-
CVE-2024-37079 and CVE-2024-37080: vCenter Server contains a heap-overflow vulnerability. Is this a prior incident? (18-June-2024)
Preface: The DCE/RPC protocol is the protocol for remote procedure calls. It is widely used in the modern Internet. Because the proper functioning of DCE/RPC protocols is critical to modern infrastructure and society, it is important to verify the reliability of DCE/RPC implementations. Background: This type of vulnerability can be particularly dangerous because it could…
-
CVE-2024-21478 – Automotive manufacturer staying alert! (18 June 2024)
Preface: For example, if your app defines a fence for headphones, it gets callbacks when the headphones are plugged in and when they’re unplugged. Background: Automotive infotainment is an in-car system that combines entertainment such as radio and music playing with driving information, including navigation, ADAS, and vehicle settings. The SA8255P delivers next-generation Qualcomm Snapdragon…
-
CVE-2024-4610: Arm was recently aware of this vulnerability being exploited in the wild (17 June 2024)
Arm has released limited details about the vulnerability. Do you think the following is similar to CVE-2024-4610? Preface: Arm was recently aware of reports of this vulnerability being exploited in the wild, but this exploit was a local attack. Perhaps, cybercriminals should help via email phishing or SMS functionality. Therefore, it attracted the attention of…
-
CVE-2023-20597: AGESA™ firmware versions previously provided did not sufficiently mitigate CVE-2023-20594. Release 2nd round of remedy.(13-June-2024)
Preface: June 2024 Update – After additional analysis, AMD believes that the Client AGESA™ firmware versions previously provided did not sufficiently mitigate CVE-2023-20594. This security bulletin has been updated with new Client AGESA™ firmware versions that contain updated mitigations. Background: The DXE drivers are responsible for initializing the processor, chipset, and platform components as well…
-
CVE-2024-35253: Microsoft Azure File Sync Elevation of Privilege Vulnerability (11 Jun 2024)
Preface: That is by design. If a file is created with the name of a just-deleted file, timestamps, attributes, and security are carried forward. Background: To immediately sync files that are changed in the Azure file share, the Invoke-AzStorageSyncChangeDetection PowerShell cmdlet can be used to manually initiate the detection of changes in the Azure file…
-
Repost CVE-2024-5274: Google Chrome fixed remote code execution vulnerability (11-06-2024)
CVE Release date: May 24, 2024 Preface: Every time I start learning CVE. It helps me enrich my knowledge. Even though it was released months ago. Background: Around the world in 2024, over 4450 companies have started using Chrome as Site Search tool. V8 is a JavaScript and WebAssembly engine developed by Google for its Chrome…
-
Regarding CVE-2024-0099 and CVE-2024-0084: Is this a renewed focus on vulnerabilities discovered in 2021? 10-June-2024
Original posted 06/06/2024 Preface: Oracle and Citrix have large customer bases and use Xen as their primary hypervisor. Red Hat, SUSE, and Canonical support KVM as a virtualization option in their Linux versions. When it comes to cloud computing, administrators face a similar decision: Citrix and Oracle offer Xen-based offerings rather than Google’s KVM. Background:…
-
CVE-2024-31335 GPU – PowerVR: Wrong order of operations in DevmemIntUnmapPMR2 may lead to temporarily dangling PTEs.AI accelerators called Neural Network Accelerator (NNA) staying alert! (7 June 2024)
Official Posted: 31st May 2024 Preface: PowerVR not limited 2D and 3D rendering, and for video encoding, decoding, associated image processing. It also develops AI accelerators called Neural Network Accelerator (NNA). The IMG Series4 is a revolutionary neural network accelerator (NNA) for the automotive industry that enables ADAS and autonomous driving. PowerVR accelerators are not…
-
CVE-2024-26926: Kernel – The vulnerability in this section could lead to local escalation of privilege in the kernel with no additional execution privileges needed (6 Jun 2024)
Preface: In linux distributions the term ‘upstream’ (also applied to kernel) refers to the original version (as is released by software developers) of a program/software (kernel in your case) while ‘downstream’ refers to the software provided by linux distribution. Background: There are many ways to communicate with IPC, such as: Shared Memory, Message Queue, PIPE,…
-
CVE-2024-22476: Improper input validation in some Intel® Neural Compressor software (5 June 2024)
Original article published on 14-05-2024 Preface: Ancient humans hunted for survival. As times goes by, the evolution make them become intelligence biology. This pursuit of progress divided into different level of human. Human want is never ending. When Artificial Intelligence has born. It is the creator’s final blessing to human. Background: Intel Neural Compressor performs…