CVE-2022-28810: ManageEngine ADSelfService Plus Authenticated Command Execution (Fixed)

CVE-2022-28810: ManageEngine ADSelfService Plus Authenticated Command Execution (Fixed) https://ift.tt/2zlAxGL On April 9, 2022, ManageEngine fixed CVE-2022-28810 with the release of ADSelfService Plus Build 6122. The vulnerability allowed the admin user to execute arbitrary operating system commands and potentially allowed partially authenticated Active Directory users to execute arbitrary operating system commands via the password reset functionality. […]

Cisco Releases Security Updates for Multiple Products

Cisco Releases Security Updates for Multiple Products https://ift.tt/g9v1NKn Original release date: April 14, 2022 Cisco has released security updates to address vulnerabilities in multiple Cisco products. An attacker could exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review the Cisco Security Advisories page and apply the […]

Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability

Cisco Wireless LAN Controller Management Interface Authentication Bypass Vulnerability https://ift.tt/Stu3RFU There are workarounds that addresses this vulnerability. Choose one of the following based on the environment: Option 1: No Macfilters in the Environment Customers who do not use macfilters can reset the macfilter radius compatibility mode to the default value using the following CLI command: […]

Microsoft Releases April 2022 Security Updates

Microsoft Releases April 2022 Security Updates https://ift.tt/TbZHa0n Original release date: April 12, 2022 Microsoft has released updates to address multiple vulnerabilities in Microsoft software. An attacker can exploit some of these vulnerabilities to take control of an affected system. CISA encourages users and administrators to review Microsoft’s April 2022 Security Update Summary and Deployment Information and apply […]

Step-by-Step SCCM 2203 Upgrade Guide

Step-by-Step SCCM 2203 Upgrade Guide https://ift.tt/5Xf2M04 Microsoft has released the first SCCM version for 2022. SCCM 2203 has been released on April 8th, 2022. This post is a complete step-by-step SCCM 2203 upgrade guide, meaning that if you want to upgrade your existing SCCM/MEMCM installation to the latest SCCM/MEMCM updates, this post is for you. If […]

FortiClient (Windows) – privilege escalation in online installer due to incorrect working directory

FortiClient (Windows) – privilege escalation in online installer due to incorrect working directory https://ift.tt/AWelUC9 FortiClient (Windows) – privilege escalation in online installer due to incorrect working directory Summary An improper initialization [CWE-665] vulnerability in FortiClient (Windows) may allow a local attacker to gain administrative privileges via placing a malicious executable inside the FortiClient installer’s directory. Affected Products […]