SafeBreach discovers yet another privilege escalation vulnerability on a security product. The flaw has similar grounds and method of exploitation as with last week’s news about Trend Micro. The root cause is again the lack of control in the DLL loading path and the absence of certificate validation. As reported by SafeBreach Labs and its security researcher, Peleg Hadar, … [Read more...] about BitDefender Antivirus Free 2020 Vulnerable to Privilege Escalation Attacks
Vulnerable
Google’s OpenWeave and Nest Cameras Vulnerable to Takeover Attacks
Talos researchers discovered eight flaws that plague Nest IQ Indoor and the weaver binary. The attacks are not entirely easy or simple to carry out with success, but they are still possible. Users are urged to apply the latest patch that fixed all eight of the reported security flaws. Cisco Talos researchers Lilith Wyatt and Claudio Bozzato have discovered multiple security … [Read more...] about Google’s OpenWeave and Nest Cameras Vulnerable to Takeover Attacks
Trend Micro Password Manager Vulnerable to Privilege Escalation Attacks
Trend Micro Password Manager version 5.0 is found to be plagued by a privilege escalation flaw. An attacker could use an unsigned arbitrary DLL to execute code as a privileged user through the app. This would result in a complete Windows system takeover with incredibly serious consequences. If you are using the Trend Micro Password Manager v5.0 standalone, or the one that is … [Read more...] about Trend Micro Password Manager Vulnerable to Privilege Escalation Attacks
DSLR Cameras Are Vulnerable to Ransomware Attacks via WiFi
Researchers present a novel way to perform a successful ransomware attack against DSLR cameras. The method involves the PTP functionality that is there to help send photos from the device to a computer. There’s a way to push a malicious firmware update on the camera and encrypt all of its files. We tend to think that DSLR cameras are somewhat locked down electronics that … [Read more...] about DSLR Cameras Are Vulnerable to Ransomware Attacks via WiFi
