VU#581311: TP-Link EAP Controller lacks RMI authentication and is vulnerable to deserialization attacks

The TP-LINK EAP Controller is TP-LINK’s software for remotely controlling wireless access point devices. EAP Controller for Linux lacks user authentication for RMI service commands,as well as utilizes an outdated vulnerable version of Apache commons-collections,which may allow an attacker to implement deserialization attacks and control the EAP Controller server. Continue reading VU#581311: TP-Link EAP Controller lacks RMI authentication and is vulnerable to deserialization attacks

VU#906424: Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the ALPC interface

The Microsoft Windows task scheduler SchRpcSetSecurity API contains a vulnerability in the handling of ALPC,which can allow an authenticated user to overwrite the contents of a file that should be protected by filesystem ACLs. This can be leveraged to … Continue reading VU#906424: Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the ALPC interface

Posted in Uncategorized

VU#982149: Intel processors are vulnerable to a speculative execution side-channel attack called L1 Terminal Fault (L1TF)

Speculative execution is a technique used by many modern processors to improve performance by predicting which instructions may be executed based on past execution history. When a program attempts to access data in memory,the logical memory address is … Continue reading VU#982149: Intel processors are vulnerable to a speculative execution side-channel attack called L1 Terminal Fault (L1TF)

Posted in Uncategorized

VU#598349: Automatic DNS registration and proxy autodiscovery allow spoofing of network services

Automatic DNS registration and autodiscovery functionality provides an opportunity for the misconfiguration of networks,resulting in a loss of confidentiality and integrity of the network if an attacker on the network adds a specially configured proxy device. Continue reading VU#598349: Automatic DNS registration and proxy autodiscovery allow spoofing of network services

VU#906424: Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the ALPC interface

Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the Advanced Local Procedure Call(ALPC)interface,which can allow a local user to obtain SYSTEM privileges. Continue reading VU#906424: Microsoft Windows task scheduler contains a local privilege escalation vulnerability in the ALPC interface

Posted in Uncategorized