Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Facebook X (Twitter) Instagram
    Tech Empire Solutions
    • Home
    • Cloud
    • Cyber Security
    • Technology
    • Business Solution
    • Tech Gadgets
    Tech Empire Solutions
    Home » Ivanti releases emergency fix for critical Sentry RCE vulnerability
    Cyber Security

    Ivanti releases emergency fix for critical Sentry RCE vulnerability

    techempireBy techempire1 Comment2 Mins Read
    Facebook Twitter Pinterest Telegram LinkedIn Tumblr WhatsApp Email
    Share
    Facebook Twitter LinkedIn Pinterest Telegram Email

    ReportMarch 21, 2024Editorial DepartmentVulnerabilities/Cyber ​​Security

    Sentry RCE vulnerability

    Ivanti has disclosed details of a critical remote code execution flaw affecting Standalone Sentry, urging customers to apply the fix immediately to protect against potential cyber threats.

    Tracked as CVE-2023-41724the vulnerability has a CVSS score of 9.6.

    “An unauthenticated threat actor could execute arbitrary commands on the underlying operating system of a device within the same physical or logical network,” the company said.

    Internet security

    This flaw affects all supported versions 9.17.0, 9.18.0 and 9.19.0 as well as older versions. The company said it has made a patch available (versions 9.17.1, 9.18.1 and 9.19.1), which can be downloaded through the standard download portal.

    It commended Vincent Hutsebaut, Pierre Vivegnis, Jerome Nokin, Roberto Suggi Liverani and Antonin B. of the NATO Cyber ​​Security Center for their “collaboration on this issue.”

    Ivanti stressed that it was not aware of any customers being affected by CVE-2023-41724, adding that “threat actors without a valid TLS client certificate registered with EPMM would not be able to exploit this issue directly on the Internet.”

    According to Mandiant, the recently disclosed Ivanti software security vulnerability has been exploited by at least three different cyber espionage clusters suspected of being linked to China, namely UNC5221, UNC5325 and UNC3886.

    This development comes as SonarSource revealed a mutated cross-site scripting (mXSS) flaw affecting the open source email client called Mailspring aka Nylas Mail (CVE-2023-47479), which can be exploited to bypass Sandboxing and Content Security Policy (CSP) protect code execution when users reply to or forward malicious emails.

    Internet security

    “mXSS exploits this by serving up a payload that initially appears innocent when parsed (during the sanitization process), but mutates it into a malicious payload when re-parsed (during the final stage of displaying the content),” said security researcher Yaniv Nizry said.

    Did you find this article interesting?follow us Twitter  and LinkedIn to read more exclusive content from us.



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    techempire
    • Website

    Related Posts

    Ongoing campaign bombards businesses with spam emails and phone calls

    6 common mistakes organizations make when deploying advanced authentication

    New Chrome zero-day vulnerability CVE-2024-4761 is being actively exploited

    Microsoft patches 61 flaws, including two actively exploited zero-day vulnerabilities

    Dutch court sentences Tornado Cash co-founder to 5 years in prison for money laundering

    Migrate from VMware vSphere to Microsoft Azure

    Leave A Reply Cancel Reply

    Top Reviews
    Editors Picks

    Chuzo Login

    Top Cooking Websites For Food Bloggers

    Katy Perry Goes To Space!

    Mr. Meowski’s Bakery To Re-Locate In St. Charles MO

    Legal Pages
    • About Us
    • Disclaimer
    • DMCA
    • Privacy Policy
    Our Picks

    Gateway Studios High-Tech Recording Studio To Open In Chesterfield, Missouri

    Edufox

    Emerging Academic Education Platforms – Sponsored By Edufox

    Top Reviews

    Type above and press Enter to search. Press Esc to cancel.