Severity Rating: HIGH

Software Affected
    Open ReadSpeaker module for Drupal 8.x version 8.x-1.x-dev

Overview
A vulnerability has been reported in Drupal, which could be exploited by a
remote attacker to add a configured ReadSpeaker button for text-to-speech
for victim site visitors.

Description
The vulnerability exists in Drupal as the module doesnt sufficiently
sanitize block configuration causing a Cross Site Scripting (XSS)
vulnerability.

Successful exploitation of this vulnerability could allow the attacker to
add a configured ReadSpeaker button for text-to-speech for victim site
visitors.

Solution
Apply appropriate patches as mentioned on Drupal website:
https://www.drupal.org/sa-contrib-2020-024

Vendor Information

Drupal
https://www.drupal.org/sa-contrib-2020-024

Severity Rating: HIGH

Software Affected

VMware Horizon Client for Windows versions prior to 5.4.3
VMware ESXi versions 6.5 and 6.7
VMware Workstation Pro / Player versions prior to 15.5.5
VMware Fusion Pro / Fusion versions prior to 11.5.5
Overview

Multiple vulnerabilities have been reported in VMware products which could
allow a local attacker to gain elevated privileges and access sensitive
information on a targeted system.

Description

1. Privilege Escalation Vulnerability ( CVE-2020-3961   ) 

This vulnerability exists in VMware Horizon Client for Windows due to
improper folder permission configuration and unsafe loading of libraries.
Successful exploitation of this vulnerability could allow an attacker with
local access to gain elevated privileges and run commands as any user on
the targeted system. 

2. Out-of-bounds read Vulnerability ( CVE-2020-3960   ) 

This vulnerability exists in VMware due to an out-of-bounds read in NVMe
functionality. 
Successful exploitation of this vulnerability could allow a local attacker
to read privileged information on the targeted system.

Solution

Update to patched versions as mentioned in the vendor advisory: 


Vendor Information
VMWare

CVE Name
CVE-2020-3960
CVE-2020-3961


Severity Rating: HIGH

Software Affected
·         IBM WebSphere Application Server versions 7.0, 8.0, 8.5, 9.0
·         IBM WebSphere Application Server ND versions 8.5, 9.0
·         IBM WebSphere Virtual Enterprise versions 7.0, 8.0

Overview
Multiple vulnerabilities have been reported in IBM WebSphere Application
Server which could allow a remote attacker to execute arbitrary code or
obtain sensitive information.

Description
1.     Remote Code Execution Vulnerability (CVE-2020-4448)
This vulnerability exists in the BroadcastMessageManager class of IBM
WebSphere Application Server Network Deployment due to improper validation
of user-supplied input. A remote attacker could exploit this vulnerability
by executing a specially-crafted sequence of serialized objects from
untrusted sources.

Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code on the target system.

2.     Remote Code Execution Vulnerability (CVE-2020-4450)
This vulnerability exists in the IIOP protocol of IBM WebSphere Application
Server due to improper validation of user-supplied input. A remote attacker
could exploit this vulnerability by executing a specially-crafted sequence
of serialized objects.

Successful exploitation of this vulnerability could allow the attacker to
execute arbitrary code on the target system.

3.     Information Disclosure Vulnerability (CVE-2020-4449)
This vulnerability exists in the IIOP protocol of IBM WebSphere Application
Server due to improper validation of user-supplied input. A remote attacker
could exploit this vulnerability by executing a specially-crafted sequence
of serialized objects.
Successful exploitation of this vulnerability could allow the attacker to
disclose sensitive information of the target system.

Solution
Contact device vendor or manufacturer for appropriate over-the-air update

Vendor Information
IBM

References
IBM

ZDI

CVE Name
CVE-2020-4448
CVE-2020-4449
CVE-2020-4450

Severity Rating: High

Systems Affected
·         WordPress versions 5.4.1 and prior

Overview
Multiple vulnerabilities have been reported in WordPress that could allow a
remote attacker to perform cross-site scripting attack, gaining elevated
privileges or sensitive information disclosure on the targeted system.

Description
These vulnerabilities exist due to insufficient sanitization of
user-supplied data, and improper impose of security restrictions. A remote
attacker could exploit these vulnerabilities by executing arbitrary script
code in user's browser.

Successful exploitation of these vulnerabilities could allow the attacker
to perform cross-site scripting attack, gaining elevated privileges or
access to sensitive information on the targeted system.

Solution
Upgrade to WordPress version 5.4.2
- -release/

Vendor Information
WordPress

- -release/

References
WordPress
- -release/
Wordfence
- -vulnerabilities/
US-CERT
- -security-and-maintenance-update

Severity rating: High

Software affected
·        Microsoft SharePoint Enterprise Server 2016
·        Microsoft SharePoint Foundation 2010 Service Pack 2
·        Microsoft SharePoint Foundation 2013 Service Pack 1
·        Microsoft SharePoint Server 2019

Overview
A vulnerability has been reported in Microsoft SharePoint Server which
could allow a remote attacker to execute arbitrary code on the targeted
system.

Description
1.  Remote Code Execution Vulnerability (CVE-2020-1181)

This vulnerability exists in Microsoft SharePoint Server due to improper
identification and filtration of unsafe ASP.Net web controls. A remote
attacker could exploit this vulnerability by using a specially crafted page
on the affected server.

Successful exploitation of this vulnerability could allow the attacker to
cause remote code execution on the targeted system.

Solution
Apply appropriate patches as mentioned in Microsoft Security Guidance

Vendor Information
Microsoft
- -1181

References
Microsoft
- -1181

CVE Name
CVE-2020-1181

Severity Rating: HIGH
Software Affected
Open Enclave SDK
Overview

A vulnerability has been reported in Open Enclave SDK which could allow
remote attacker to improperly handle objects on the targeted system.
Description

An information disclosure vulnerability exists in Open Enclave SDK due to
improper handling of objects in memory. An attacker could exploit this
vulnerability by compromising the host application running the enclave
without user interaction. 

Successful exploitation of this vulnerability could allow an attacker to
obtain information stored in the Enclave.

Solution

Apply appropriate patches as mentioned in following vendor advisory: 
- -1369

Vendor Information
Microsoft
- -1369

References

Microsoft
- -1369

CVE Name
CVE-2019-1369
Severity Rating: HIGH

Software Affected
Linux kernel through 5.3.6
Overview
Vulnerability has been reported in Linux which could allow an attacker to
access sensitive information on a targeted system.

Description

This vulnerability exists due to Realtek Wi-Fi chips model in Linux
devices. An attacker could exploit this vulnerability by rtlwifi driver
that mainly supports the Realtek Wi-Fi chips model used in Linux devices.

Successful exploitation of this vulnerability could allow an attacker to
compromise a system using nearby Wi-Fi devices.

Solution
Apply appropriate updates as mentioned in the following URL:
https://lkml.org/lkml/2019/10/16/1226
Vendor Information

Linux
https://lkml.org/lkml/2019/10/16/1226

References

Linux
https://lkml.org/lkml/2019/10/16/1226
https://arstechnica.com/information-technology/2019/10/unpatched-linux-flaw
- -may-let-attackers-crash-or-compromise-nearby-devices/

CVE Name
CVE-2019-17666

© Copyright 2020. Designed By Templateify

© Copyright 2020. Ud64

Scroll to Top