Subscribe via feed.
Archive for February, 2023

Zoho ManageEngine ServiceDesk Plus 14003 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine ServiceDesk Plus versions 14003 and below (CVE-2022-47966). Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ServiceDesk Plus SAML endpoint. Note that the […]

Zoho ManageEngine ServiceDesk Plus 14003 Remote Code Execution

Posted by deepcore under exploit (No Respond)

This Metasploit module exploits an unauthenticated remote code execution vulnerability that affects Zoho ManageEngine ServiceDesk Plus versions 14003 and below (CVE-2022-47966). Due to a dependency to an outdated library (Apache Santuario version 1.4.1), it is possible to execute arbitrary code by providing a crafted samlResponse XML to the ServiceDesk Plus SAML endpoint. Note that the […]

Windows Kernel Registry Virtualization Memory Corruption

Posted by deepcore under exploit (No Respond)

Microsoft Windows suffers from a kernel memory corruption due to an insufficient handling of predefined keys in registry virtualization.

Android Binder VMA Management Security Issues

Posted by deepcore under exploit (No Respond)

Android Binder VMA management suffers from multiple security issues.

Apache Tomcat On Ubuntu Log Init Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module targets a vulnerability in Tomcat versions 6, 7, and 8 on Debian-based distributions where these older versions provide a vulnerable tomcat init script that allows local attackers who have already gained access to the tomcat account to escalate their privileges from the tomcat user to root and fully compromise the target system.

Apache Tomcat On Ubuntu Log Init Privilege Escalation

Posted by deepcore under exploit (No Respond)

This Metasploit module targets a vulnerability in Tomcat versions 6, 7, and 8 on Debian-based distributions where these older versions provide a vulnerable tomcat init script that allows local attackers who have already gained access to the tomcat account to escalate their privileges from the tomcat user to root and fully compromise the target system.

Oracle Database 12.1.0.2 Spatial Component Privilege Escalation

Posted by deepcore under exploit (No Respond)

Oracle Database version 12.1.0.2 suffers from a privilege escalation vulnerability that achieves DBA access via the Spatial component.

F5 Big-IP Create Administrative User

Posted by deepcore under exploit (No Respond)

This Metasploit module creates a local user with a username/password and root-level privileges. Note that a root-level account is not required to do this, which makes it a privilege escalation issue. Note that this is pretty noisy, since it creates a user account and creates log files and such. Additionally, most (if not all) vulnerabilities […]

macOS Dirty Cow Arbitrary File Write Local Privilege Escalation

Posted by deepcore under exploit (No Respond)

Dirty Cow arbitrary file write local privilege escalation exploit for macOS.

Lenovo Diagnostics Driver Memory Access

Posted by deepcore under exploit (No Respond)

This Metasploit module demonstrates how an incorrect access control for the Lenovo Diagnostics Driver allows a low-privileged user the ability to issue device IOCTLs to perform arbitrary physical/virtual memory reads and writes.