• mehdi@mkvlab.at

VMSA-2024-0002 – VMware Aria Operations for Networks – multiple vulnerabilities

Multiple vulnerabilities in Aria Operations for Networks were responsibly reported to VMware. Updates are available to remediate these vulnerabilities in affected VMware products. CVE(s): CVE-2024-22237, CVE-2024-22238, CVE-2024-22239, CVE-2024-22240, CVE-2024-22241 Impacted Products: VMware Aria Operations for Networks (formerly vRealize Network Insight) Description: Aria Operations for Networks contains a local privilege escalation vulnerability. VMware has evaluated the severity of this issue to be […]

Exchange Server Security Updates – November 2023

Microsoft released several SUs for Microsoft Exchange Server 2016, 2019 addressing found vulnerabilities in these products. Microsoft encourages customers to apply SU due to the critical nature of these vulnerabilities. Exchange Online customers are already protected from the vulnerabilities addressed by these SUs and do not need to take any action. Microsoft has released Security Updates for vulnerabilities found in: […]

PrintNightmare – Print Spooler Remote Code Execution Vulnerability

All Windows systems are vulnerable!!! Microsoft (01.07.2021) has published the information related to  remote code execution vulnerability that affects Windows Print Spooler and has assigned CVE-2021-34527 to this vulnerability -nicknamed PrintNightmare-. A remote code execution vulnerability exists when the Windows Print Spooler service is improperly performs privileged file operations. An attacker who successfully exploited this vulnerability could run arbitrary code […]

Security Update Exchange Server 2013-2019 | Pwn2Own Vulnerability

Microsoft has released critical security update -April 2021- for on-premises Exchange Servers 2013, 2016 and 2019 to fix the following Remote Code Execution vulnerabilities: CVE-2021-28480 | Microsoft Exchange Server Remote Code Execution Vulnerability CVE-2021-28481 | Microsoft Exchange Server Remote Code Execution Vulnerability CVE-2021-28482 | Microsoft Exchange Server Remote Code Execution Vulnerability CVE-2021-28483 | Microsoft Exchange Server Remote Code Execution Vulnerability […]

Exchange Servers 0-day exploits -HAFNIUM-

On March 2, 2021 Microsoft has released several security update for Microsoft Exchange Server to address the vulnerabilities that has beed exposed targeting on-premises version of Exchange server. Microsoft has categorised this as a critical vulnerabilities and recommended the update the Exchange Server as soon as possible. The Exchange versions affected are:  NOTE: Exchange Online is not affected. also Microsoft Exchange Server 2010 […]

Check SHA1 and MD5 Hash on your Mac

SHA hashing is frequently used with distribution control systems to determine revisions and to check data integrity by detecting file corruption or tampering. For common usage, a SHA checksum provides a string that can be used to verify a file has been transferred as intended. If SHA checksums match, the integrity of the files has been maintained. Using SHA1 hash […]