Welcome to the TrustedSec Tech Brief where Director of Security Intelligence Carlos Perez goes over the top security news for the week of August 11, 2024.
00:00 Start
00:12 Patch Tuesday
00:50 Zero-click Windows TCP/IP RCE
01:43 OpenVPN Vulns
04:00 Ivanti vTM
05:03 Zoom Vulnerabilities
06:26 News
08:01 NPM Malware GitHub
CVE-2024-38063, the Zero-click Windows TCP/IP RCE was found by Kunlun Lab's
CVE-2024-27459
CVSS: 7.8
OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.
CVE-2024-24974
CVSS: 7.5
OpenVPN 2.6.9 and earlier allows the OpenVPN service pipe to be accessed remotely, which allows a remote attacker to interact with the privileged OpenVPN interactive service.
CVE-2024-27903
CVSS: 9.8
OpenVPN 2.6.9 and earlier allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
CVE-2024-1305
CVSS: 9.8
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space
CVE-2024-7593
CVSS: 9.8
Virtual Traffic Manager (vTM) focuses on application traffic management and load balancing. has an authentication bypass.
POC available
Not actively exploited.
patches are not available for all versions yet.
https://forums.ivanti.com/s/article/S...
CVE-2024-39825
CVSS: 8.5
Buffer overflow in some Zoom Workplace Apps and Rooms Clients may allow an authenticated user to conduct an escalation of privilege via network access.
Affects Windows, MacOS, iOS and iPadOS versions
https://www.zoom.com/en/trust/securit...
CVE-2024-39818
CVSS: 7.5
Protection mechanism failure in some Zoom Workplace Apps and SDKs may allow an authenticated user to conduct information disclosure via network access.
Affects Windows, MacOS, iOS and iPadOS versions
National Public Data, a data broker appears to have been hacked and their database of personal information stolen and offered in the dark web. The information includes SSN, Criminal records and other type of personal information.
We recommend monitoring credit, given that the information is organized and sorted it will be easier to abuse by bad actors.
https://nationalpublicdata.com/Breach...
Malicious NPM Packages
The number of malicious NPM packages reported by GitHub in the recent weeks keeps rizing. This is something we should worry about given how many developers do not review code they download and deploy. In addition to typosquatings this poses a large risk for many.
https://github.com/advisories?page=1&...