Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

CISA Warns of Microsoft SQL Server RCE Vulnerability Exploited in Attacks

The U. S. Cybersecurity and Infrastructure Security Agency has added a Microsoft SQL Server remote code execution vulnerability , tracked as CVE-2019-1068, to its Known Exploited Vulnerabilities catalog after confirming exploitation in attacks. The flaw affects Microsoft SQL Server and can allow an attacker to execute code under the permissions of the SQL Server Database Engine service account. CVE-2019-1068 is a remote code execution vulnerability in Microsoft SQL Server. Successful exploitation could allow an attacker to run malicious commands on a vulnerable database server, with the level of access depending on the privileges assigned to the SQL Server service account. Systems configured with highly privileged service accounts may face a greater impact because the attacker could potentially move beyond the database environment and affect the underlying Windows host.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U. S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A remote code execution vulnerability in

·The Hacker News
Read →
Vulnerabilities & Patches
Emerging1 src

CISA Adds Six Known Exploited Vulnerabilities to Catalog

CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability • CVE-2015-5287 Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability • CVE-2019-1068 Microsoft SQL Server Remote Code Execution Vulnerability • CVE-2021-23758 Ajax.NET Professional Deserialization of Untrusted Data Vulnerability • CVE-2022-0995 Linux Kernel Out-of-Bounds Write Vulnerability • CVE-2026-8452 Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise.

·CISA Alerts
Read →
Vulnerabilities & Patches
Emerging1 src

CVE-2019-1068 - Microsoft SQL Server Remote Code Execution Vulnerability

Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.

·CISA KEV
Read →

You've reached the end of current stories for this search.