TippingPoint Threat Intelligence and Zero-Day Coverage – Week of June 18, 2018

0

As I pull together the list of zero-day filters for this blog, I see all types of vulnerabilities from various vendors. My interest is always piqued when I see a vulnerability affecting a security company. The Zero Day Initiative’s (ZDI) interest was also piqued when the researcher Pagefault submitted a Bitdefender vulnerability to the ZDI bug bounty program. Most of the time, researchers who submit to ZDI will include details of the specific vulnerability they found, but Pagefault took it to the next level and provided a proof of concept exploit.

For details and in-depth analysis, you can read part 1 of the blog series that covers the vulnerability and part 2 that covers the exploit. By the way, a big thank you to Pagefault for the great write up and for Bitdefender for quickly addressing the vulnerability.

Zero-Day Filters

There are 43 new zero-day filters covering six vendors in this week’s Digital Vaccine (DV) package. A number of existing filters in this week’s DV package were modified to update the filter description, update specific filter deployment recommendation, increase filter accuracy and/or optimize performance. You can browse the list of published advisories and upcoming advisories on the Zero Day Initiative website. You can also follow the Zero Day Initiative on Twitter @thezdi and on their blog.

Adobe (2)

  • 32167: ZDI-CAN-5891: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)
  • 32169: ZDI-CAN-5892: Zero Day Initiative Vulnerability (Adobe Acrobat Pro DC)

Advantech (1)

  • 32166: HTTPS: Advantech WebAccess NMS DownloadAction Directory Traversal Vulnerability (ZDI-18-471)

Creston (20)

  • 32141: ZDI-CAN-6155: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32142: ZDI-CAN-6161: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32143: ZDI-CAN-6157: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32144: ZDI-CAN-6158: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32145: ZDI-CAN-6159: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32146: ZDI-CAN-6160: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32149: ZDI-CAN-6163: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32150: ZDI-CAN-6164: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32151: ZDI-CAN-6165: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32152: ZDI-CAN-6167: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32153: ZDI-CAN-6168: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32154: ZDI-CAN-6169: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32155: ZDI-CAN-6170: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32156: ZDI-CAN-6171: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32157: ZDI-CAN-6172: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32158: ZDI-CAN-6174: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32159: ZDI-CAN-6175: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32160: ZDI-CAN-6177: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32161: ZDI-CAN-6189: Zero Day Initiative Vulnerability (Crestron Multiple Products)
  • 32165: ZDI-CAN-6156: Zero Day Initiative Vulnerability (Crestron Multiple Products)

Fiji (13)

  • 32047: ZDI-CAN-5877: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32048: ZDI-CAN-5879: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32049: ZDI-CAN-5880: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32050: ZDI-CAN-5881: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32051: ZDI-CAN-5882: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32055: ZDI-CAN-5883: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32056: ZDI-CAN-5884: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32057: ZDI-CAN-5885: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32058: ZDI-CAN-5886: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32059: ZDI-CAN-5887: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32059: ZDI-CAN-5887: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32060: ZDI-CAN-5888: Zero Day Initiative Vulnerability (Fuji Electric V-Server)
  • 32061: ZDI-CAN-5889: Zero Day Initiative Vulnerability (Fuji Electric V-Server)

Microsoft (1)

  • 31948: SMB: Microsoft Windows SMB Client Improper Initialization Denial-of-Service (ZDI-18-166)

WECON (6)

  • 32037: ZDI-CAN-5862: Zero Day Initiative Vulnerability (WECON LeviStudioU)
  • 32040: ZDI-CAN-5866: Zero Day Initiative Vulnerability (WECON LeviStudioU)
  • 32041: ZDI-CAN-5867-5870: Zero Day Initiative Vulnerability (WECON LeviStudioU)
  • 32042: ZDI-CAN-5871: Zero Day Initiative Vulnerability (WECON LeviStudioU)
  • 32045: ZDI-CAN-5874: Zero Day Initiative Vulnerability (WECON LeviStudioU)
  • 32046: ZDI-CAN-5872: Zero Day Initiative Vulnerability (WECON LeviStudioU)

Missed Last Week’s News?

Catch up on last week’s news in my weekly recap.

Read More HERE

0