Critical RCE in Ivanti Endpoint Manager, Citrix Virtual Apps & Desktops Flaws – Patch Now – SOCRadar® Cyber Intelligence Inc.

Critical RCE in Ivanti Endpoint Manager, Citrix Virtual Apps & Desktops Flaws – Patch Now – SOCRadar® Cyber Intelligence Inc.

Two recent vulnerability disclosures demand swift attention from organizations using Ivanti Endpoint Manager and Citrix Virtual Apps & Desktops. Ivanti’s latest security update addresses a critical vulnerability (CVE-2024-50330) that… Article Source https://socradar.io/critical-rce-in-ivanti-endpoint-manager-citrix-virtual-apps-desktops-flaws-patch-now/

Citrix Virtual Apps & Desktops RCE Vulnerability, PoC Exploitation Underway

Citrix Virtual Apps & Desktops RCE Vulnerability, PoC Exploitation Underway

Security researchers have disclosed critical vulnerabilities in Citrix Virtual Apps and Desktops that could allow remote code execution (RCE) attacks. Proof-of-concept (PoC) exploitation attempts have already been… Article Source https://cybersecuritynews.com/citrix-virtual-apps-desktops-rce/

Citrix Zero-Day Bug Allows Unauthenticated RCE

Citrix Zero-Day Bug Allows Unauthenticated RCE

An unpatched zero-day vulnerability in Citrix’s Session Recording Manager allows unauthenticated remote code execution (RCE, paving the way for data theft, lateral movement, and desktop takeover. According to watchTowr research out today, the… Article Source https://www.darkreading.com/cloud-security/citrix-recording-manager-zero-day-bug-unauthenticated-rce

New Flaws in Citrix Virtual Apps Enable RCE Attacks via MSMQ Misconfiguration

New Flaws in Citrix Virtual Apps Enable RCE Attacks via MSMQ Misconfiguration

Nov 12, 2024Ravie LakshmananVirtualization / Vulnerability Cybersecurity researchers have disclosed new security flaws impacting Citrix Virtual Apps and Desktop that could be exploited to achieve unauthenticated remote code execution… Article Source https://thehackernews.com/2024/11/new-flaws-in-citrix-virtual-apps-enable.html

HPE warns of critical RCE flaws in Aruba Networking access points

HPE warns of critical RCE flaws in Aruba Networking access points

Hewlett Packard Enterprise (HPE) released updates for Instant AOS-8 and AOS-10 software to address two critical vulnerabilities in Aruba Networking Access Points. The two security issues could allow a remote attacker to perform… Article Source https://www.bleepingcomputer.com/news/security/hpe-warns-of-critical-rce-flaws-in-aruba-networking-access-points/

VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability

VMware Releases vCenter Server Update to Fix Critical RCE Vulnerability

Oct 22, 2024Ravie LakshmananVulnerability / Enterprise Security VMware has released software updates to address an already patched security flaw in vCenter Server that could pave the way for remote code execution. The vulnerability,… Source link

VMware vCenter Server RCE Vulnerability Exploit Released for PoC

VMware vCenter Server RCE Vulnerability Exploit Released for PoC

A recent proof-of-concept exploit has been published for a critical vulnerability in VMware vCenter Server, designated CVE-2024-22274. This vulnerability affects the API components of the vCenter Server and has been rated as Important with a CVSSv3 base score of 7.2. The exploit targets specific API components that are vulnerable to a flag injection attack, allowing … Read more