Remove Blog Remove LAN Remove Research Remove Systems Review
article thumbnail

DNSpooq: Seven Vulnerabilities Identified in dnsmasq

Tenable

Researchers identify seven vulnerabilities in popular Domain Name System software. On January 19, researchers from the JSOF Research lab disclosed seven vulnerabilities in dnsmasq , a widely used open-source application for network infrastructure. Background. Image Source: JSOF. CVE-2020-25684. DNS Cache Poisoning.

LAN 102
article thumbnail

CVE-2020-0796: "Wormable" Remote Code Execution Vulnerability in Microsoft Server Message Block SMBv3 (ADV200005)

Tenable

Details about this vulnerability were originally disclosed accidentally in another security vendor’s blog for March’s Microsoft Patch Tuesday. Soon after their blog post was published, the vendor removed reference to the vulnerability, but security researchers already seized on its accidental disclosure. Windows Server.

Insiders

Sign Up for our Newsletter

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Trending Sources

article thumbnail

CVE-2020-1472: 'Zerologon' Vulnerability in Netlogon Could Allow Attackers to Hijack Windows Domain Controller

Tenable

Security researchers reveal how the cryptographic authentication scheme in Netlogon can be exploited to take control of a Windows domain controller (DC). On September 11, researchers at Secura published a blog post for a critical vulnerability they’ve dubbed “Zerologon.” Identifying affected systems. Background.

Windows 114
article thumbnail

Microsoft’s October 2023 Patch Tuesday Addresses 103 CVEs (CVE-2023-36563, CVE-2023-41763)

Tenable

An unauthenticated, remote attacker could exploit this vulnerability using social engineering in order to convince a target to open a link or download a malicious file and run it on the vulnerable system. Alternatively, an attacker could execute a specially crafted application to exploit the flaw after gaining access to a vulnerable system.

Windows 114
article thumbnail

Microsoft’s August 2023 Patch Tuesday Addresses 73 CVEs (CVE-2023-38180)

Tenable

While details of its exploitation were not available at the time this blog post was published, an attacker that exploits this vulnerability would be able to create a DoS condition on a vulnerable server. Tenable customers can utilize Plugin ID 174933 to identify systems that have this service running. Important CVE-2023-38180 |.NET

Windows 98
article thumbnail

CVE-2020-12695: CallStranger Vulnerability in Universal Plug and Play (UPnP) Puts Billions of Devices At Risk

Tenable

On June 8, researcher Yunus Çadirci published an advisory for CallStranger , a vulnerability in the Universal Plug and Play (UPnP) protocol. The vulnerability exists due to the ability to control the Callback header value in the UPnP SUBSCRIBE function. Operating Systems. Identifying affected systems. Background.

LAN 110
article thumbnail

Causal Machine Learning for Creative Insights

Netflix Tech

By Billur Engin , Yinghong Lan , Grace Tang , Cristina Segalin , Kelli Griggs , Vi Iyengar Introduction At Netflix, we want our viewers to easily find TV shows and movies that resonate and engage. A framework to identify the causal impact of successful visual components. Every show on our platform has multiple promotional artwork assets.