{"id":12646,"date":"2018-06-22T07:00:13","date_gmt":"2018-06-22T15:00:13","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2018\/06\/22\/news-6414\/"},"modified":"2018-06-22T07:00:13","modified_gmt":"2018-06-22T15:00:13","slug":"news-6414","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2018\/06\/22\/news-6414\/","title":{"rendered":"TippingPoint Threat Intelligence and Zero-Day Coverage \u2013 Week of June 18, 2018"},"content":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 22 Jun 2018 13:51:39 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/08\/TippingPoint-300x205.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/08\/TippingPoint.jpg 300w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/08\/TippingPoint-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>As I pull together the list of zero-day filters for this blog, I see all types of vulnerabilities from various vendors. My interest is always piqued when I see a vulnerability affecting a security company. The Zero Day Initiative\u2019s (ZDI) interest was also piqued when the researcher Pagefault submitted a Bitdefender vulnerability to the ZDI bug bounty program. Most of the time, researchers who submit to ZDI will include details of the specific vulnerability they found, but Pagefault took it to the next level and provided a proof of concept exploit.<\/p>\n<p>For details and in-depth analysis, you can read <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2018\/6\/19\/analyzing-an-integer-overflow-in-bitdefender-av-part-1-the-vulnerability\">part 1<\/a> of the blog series that covers the vulnerability and <a href=\"https:\/\/www.zerodayinitiative.com\/blog\/2018\/6\/21\/analyzing-an-integer-overflow-in-bitdefender-av-part-2-the-exploit\">part 2<\/a> that covers the exploit. By the way, a big thank you to Pagefault for the great write up and for Bitdefender for quickly addressing the <a href=\"https:\/\/www.zerodayinitiative.com\/advisories\/ZDI-17-942\/\">vulnerability<\/a>.<\/p>\n<p><strong>Zero-Day Filters<\/strong><\/p>\n<p>There are 43 new zero-day filters covering six vendors in this week\u2019s Digital Vaccine (DV) package. A number of existing filters in this week\u2019s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and\/or optimize performance. You can browse the list of <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/published\/\">published advisories<\/a> and <a href=\"http:\/\/www.zerodayinitiative.com\/advisories\/upcoming\/\">upcoming advisories<\/a> on the <a href=\"http:\/\/www.zerodayinitiative.com\/\">Zero Day Initiative<\/a> website. You can also follow the Zero Day Initiative on Twitter <a href=\"https:\/\/twitter.com\/thezdi\">@thezdi<\/a> and on their <a href=\"https:\/\/www.zerodayinitiative.com\/blog\">blog<\/a>.<\/p>\n<p><strong><em>Adobe (2)<\/em><\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li>32167: ZDI-CAN-5891: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)<\/li>\n<li>32169: ZDI-CAN-5892: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><em>Advantech (1)<\/em><\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li>32166: HTTPS: Advantech WebAccess NMS DownloadAction Directory Traversal Vulnerability (ZDI-18-471)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><em>Creston (20)<\/em><\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li>32141: ZDI-CAN-6155: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32142: ZDI-CAN-6161: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32143: ZDI-CAN-6157: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32144: ZDI-CAN-6158: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32145: ZDI-CAN-6159: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32146: ZDI-CAN-6160: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32149: ZDI-CAN-6163: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32150: ZDI-CAN-6164: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32151: ZDI-CAN-6165: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32152: ZDI-CAN-6167: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32153: ZDI-CAN-6168: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32154: ZDI-CAN-6169: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32155: ZDI-CAN-6170: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32156: ZDI-CAN-6171: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32157: ZDI-CAN-6172: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32158: ZDI-CAN-6174: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32159: ZDI-CAN-6175: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32160: ZDI-CAN-6177: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32161: ZDI-CAN-6189: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<li>32165: ZDI-CAN-6156: Zero Day Initiative Vulnerability (Crestron Multiple Products)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><em>Fiji (13)<\/em><\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li>32047: ZDI-CAN-5877: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32048: ZDI-CAN-5879: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32049: ZDI-CAN-5880: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32050: ZDI-CAN-5881: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32051: ZDI-CAN-5882: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32055: ZDI-CAN-5883: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32056: ZDI-CAN-5884: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32057: ZDI-CAN-5885: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32058: ZDI-CAN-5886: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32059: ZDI-CAN-5887: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32059: ZDI-CAN-5887: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32060: ZDI-CAN-5888: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<li>32061: ZDI-CAN-5889: Zero Day Initiative Vulnerability (Fuji Electric V-Server)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><em>Microsoft (1)<\/em><\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li>31948: SMB: Microsoft Windows SMB Client Improper Initialization Denial-of-Service (ZDI-18-166)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong><em>WECON (6)<\/em><\/strong><\/p>\n<table>\n<tbody>\n<tr>\n<td width=\"20px\"><\/td>\n<td>\n<ul>\n<li>32037: ZDI-CAN-5862: Zero Day Initiative Vulnerability (WECON LeviStudioU)<\/li>\n<li>32040: ZDI-CAN-5866: Zero Day Initiative Vulnerability (WECON LeviStudioU)<\/li>\n<li>32041: ZDI-CAN-5867-5870: Zero Day Initiative Vulnerability (WECON LeviStudioU)<\/li>\n<li>32042: ZDI-CAN-5871: Zero Day Initiative Vulnerability (WECON LeviStudioU)<\/li>\n<li>32045: ZDI-CAN-5874: Zero Day Initiative Vulnerability (WECON LeviStudioU)<\/li>\n<li>32046: ZDI-CAN-5872: Zero Day Initiative Vulnerability (WECON LeviStudioU)<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<tr>\n<td height=\"10px\"><\/td>\n<td><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>Missed Last Week\u2019s News?<\/strong><\/p>\n<p>Catch up on last week\u2019s news in my <a href=\"https:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-and-zero-day-coverage-week-of-june-11-2018\/\">weekly recap<\/a>.<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-and-zero-day-coverage-week-of-june-18-2018\/\">TippingPoint Threat Intelligence and Zero-Day Coverage \u2013 Week of June 18, 2018<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n<p><a href=\"https:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-and-zero-day-coverage-week-of-june-18-2018\/\" target=\"bwo\" >http:\/\/feeds.trendmicro.com\/TrendMicroSimplySecurity<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><strong>Credit to Author: Elisa Lippincott (TippingPoint Global Product Marketing)| Date: Fri, 22 Jun 2018 13:51:39 +0000<\/strong><\/p>\n<p><img loading=\"lazy\" decoding=\"async\" width=\"300\" height=\"205\" src=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/08\/TippingPoint-300x205.jpg\" class=\"webfeedsFeaturedVisual wp-post-image\" alt=\"\" style=\"float: left; margin-right: 5px;\" srcset=\"https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/08\/TippingPoint.jpg 300w, https:\/\/blog.trendmicro.com\/wp-content\/uploads\/2017\/08\/TippingPoint-125x85.jpg 125w\" sizes=\"auto, (max-width: 300px) 100vw, 300px\" \/><\/p>\n<p>As I pull together the list of zero-day filters for this blog, I see all types of vulnerabilities from various vendors. My interest is always piqued when I see a vulnerability affecting a security company. The Zero Day Initiative\u2019s (ZDI) interest was also piqued when the researcher Pagefault submitted a Bitdefender vulnerability to the ZDI&#8230;<\/p>\n<p>The post <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\/tippingpoint-threat-intelligence-and-zero-day-coverage-week-of-june-18-2018\/\">TippingPoint Threat Intelligence and Zero-Day Coverage \u2013 Week of June 18, 2018<\/a> appeared first on <a rel=\"nofollow\" href=\"https:\/\/blog.trendmicro.com\"><\/a>.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10413],"tags":[11414,18755,18816,18255,18817,10516,10384,714,18610,10415],"class_list":["post-12646","post","type-post","status-publish","format-standard","hentry","category-security","category-trendmicro","tag-adobe","tag-advantech","tag-creston","tag-digital-vaccine","tag-fuji-electric","tag-microsoft","tag-network","tag-security","tag-wecon","tag-zero-day-initiative"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12646","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=12646"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/12646\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=12646"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=12646"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=12646"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}