CVE-2024-21407: Hyper-V remote code execution
Patch the Hyper-V vulnerability that allows escape from a guest virtual machine to the host operating system.
The pulse of your infrastructure. The screen for threats.
Ubuntu Server, Windows Server, Proxmox VE, Plesk, FortiGate / FortiOS and 6 more platforms — vulnerabilities, critical patches and release news on a single screen: verified and actionable.
Patch the Hyper-V vulnerability that allows escape from a guest virtual machine to the host operating system.
Hardening updates were released for web interface session management and CSRF validations.
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
A buffer overflow in the dynamic loader allows obtaining root privileges via GLIBC_TUNABLES.
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.
A vulnerability in the Common Log File System driver was actively used in Nokoyanya ransomware operations.
A bug in the pipe mechanism allows overwriting of read-only files and can lead to root privileges.
The Onyx series lifecycle is complete; remaining licenses are recommended to be upgraded to the Obsidian 18 line.
The notorious vulnerability in the Print Spooler service; kept permanently under control on Domain Controllers with Point and Print restrictions.
The legendary CVSS 10.0 vulnerability enabling impersonation of a Domain Controller — enforcement mode active.
The SMBv1 protocol has been permanently disabled across the entire server fleet to mitigate the SMBv1 vulnerability exploited by WannaCry.
Vulnerabilities and release notes for the platforms you follow, in one email every morning. You choose which platforms to track, and you can leave at any time.
Already subscribed? Manage your preferences