Subscribe via feed.
Archive for September, 2015

Cisco AnyConnect DMG Install Script Privilege Escalation

Posted by deepcore under Apple (No Respond)

Cisco AnyConnect Secure Mobility Client for OS X is affected by a vulnerability that allows local attackers to mount arbitrary DMG files at arbitrary mount points. By exploiting this vulnerability is is possible for the attacker to gain root privileges. Cisco reports that a similar issue also exists in Cisco AnyConnect Secure Mobility Client for […]

Tags: , ,

Cisco AnyConnect DLL Side Loading Privilege Escalation

Posted by deepcore under exploit (No Respond)

Cisco AnyConnect Secure Mobility Client for Windows is affected by an vulnerability that allows local attackers to execute arbitrary DLL files with elevated privilege. By exploiting this vulnerability is is possible for the attacker to gain SYSTEM privileges.

Windows Kernel DeferWindowPos Use-After-Free

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a use-after-free vulnerability related to DeferWindowPos.

Windows Kernel FlashWindowEx Memory Corruption

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a FlashWindowEx related memory corruption vulnerability.

w3tw0rk / Pitbul IRC Bot Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module allows remote command execution on the w3tw0rk / Pitbul IRC Bot.

iTop 2.1.0-2127 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

iTop version 2.1.0-2127 suffers from a cross site scripting vulnerability.

Windows Kernel BGetRealizedBrush Use-After-Free

Posted by deepcore under exploit (No Respond)

The Microsoft Windows kernel suffers from a use-after-free vulnerability in BGetRealizedBrush.

Flowdock API Bug Bounty #2 – Persistent Web Vulnerability

Posted by deepcore under exploit (No Respond)

The Vulnerability Laboratory Research Team discovered an application-side input validation web vulnerability in the official Flowdock online service web-application.

WiFi Drive CR v1.0 iOS – Persistent Filename Vulnerability

Posted by deepcore under exploit (No Respond)

The Vulnerability Laboratory Core Research Team discovered an application-side exception web vulnerability in the official WiFi Drive + CR v1.0 iOS mobile web-application.

[papers] – Deep Dive into .NET Malwares

Posted by deepcore under Security (No Respond)

Deep Dive into .NET Malwares

Tags: ,