Tag
#windows
Today, Talos is publishing a glimpse into the most prevalent threats we've observed between June 16 and June 23. As with previous roundups, this post isn't meant to be an in-depth analysis. Instead, this post will summarize the threats we've observed by highlighting key
A logic issue was addressed with improved checks. This issue is fixed in iTunes 12.12.9 for Windows. An app may be able to elevate privileges
For line-of-business execs, the fear of grinding mission-critical systems to a halt overrides the fear of ransomware. How can CISOs overcome this?
This Metasploit module exploits an SQL injection vulnerability in the MOVEit Transfer web application that allows an unauthenticated attacker to gain access to MOVEit Transfer's database. Depending on the database engine being used (MySQL, Microsoft SQL Server, or Azure SQL), an attacker can leverage an information leak be able to upload a .NET deserialization payload.
Advanced ASP Chat version 2.0 suffers from a database disclosure vulnerability.
Adult Video Script version 3.0 suffers from local and remote file inclusion vulnerabilities.
Adiscon LogAnalyzer version 4.1.5 suffers from a cross site scripting vulnerability.
Adapt Inventory Management System version 1.0.0 suffers from a remote SQL injection vulnerability that allows for authentication bypass.
Active Newspaper version 2.0 suffers from an html injection vulnerability.
Improper Access Control in GitHub repository admidio/admidio prior to 4.2.9.