Aggregator
An Interview With the Target & Home Depot Hacker
1 year 7 months ago
In December 2023, KrebsOnSecurity revealed the real-life identity of Rescator, the nickname used by a Russian cybercriminal who sold more than 100 million payment cards stolen from Target and Home Depot between 2013 and 2014. Moscow resident Mikhail Shefel, who confirmed using the Rescator identity in a recent interview, also admitted reaching out because he is broke and seeking publicity for several new money making schemes.
BrianKrebs
CVE-2022-21899 | Microsoft Windows up to Server 2012 R2 Extensible Firmware Interface Privilege Escalation (Replaces VDB-190120)
1 year 7 months ago
A vulnerability, which was classified as critical, was found in Microsoft Windows up to Server 2012 R2. Affected is an unknown function of the component Extensible Firmware Interface. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2022-21899. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21900 | Microsoft Windows up to Server 2022 Hyper-V (Replaces VDB-190121)
1 year 7 months ago
A vulnerability has been found in Microsoft Windows and classified as problematic. Affected by this vulnerability is an unknown functionality of the component Hyper-V. The manipulation leads to an unknown weakness.
This vulnerability is known as CVE-2022-21900. Access to the local network is required for this attack. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21901 | Microsoft Windows up to Server 2022 Hyper-V Privilege Escalation (Replaces VDB-190122)
1 year 7 months ago
A vulnerability was found in Microsoft Windows and classified as very critical. Affected by this issue is some unknown functionality of the component Hyper-V. The manipulation leads to Privilege Escalation.
This vulnerability is handled as CVE-2022-21901. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21902 | Microsoft Windows up to Server 2022 DWM Core Library privileges management (Replaces VDB-190123)
1 year 7 months ago
A vulnerability was found in Microsoft Windows up to Server 2022. It has been classified as critical. This affects an unknown part of the component DWM Core Library. The manipulation leads to improper privilege management.
This vulnerability is uniquely identified as CVE-2022-21902. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21903 | Microsoft Windows up to Server 2022 GDI Privilege Escalation (Replaces VDB-190124)
1 year 7 months ago
A vulnerability was found in Microsoft Windows. It has been declared as critical. This vulnerability affects unknown code of the component GDI. The manipulation leads to Privilege Escalation.
This vulnerability was named CVE-2022-21903. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21899 | Microsoft Windows up to Server 2012 R2 Extensible Firmware Interface denial of service (Replaced by VDB-190110)
1 year 7 months ago
A vulnerability has been found in Microsoft Windows up to Server 2012 R2 and classified as critical. This vulnerability affects unknown code of the component Extensible Firmware Interface. The manipulation leads to denial of service.
This vulnerability was named CVE-2022-21899. The attack can be initiated remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21900 | Microsoft Windows up to Server 2022 Hyper-V Privilege Escalation (Replaced by VDB-190111)
1 year 7 months ago
A vulnerability was found in Microsoft Windows and classified as problematic. This issue affects some unknown processing of the component Hyper-V. The manipulation leads to Privilege Escalation.
The identification of this vulnerability is CVE-2022-21900. The attack can only be done within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21901 | Microsoft Windows up to Server 2022 Hyper-V Privilege Escalation (Replaced by VDB-190112)
1 year 7 months ago
A vulnerability was found in Microsoft Windows. It has been classified as critical. Affected is an unknown function of the component Hyper-V. The manipulation leads to Privilege Escalation.
This vulnerability is traded as CVE-2022-21901. The attack can only be initiated within the local network. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21902 | Microsoft Windows up to Server 2022 DWM Core Library privileges management (Replaced by VDB-190113)
1 year 7 months ago
A vulnerability was found in Microsoft Windows up to Server 2022. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component DWM Core Library. The manipulation leads to improper privilege management.
This vulnerability is known as CVE-2022-21902. The attack can be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21903 | Microsoft Windows up to Server 2022 GDI Privilege Escalation (Replaced by VDB-190114)
1 year 7 months ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. Affected by this issue is some unknown functionality of the component GDI. The manipulation leads to Privilege Escalation.
This vulnerability is handled as CVE-2022-21903. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21904 | Microsoft Windows up to Server 2022 GDI information disclosure
1 year 7 months ago
A vulnerability classified as problematic has been found in Microsoft Windows. This affects an unknown part of the component GDI. The manipulation leads to information disclosure.
This vulnerability is uniquely identified as CVE-2022-21904. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21905 | Microsoft Windows up to Server 2022 Hyper-V denial of service
1 year 7 months ago
A vulnerability classified as problematic was found in Microsoft Windows. This vulnerability affects unknown code of the component Hyper-V. The manipulation leads to denial of service.
This vulnerability was named CVE-2022-21905. Access to the local network is required for this attack to succeed. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
Critical vulnerabilities persist in high-risk sectors
1 year 7 months ago
Finance and insurance sectors found to have the highest number of critical vulnerabilities, according to Black Duck. Finance and insurance industry faces highest vulnerabilities The report, which analyzes data from over 200,000 dynamic application security testing (DAST) scans conducted by Black Duck on approximately 1,300 applications across 19 industry sectors from June 2023 to June 2024, found variations in vulnerability types and remediation practices. Of the 96,917 total vulnerabilities identified, the two most critical categories … More →
The post Critical vulnerabilities persist in high-risk sectors appeared first on Help Net Security.
Help Net Security
2024年网络安全漏洞研究人才培养交流活动成功举办
1 year 7 months ago
2024年11月14日,由中国信息安全测评中心主办,中国信息产业商会信息安全产业分会承办的“网络安全漏洞研究人才培养交流活动”在北京国家会议中心成功举办。
CVE-2022-21892 | Microsoft Windows up to Server 2022 Resilient File System Local Privilege Escalation
1 year 7 months ago
A vulnerability was found in Microsoft Windows and classified as critical. This issue affects some unknown processing of the component Resilient File System. The manipulation leads to Local Privilege Escalation.
The identification of this vulnerability is CVE-2022-21892. It is possible to launch the attack on the physical device. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21894 | Microsoft Windows up to Server 2022 Secure Boot (Replaces VDB-190115)
1 year 7 months ago
A vulnerability was found in Microsoft Windows. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Secure Boot. The manipulation leads to an unknown weakness.
This vulnerability is known as CVE-2022-21894. The attack needs to be approached locally. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21895 | Microsoft Windows up to Server 2022 User Profile Service link following (Replaces VDB-190116)
1 year 7 months ago
A vulnerability was found in Microsoft Windows. It has been rated as critical. Affected by this issue is some unknown functionality of the component User Profile Service. The manipulation leads to link following.
This vulnerability is handled as CVE-2022-21895. The attack may be launched remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com
CVE-2022-21896 | Microsoft Windows up to Server 2022 DWM Core Library race condition (Replaces VDB-190117)
1 year 7 months ago
A vulnerability classified as critical has been found in Microsoft Windows up to Server 2022. This affects an unknown part of the component DWM Core Library. The manipulation leads to race condition.
This vulnerability is uniquely identified as CVE-2022-21896. It is possible to initiate the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.
vuldb.com