THREAT ADVISORY: Zero-Day Vulnerabilities Detected on WinRAR

Credit to Author: Quickheal| Date: Mon, 04 Sep 2023 06:21:13 +0000

Zero-day vulnerabilities represent an imminent threat to cybersecurity, and in this case, two such vulnerabilities, CVE-2023-38831 and CVE-2023-40477,…

The post THREAT ADVISORY: Zero-Day Vulnerabilities Detected on WinRAR appeared first on Quick Heal Blog.

Read more

Update now! WinRAR files can be abused to run malware

Categories: Exploits and vulnerabilities

Categories: News

Tags: WinRAR

Tags: CVE-2023-40477

Tags: RCE

Tags: Windows 11

A new version of WinRAR is available that patches two vulnerabilities attackers could use for remote code execution.

(Read more…)

The post Update now! WinRAR files can be abused to run malware appeared first on Malwarebytes Labs.

Read more

Patch now! Citrix Sharefile joins the list of actively exploited file sharing software

Categories: Exploits and vulnerabilities

Categories: News

Tags: Citrix

Tags: ShareFile

Tags: CVE-2023-24489

Tags: RCE

Tags: unauthenticated

Tags: vulnerability

Tags: PoC

Citrix ShareFile can be exploited remotely by unauthenticated attackers.

(Read more…)

The post Patch now! Citrix Sharefile joins the list of actively exploited file sharing software appeared first on Malwarebytes Labs.

Read more

Minecraft fans beware: Players and servers at risk from BleedingPipe vulnerability

Categories: Personal

Tags: Minecraft

Tags: mod

Tags: forge

Tags: players

Tags: vulnerability

Tags: RCE

Tags: bleedingpipe

Tags: malware

Minecraft players interested in modding are at risk from a remote code execution vulnerability targeting both players and servers.

(Read more…)

The post Minecraft fans beware: Players and servers at risk from BleedingPipe vulnerability appeared first on Malwarebytes Labs.

Read more

VMware patches critical vulnerabilities in Aria Operations for Networks

Categories: Exploits and vulnerabilities

Categories: News

Tags: cve-2023-20887

Tags: cve-2023-20888

Tags: cve-2023-20889

Tags: vmware

Tags: Aria Operations for Networks

Tags: RCE

Tags: information disclosure

Tags: deserialization

Tags: command injection

VMware has released security updates to fix a trio of flaws in Aria Operations for Networks that could result in information disclosure and remote code execution

(Read more…)

The post VMware patches critical vulnerabilities in Aria Operations for Networks appeared first on Malwarebytes Labs.

Read more

Super FabriXss: an RCE vulnerability in Azure Service Fabric Explorer

Categories: Exploits and vulnerabilities

Categories: News

Tags: Azure

Tags: Microsoft

Tags: Super FabriXss

Tags: RCE

Tags: vulnerability

Tags: CVE-2023-23383

Researchers disclosed how they found a remote code execution vulnerability in Azure Service Fabric Explorer.

(Read more…)

The post Super FabriXss: an RCE vulnerability in Azure Service Fabric Explorer appeared first on Malwarebytes Labs.

Read more

Update Android now! Two critical vulnerabilities patched

Categories: Android

Categories: News

Tags: Android

Tags: 2023-03-05

Tags: RCE

Tags: EoP

Tags: CVE-2023-20951

Tags: CVE-2023-20954

Tags: CVE-2022-33213

Tags: CVE-2022-33256

Tags: CVE-2021-33655

The March security updates for Android include fixes for two critical remote code execution (RCE) vulnerabilities. Update as soon as you can!

(Read more…)

The post Update Android now! Two critical vulnerabilities patched appeared first on Malwarebytes Labs.

Read more

Update now! Proof of concept code to be released for Zoho ManageEngine vulnerability

Categories: Exploits and vulnerabilities

Categories: News

Tags: Zoho

Tags: ManageEngine

Tags: PoC

Tags: RCE

Tags: CVE-2022-47966

Tags: CVE-2022-35405

Tags: SAML

Tags: Apache Santuario

Proof of Concept code is about to be released for a vulnerability in many ManageEngine products which could enable RCE with SYSTEM privileges.

(Read more…)

The post Update now! Proof of concept code to be released for Zoho ManageEngine vulnerability appeared first on Malwarebytes Labs.

Read more