Google Chrome V8 Type confusion Vulnerability (CVE-2020-6418)

Summary: In last week of February,2020, a type confusion vulnerability in V8, Google Chrome’s open-source JavaScript and WebAssembly engine.  Description: Details about these attacks are not yet public, and we don’t know how this bug  (that has been restricted) is being used against Chrome users. V8 is Chrome’s component that is responsible for processing JavaScript … Continue reading “Google Chrome V8 Type confusion Vulnerability (CVE-2020-6418)”

Microsoft Edge based on Edge HTML Information Disclosure Vulnerability

Microsoft Edge is the most commonly used web browser among the Windows user. It is the default browser in Windows. So, it is not strange if an attacker tries to hack the Commonly used web browser. Vulnerability Details: “An information disclosure vulnerability exists when Microsoft Edge based on Edge HTML improperly handles objects in memory.” … Continue reading “Microsoft Edge based on Edge HTML Information Disclosure Vulnerability”

PhpUnit Remote Command Execution Vulnerability

Summary: PHPUnit is widely used testing framework for PHP. A remote code execution vulnerability was discovered in Util/PHP/eval-stdin.php in that allows remote attackers to execute arbitrary PHP code. This issue was assigned under CVE-2017-9841. Affected Versions: PHPUnit versions from 4.8.19 before 4.8.28 and from 5.0.10 before 5.6.3 Description: CVE-2017-9841 is a code execution vulnerability in … Continue reading “PhpUnit Remote Command Execution Vulnerability”

Apache-Tomcat-Ajp File containment Vulnerability (CVE-2020-1938, CNVD-2020-10487)

Summary: In third week of February,2020, after MSPT, a file containing vulnerability, which can be used by an attacker to read or include any files in all webapp directories on Tomcat, such as webapp configuration files or source code. Description: AJP is a protocol that is supported by various WAS such as Apache HTTP Server, … Continue reading “Apache-Tomcat-Ajp File containment Vulnerability (CVE-2020-1938, CNVD-2020-10487)”

Adobe Media Encoder Out-of-Bounds Write Vulnerability (CVE-2020-3764)

Summary: In third week of February,2020, after MSPT, an out-of-bounds (OOB) write vulnerability was observed in Adobe Media Encoder that leads to arbitrary code execution. This vulnerability was observed only for Microsoft Windows platform. Description: Adobe Media Encoder, is a software for encoding and compressing audio or video files. When the untrusted input is processed, … Continue reading “Adobe Media Encoder Out-of-Bounds Write Vulnerability (CVE-2020-3764)”

Remote Desktop Client Remote Code Execution Vulnerability. (CVE-2020-0734, CVE-2020-0681)

Summary: In the month of February,2020, among MSPT, a remote code execution vulnerability exists in the Windows Remote Desktop Client when a user connects to a malicious server. On account of this vulnerability, an attacker could execute arbitrary code as well as compromise a legitimate server and perform CnC operation. Description: An attacker would need … Continue reading “Remote Desktop Client Remote Code Execution Vulnerability. (CVE-2020-0734, CVE-2020-0681)”

Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability Alert (CVE-2020-0618)

Summary: In the month of February,2020, among MSPT, Microsoft SQL Server Reporting Services had to deal with a remote code execution vulnerability. This happens as it incorrectly handles page requests. The SSRS web application allowed low privileged user accounts to run code on the server by exploiting a deserialization issue. Description: As a initial part … Continue reading “Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability Alert (CVE-2020-0618)”

Windows Modules Installer Service Information Disclosure Vulnerability (CVE-2020-0728)

Summary: In the month of February,2020, among MSPT, Windows Modules Installer Service improperly discloses file information., resulting into an information disclosure vulnerability. Description: Logging onto an affected system and run a crafted application would lead to this information disclosure vulnerability. The TrustedInstaller service running on the Microsoft Windows operating system hosts a COM service called … Continue reading “Windows Modules Installer Service Information Disclosure Vulnerability (CVE-2020-0728)”

Mozilla Firefox And Firefox ESR Type Confusion Vulnerability

Summary: Mozilla Firefox and Firefox Extended Support Release (ESR) suffer from Type Confusion Vulnerability which could allow for arbitrary code execution. Depending on the privileges of the user, an attacker could install, view, change, or delete data, or create new accounts with full user rights. This issue was assigned under CVE-2019-17026. Description: Recently a Type … Continue reading “Mozilla Firefox And Firefox ESR Type Confusion Vulnerability”

Microsoft Windows Privilege Escalation Vulnerability – CVE-2020-0668

In February 2020 Patch Tuesday, Microsoft released patches for CVE-2020-0668, an elevation of privilege vulnerability that could allow a local authenticated attacker to execute arbitrary code with elevated permissions. Description: It’s an arbitrary file move vulnerability in Service Tracing feature of Windows Operating Systems. This feature provides some basic debug information about running services and … Continue reading “Microsoft Windows Privilege Escalation Vulnerability – CVE-2020-0668”