-
Microsoft Windows MsiAdvertise Product function vulnerable to privilege escalation via race condition – 20th DEC 2018
Preface: MsiAdvertiseProduct function enables the installer to write to a script the registry and shortcut information used to assign or publish a product. Vulnerability details: Due to improper validation, the affected function can be abused to force installer service into making a copy of any file as SYSTEM privileges and read its content, resulting in…
-
OpenSource user mode file system for Windows, software driver contains a stack-based buffer overflow – 20th Dec 2018
Preface: Dokan is a user mode file system for Windows. It allows anyone to safely and easily develop new file systems on Windows operating systems. Technical details: When you want to create a new file system on Windows you need to develop a file system driver. Developing a device driver that works in the kernel…
-
CVE-2018-8653 | Scripting Engine Memory Corruption Vulnerability
Preface: “I Saw Mommy Kissing Santa Claus” is a famous Christmas song.But perhaps that it is the hacker kissing your Internet Explorer web browser before christmas time. Above description has similarity because both two people are the famous guy in the world. Detail description: ChakraCore is the core part of Chakra, the high-performance JavaScript engine…
-
Cyber security practitioner must stay alert! (Cisco security advice) – 19th Dec 2018
Preface: Firewall solutions are essential to protect organizations from potential cyber threats. HTTPS is used to make communication between the server and the browser secure. Key factor of Cyber security:It is hard to avoid vulnerability will be occured in digital products today. But the most critical issue is that how to know and the efficiency…
-
Analysis Reports by US Homeland Security – Legitimate open source remote administration tool re-engineer by threat actor as APT way of attack – Dec 2018
Preface: Quasar, a legitimate open-source remote administration tool. It is a fast and light-weight remote administration tool coded in C#. Background: APT actors have adapted Quasar and created modified minor (1.3.4.0) and major (2.0.0.0 and 2.0.0.1) versions. Since the re-engineering Quasar client will be mimics a Mozilla Firefox 48 browser running on Windows 8.1 or…
-
Webroot BrightCloud SDK HTTP headers-parsing code execution vulnerability – 17th Dec 2018
Preface: Webroot delivers next-generation endpoint security and threat intelligence services to protect businesses and individuals in a connected world. Technical background: The Webroot BrightCloud® Mobile Security SDK addresses mobile device vulnerabilities by enabling mobile management partners to offer enhanced security . Vulnerability found on 17th Dec 2018:CUJO Smart Firewall (ver 7003) provides services to avoid…
-
Jenkins Stapler Web Framework Arbitrary Code Execution Vulnerability – 17th Dec 2018
Preface: Vulnerabilities are flaws in computer software that create weaknesses in your computer or network overall security.Can you imagine that what is the actual situation before vulnerability found? Background information: Jenkins is the leading open-source automation server. Built with Java, it provides over 1000 plugins to support automation. Vulnerability announcement on 17th Dec 2018:The vulnerability…
-
Fake apps embedded ultimate spyware are being infect smartphones especially Android – Dec 2018
Preface: Blackhat conference held 3rd to 6th December 2018 in London. A topic awaken people bring attention to the smartphone security awareness especially Android OS. Technical details:Cyber security expert observe that a malform type of counterfeit apps spreading via watering hole websites and phishing emails. Targets were likely approached directly and encouraged to visit the…
-
CVE-2018-19966:Xen Union Data Structure Guest OS Users Privilege Escalation Vulnerability
Preface: Xen Project is a hypervisor using a microkernel design, providing services that allow multiple computer operating systems to execute on the same computer hardware concurrently. Vulnerability description:The vulnerability is due to an interpretation conflict for union data structure associated with shadow paging.The XSA-240 introduced a new field into the control structureassociated with each page…
-
Cisco Security Advisory – Texas Instruments Bluetooth Low Energy Denial of Service and Remote Code Execution Vulnerability – Last Updated: 13th Dec 2018.
Preface: Key component of smart city are the IoT devices. The communication protocol of the IoT devices are Lora, SigFox and NarrowBand (NB). Background: In realistic, smart city cannot lack of wifi setup for assistance. So, WiFi is one the key component in this family (Smart City). Vendor Cisco follow up TI BLE chips vulnerability…