Subscribe via feed.
Archive for September, 2022

Windows Credential Guard BCrypt Context Use-After-Free Privilege Escalation

Posted by deepcore under exploit (No Respond)

On Windows, the method for allocating a context when using the CG BCrypt APIs is insecure leading to use-after-free of secure memory resulting in elevation of privilege.

@Drive 2.8 Local File Inclusion

Posted by deepcore under exploit (No Respond)

@Drive version 2.8 suffers from a local file inclusion vulnerability.

Windows Credential Guard Insufficient Checks On Kerberos Encryption Type Use

Posted by deepcore under exploit (No Respond)

Windows CG APIs, which take encrypted keys, do not limit what encryption or checksum types can be used with those keys. This can result in using weak encryption algorithms which could be abused to either generate keystreams or brute force encryption keys.

Windows Credential Guard Kerberos Change Password Privilege Escalation

Posted by deepcore under exploit (No Respond)

Windows Credential guard does not prevent using encrypted Kerberos keys to change a user’s password leading to elevation of privilege.

AirDisk 7.5.5 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

AirDisk version 7.5.5 suffers from a persistent cross site scripting vulnerability.

mbDrive Lite WiFi Flash Disk 1.4.0 Cross Site Scripting

Posted by deepcore under exploit (No Respond)

mbDrive Lite WiFi Flash Disk version 1.4.0 suffers from a cross site scripting vulnerability.

Online Notice Board 2022 SQL Injection

Posted by deepcore under exploit (No Respond)

Online Notice Board 2022 suffers from a remote SQL injection vulnerability.

Windows Credential Guard KerbIumCreateApReqAuthenticator Key Information Disclosure

Posted by deepcore under exploit (No Respond)

On Windows, CG API KerbIumCreateApReqAuthenticator can be used to decrypt arbitrary encrypted Kerberos keys leading to information disclosure.

Windows Credential Guard KerbIumGetNtlmSupplementalCredential Information Disclosure

Posted by deepcore under exploit (No Respond)

On Windows, the KerbIumGetNtlmSupplementalCredential CG API does not check the encryption key type leading to information disclosure of key material.

InTouch Access Anywhere Secure Gateway 2020 R2 Path Traversal

Posted by deepcore under exploit (No Respond)

InTouch Access Anywhere Secure Gateway versions 2020 R2 and below suffer from a path traversal vulnerability.