Subscribe via feed.
Posts under exploit

Riello UPS Restricted Shell Bypass

Posted by deepcore under exploit (No Respond)

Riello UPS systems can have their restricted configuration shell bypassed to gain full underlying operating system access.

Shannon Baseband NrmmMsgCodec Intra-Object Overflow

Posted by deepcore under exploit (No Respond)

There is an intra-object overflow in Shannon Baseband, inside the 5G MM protocol implementation (NrmmMsgCodec as it is called in Shannon according to debug strings), specifically when handling the Service Area List message (IEI = 0x27).

Open Web Analytics 1.7.3 Remote Code Execution

Posted by deepcore under exploit (No Respond)

Open Web Analytics (OWA) versions prior to 1.7.4 allow an unauthenticated remote attacker to obtain sensitive user information, which can be used to gain admin privileges by leveraging cache hashes.

18 Zero-Day Flaws Impact Samsung Android Handsets, Wearables And Telematics

Posted by deepcore under exploit (No Respond)

Shannon Baseband NrmmMsgCodec Intra-Object Overflow

Posted by deepcore under exploit (No Respond)

There is an intra-object overflow in Shannon Baseband, inside the 5G MM protocol implementation (NrmmMsgCodec as it is called in Shannon according to debug strings), specifically when handling the Service Area List message (IEI = 0x27).

XNU NFSSVC Root Check Bypass / Use-After-Free

Posted by deepcore under exploit (No Respond)

XNU NFSSVC suffers from root check bypass and use-after-free vulnerabilities due to insufficient locking in upcall worker threads.

Microsoft SQL Server 2014 / 2016 / 2017 / 2019 / 2022 Audit Logging Failure

Posted by deepcore under exploit (No Respond)

Microsoft SQL Server 2014, 2016, 2017, 2019, and 2022 appears to ignore audit rules for sys.sysxlgns allowing an attacker with administrative permissions to extract password hashes under the radar. Microsoft told the researcher they are not willing to fix it but acknowledge it as a security problem.

Bitbucket Environment Variable Remote Command Injection

Posted by deepcore under exploit (No Respond)

For various versions of Bitbucket, there is an authenticated command injection vulnerability that can be exploited by injecting environment variables into a user name. This module achieves remote code execution as the atlbitbucket user by injecting the GIT_EXTERNAL_DIFF environment variable, a null character as a delimiter, and arbitrary code into a user’s user name. The […]

Microsoft Outlook CVE-2023-23397 Proof Of Concept

Posted by deepcore under exploit (No Respond)

Proof of concept code for a critical Microsoft Outlook vulnerability for Windows that allows hackers to remotely steal hashed passwords by simply receiving an email.

Microsoft Outlook CVE-2023-23397 Proof Of Concept

Posted by deepcore under exploit (No Respond)

Proof of concept code for a critical Microsoft Outlook vulnerability for Windows that allows hackers to remotely steal hashed passwords by simply receiving an email.