Blog | G5 Cyber Security

Vulnerability Spotlight: Multiple vulnerabilities in Aspose APIs

Cisco Talos recently discovered multiple remote code execution vulnerabilities in various Aspose APIs. Aspose provides a series of APIs for manipulating or converting a large family of document formats. These vulnerabilities exist in APIs that help process PDFs, Microsoft Word files and more. An attacker could exploit these vulnerabilities by sending a specially crafted, malicious file to the target and trick them into opening it while using the corresponding API. The following SNORT rules will detect exploitation attempts. The following rules are subject to change pending additional vulnerability information.”]

Source: https://blog.talosintelligence.com/2019/08/aspose-APIs-RCE-vulns-aug-2019.html

Exit mobile version