Get a Pentest and security assessment of your IT network.

News

Microsoft fixed the Zero-Day for JET flaw, but the fix is incomplete

Experts from 0Patch revealed that the Microsoft Zero-Day Patch for JET Database Engine vulnerability (CVE-2018-8423) is incomplete. The vulnerability was discovered by the researcher Lucas Leong of the Trend Micro Security Research team that publicly disclosed an unpatched zero-day vulnerability in all supported versions of Microsoft Windows. An attacker can use specially crafted data in a database file to trigger a write past the end of an allocated buffer. The exploit requires user interaction, the attackers have to trick victims into opening a malicious file that would trigger the bug.”]

Source: https://securityaffairs.co/wordpress/77119/hacking/zero-day-patch-incomplete.html

Related posts
News

Ashley Madison 2.0 Hackers Leak 20GB Data Dump, Including CEO's Emails

News

Art of Twitter account hacking

News

BlackEnergy exploits recently fixed flaws in Siemens WinCC

News

Google Chrome will block code injection from third-party software within 14 months