The Girlfriend’s Sister [Uncut]U.S. Cybersecurity and Infrastructure Security Agency (CISA) has just added new exploits to its actively exploited list, as first noticed by BleepingComputer.
CISA's actions basically serve as a warning to U.S. federal agencies about vulnerabilities currently being exploited in the wild.
One exploit being tracked, CVE-2023-20118, allows hackers to remotely "execute arbitrary commands" on certain VPN routers. These routers include Cisco Small Business Routers RV016, RV042, RV042G, RV082, RV320, and RV325.
"An attacker could exploit this vulnerability by sending a crafted HTTP request to the web-based management interface," CISA wrote. "A successful exploit could allow the attacker to gain root-level privileges and access unauthorized data."
In order to take advantage of this exploit, an attacker would need admin credentials. However, as BleepingComputer points out, hackers could take advantage of another vulnerability, CVE-2023-20025, in order to bypass authentication.
Another vulnerability added by CISA is CVE-2018-8639. This bug affects a broad swath of Windows operating systems including Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, and Windows 10 Servers.
According to CISA, this vulnerability "exists in Windows when the Win32k component fails to properly handle objects in memory." A bad actor with local access to the vulnerable system can utilize the exploit to run arbitrary code in kernel mode. BleepingComputer reports that a bad actor could use this vulnerability to "alter data or create rogue accounts with full user rights to take over vulnerable Windows devices."
Microsoft and Cisco have not yet released their own security warning regarding these two exploits.
Topics Cybersecurity
Huawei Mate 10 Pro is looking pretty in new leakBoyfriend of the Year swaps shoes with girlfriend whose heels were hurting herAntarctica's massive Larsen C iceberg looks different in daylightIs 'Star Trek Discovery' worth subscribing to CBS All Access?'The Walking Dead' Season 8 will explore Negan's backstoryHow Do Not Disturb While Driving works in iOS 11'The Simpsons' premiere ended with an appeal for aid in Puerto RicoLinkedIn is rolling out SnapchatApple pushes out iOS 11 update to patch "crackling" iPhone 8 issueAmerican Airlines ups its pillow game by tossing in a mattress pad, duvetJared and Ivanka had a third private email accountIn defense of the anticlimactic 'Rick and Morty' Season 3 finaleLinkedIn is rolling out SnapchatFacebook's data'Super Smash Bros. Melee' is starting to outgrow its controllersIn defense of the anticlimactic 'Rick and Morty' Season 3 finaleGoogle algorithm fail puts 4chan's wrongly named Las Vegas gunman on top of searchPeople are demanding that the Las Vegas attack be labeled as an act of terrorismHuawei Mate 10 Pro is looking pretty in new leakBoyfriend of the Year swaps shoes with girlfriend whose heels were hurting her DeepSeek reveals cost Best Prime Day gaming deals 2024: Save on games, accessories, and more TSMC nears 2nm rollout with per wafer prices climbing to $30,000 · TechNode iPhone 16 Pro may finally get a pink Tencent Q1 profit rises 14% as AI investment begins to pay off · TechNode Toyota's China joint venture partners with Huawei and Xiaomi in EV push · TechNode Huawei chairman Xu Zhijun calls for new growth drivers in the telecom industry · TechNode Best headphones deal: Get Sony WH Best Prime Day laptop deals 2024: MacBooks, gaming laptops, and more Xpeng in talks with Volkswagen and more over use of its AI chip, CEO says · TechNode Best Roomba deals at Amazon: Combo j9+ and more at record low prices Xpeng partners with Huawei for what it calls “the world’s best head Luo Yonghao's digital avatar draws over 13 million viewers in AI Xiaomi unveils self NetEase to launch mobile adaptation of survival game Frostpunk tomorrow · TechNode When does Prime Day start? Amazon's sale is live now. Qualcomm’s third Over 1TB of data stolen from Disney internal Slack, allegedly by anti DJI’s car tech unit raises new funds from Chinese automakers GAC and BAIC · TechNode The best noise
2.0918s , 10107.7421875 kb
Copyright © 2025 Powered by 【Girlfriend’s Sister [Uncut]】,Co-creation Information Network