module causes Siemens Nucleus Products involves WRECK loophole – 19th April, 2021.
-
About WRECK DNS vulnerabilities – 15th Apr 2021
Background: DNS security awareness awaken by expert conduct a simple DNSsteal to do a demonstration show how to exploit unknown function feature on DNS function in few years ago.On April 2021, cyber security product vendor with security experts announce that a unknown TCP/IP Stack weakness in IoT.The difference in between DNS misuse function (DNSsteal) and…
-
Security Focus – About SAP Releases April 2021 Security Updates – 15th Apr 2021
As usual, because of vendor decision, vendor not going to release the details of design weakness. From my opinion that understand the details will be enhanced your system and infrastructure defense mechanism. Below is my personal comment according to this specifics vulnerability. Vulnerability details: CVE-2021-21481 – The MigrationService, which is part of SAP NetWeaver, does…
-
MS exchange Precautions – (13th Apr 2021)
Preface: A named pipe is just a file on the filesystem used for I/O through SMB. Background: Outlook Web App is hosted on the Client Access Server role for Exchange Server and integrated with IIS. An Internet Information Services (IIS) worker process is a Windows process (w3wp.exe) which runs web applications, and is responsible for…
-
RIOT-OS 2021.01 Precautions (CVE-2021-27697,CVE-2021-27698 & CVE-2021-27357) – 13th Apr 2021
Preface: RIOT is a low-memory operating system suitable for IoT devices. It is an open source software released under LGPLv2. Background: RPL (Routing Protocol for Low-Power and Lossy Networks) is a routing protocol for wireless networks with low power consumption and generally susceptible to packet loss. It is a proactive protocol based on distance vectors…
-
CVE-2021-30485 – A technical defect was found in ezxml 0.8.6 (11th Apr, 2021)
Preface: ezXML – XML Parsing C Library version 0.8.5 ezXML is a C library for parsing XML documents inspired by simpleXML for PHP.According to the statistis by W3Techs, PHP is use by 79.2% of all websites primary server-side programming language. Background: In an XML file, there are both tags and text. The tags provide the…