Published Vulnerabilities

Thu
18
Dec

IBackup v10.0.0.45 suffers from a local Privilege Escalation Vulnerability

IBackup v10.0.0.45 suffers from a local Privilege Escalation Vulnerability

The indepndent vulnerability laboratory researcher `Hadji Samir ` discovered a local privilege escalation web vulnerability in the official Pro Softnet Corporation iBackup v10.x software. The issue exploits a local server vulnerability in the root path of the software to compromise the system by gaining higher system access privileges.

The `ibservice` service for windows could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the system. A successful attempt would require the local user to be able to insert their code in the system root path undetected by the OS or other security applications where it could potentially be executed during application startup or reboot. If successful, the local user`s code would execute with the elevated privileges of the application.

Tue
16
Dec

Apple iOS v8.x - Message Context & Privacy Vulnerability demonstrated in Wickr App

Apple iOS v8.x - Local Message Context & Privacy Vulnerability demonstrated in Wickr App

Due to some tests in the mobile vulnerability lab the german researcher Benjamin Kunz Mejri discovered a privacy issue in connection with a glitch. The issue allows to merge the message select context menu ahead to an application task even if the task requires an auth. The researcher reported the vulnerability to the apple product security team as responsible disclosure issue.

Technical Details

Pages

Subscribe to RSS - Published Vulnerabilities