Author Archives: CIRT Team



CIRT Team

in Security Advisories & Alerts

Windows SeriousSAM vulnerability: CVE-2021-36934 Local Privilege Escalation Vulnerability in Microsoft Windows

An elevation of privilege vulnerability exists because of overly permissive Access Control Lists (ACLs) on multiple system files, including the Security Accounts Manager (SAM) database.An attacker who successfully exploited this vulnerability could run arbitrary code with SYSTEM privileges. An attacker could then install programs; view, change, or delete data; or...

Read more

0
25 Jul 2021
in Security Advisories & Alerts

A Vulnerability in SolarWinds Serv-U Could Allow for Remote Code Execution

DESCRIPTION:A vulnerability has been discovered in SolarWinds Serv-U, which couldresult in remote code execution. SolarWinds Serv-U is an FTP serversoftware for secure file transfer. Successful exploitation of thisvulnerability could allow for remote code execution within the contextof a privileged process. Depending on the privileges associated withthis application, an attacker could...

Read more

0
19 Jul 2021
in Security Advisories & Alerts

Multiple Vulnerabilities in Kaseya VSA Could Allow for Arbitrary Code Execution

DESCRIPTION:Multiple vulnerabilities have been discovered in Kaseya VSA that couldallow for arbitrary code execution. Kaseya VSA is a software used byMSPs to remotely manage networks and endpoints. Successful exploitationof these vulnerabilities could result in arbitrary code execution withinthe context of the application, an attacker gaining the same privilegesas the logged-on...

Read more

0
19 Jul 2021
in Security Advisories & Alerts

Multiple Vulnerabilities in Google Android OS Could Allow for Arbitrary Code Execution

DESCRIPTION:Multiple vulnerabilities have been discovered in the Google Androidoperating system (OS), the most severe of which could allow forarbitrary code execution. Android is an operating system developed byGoogle for mobile devices, including, but not limited to, smartphones,tablets, and watches. Successful exploitation of the most severe ofthese vulnerabilities could allow for...

Read more

0
11 Jul 2021
in Security Advisories & Alerts

UPDATED – Critical Patches Issued for Microsoft Products, June 8, 2021

DESCRIPTION:Multiple vulnerabilities have been discovered in Microsoft products, themost severe of which could allow for arbitrary code execution in thecontext of the logged-on user. Depending on the privileges associatedwith the user, an attacker could then install programs; view, change, ordelete data; or create new accounts with full user rights. Users...

Read more

0
11 Jul 2021
in CVE, Security Advisories & Alerts

Millions of Dell Devices at Risk for Remote BIOS Attacks – CVE-2021-21571, CVE-2021-21572, CVE-2021-21573, CVE-2021-21574

Description:Eclypsium researchers have identified multiple vulnerabilities affecting the BIOSConnect feature within Dell Client BIOS.This chain of vulnerabilities has a cumulative CVSS score of 8.3 (High) because it allows a privileged network adversary to impersonate Dell.com andgain arbitrary code execution at the BIOS/UEFI level of the affected device. Such an attack...

Read more

0
11 Jul 2021
in CVE, Security Advisories & Alerts

PrintNightmare(CVE-2021-34527): Microsoft Releases Out-of-Band Security Updates

Microsoft has released the KB5004945 emergency security update to fix the actively exploited PrintNightmare zero-day vulnerability in the Windows Print Spooler service impacting all Windows versions. However, the patch is incomplete and the vulnerability can still be locally exploited to gain SYSTEM privileges. The remote code execution bug (tracked as...

Read more

0
07 Jul 2021
Page 1 of 512345