VU#871675: WPA3 design issues and implementation vulnerabilities in hostapd and wpa_supplicant

CERT continues to review the WPA3 protocol in support of this body of research. The root cause of the numerous”implementation”vulnerabilities may involve modifying the protocol. WPA3 uses Simultaneous Authentication of Equals(SAE),also known as Dragonf… Continue reading VU#871675: WPA3 design issues and implementation vulnerabilities in hostapd and wpa_supplicant

Posted in Uncategorized

VU#465632: Microsoft Exchange server 2013 and newer are vulnerable to NTLM relay attacks

Microsoft Exchange supports a API called Exchange Web Services(EWS). One of the EWS API functions is called PushSubscriptionRequest,which can be used to cause the Exchange server to connect to an arbitrary website. Connections made using the PushSubscr… Continue reading VU#465632: Microsoft Exchange server 2013 and newer are vulnerable to NTLM relay attacks

Posted in Uncategorized

VU#289907: Microsoft Windows Kernel Transaction Manager (KTM) is vulnerable to a race condition

CWE-362:Concurrent Execution using Shared Resource with Improper Synchronization(‘Race Condition’)- CVE-2018-8611 According to Microsoft,the Windows kernel fails”to properly handle objects in memory”. A successful attacker could run arbitrary code in k… Continue reading VU#289907: Microsoft Windows Kernel Transaction Manager (KTM) is vulnerable to a race condition

Posted in Uncategorized

VU#228297: Microsoft Windows MsiAdvertiseProduct function vulnerable to privilege escalation via race condition

The Microsoft Windows MsiAdvertiseProduct function allows a Windows installer product to generate a script to advertise a product to Windows,which handles shortcut and registry information associated with an installed application. The MsiAdvertiseProdu… Continue reading VU#228297: Microsoft Windows MsiAdvertiseProduct function vulnerable to privilege escalation via race condition

Posted in Uncategorized