[FD] Vulnerability Repot# MAMP PRO 4.2.0 Local Privilege Escalation

2020-07-24 Thread Nicholas
Hi! I have discovered a local privilege escalation vulnerability on MAMP PRO 4.2.0 and would like to post it. Please kindly check the attached file. Best regards, Nicholas # Exploit Title: MAMP PRO 4.2.0 Local Privilege Escalation # Date: 2020-07-08 # Exploit Author: b1nary # Vendor Homepage:

[FD] Defense in depth -- the Microsoft way (part 70): CVE-2014-0315 alias MS14-019 revisited

2020-07-24 Thread Stefan Kanthak
Hi @ll, This multi-part post can be read even without a MIME-compliant program! Back in 2014, I reported a vulnerability in CreateProcess()'s handling of *.cmd and *.bat files that Microsoft fixed with MS14-019 alias MSKB 299 and assigned CVE-2014-0315: command lines with a batch script as

[FD] Three vulnerabilities found in MikroTik's RouterOS

2020-07-24 Thread Q C
Advisory: three vulnerabilities found in MikroTik's RouterOS Details === Product: MikroTik's RouterOS Vendor URL: https://mikrotik.com/ Vendor Status: fixed version released CVE: - Credit: Qian Chen(@cq674350529) of Qihoo 360 Nirvan Team Product Description == RouterOS is

[FD] SEC Consult SA-20200724-0 :: Privilege Escalation Vulnerability in SteelCentral Aternity Agent

2020-07-24 Thread SEC Consult Vulnerability Lab
SEC Consult Vulnerability Lab Security Advisory < 20200724-0 > === title: Privilege Escalation Vulnerability product: SteelCentral Aternity Agent vulnerable version: 11.0.0.120 fixed v