Skip navigation

Category Archives: Zero Day

This is said to be a heap buffer overflow flaw in the WebRTC framework according to Google.

A heap buffer overflow is a software code vulnerability that can be faulted or exploited by a bad actor, which can cause unintended consequences including a blue screen of death (BSOD, unauthorized access, or Denial of Service (DoS). The overflow generally occurs when the allotted storage capacity is exceeded by the volume of data.

More can be read at thehackernews.com here:

https://thehackernews.com/2023/12/zero-day-alert-apple-rolls-out-ios.html

https://support.apple.com/en-us/HT201222

https://thehackernews.com/2023/11/alert-microsoft-releases-patch-updates.html

There are ~2,500 MOVEit servers available on the internet as of 6/1/2023. This is still developing. There are plenty of sources out there and it looks like these attacks started as resent as 5/27/2023.

https://www.huntress.com/blog/moveit-transfer-critical-vulnerability-rapid-response

https://www.bleepingcomputer.com/news/security/new-moveit-transfer-zero-day-mass-exploited-in-data-theft-attacks/

https://www.bleepingcomputer.com/news/technology/twitter-bug-lets-legacy-verified-accounts-get-the-blue-check-back/

https://www.theregister.com/2023/04/17/chrome_emergency_patch/

Anyone else seeing other impacted products? What else is vulnerable to ” heap-based buffer overflow vulnerability [CWE-122]”

https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-citrix-adc-and-gateway-zero-day-patch-now/

https://thehackernews.com/2022/11/update-chrome-browser-now-to-patch-new.html

thehackernews.com