#arbitrarycodeexecution

2025-05-10

speedrunners should try to get arbitrary code execution working on an ant colony

🛡 H3lium@infosec.exchange/:~# :blinking_cursor:​H3liumb0y@infosec.exchange
2024-09-06

Critical Kibana Vulnerability - Arbitrary Code Execution via YAML Deserialization

Date: September 5, 2024

CVE: CVE-2024-37285

Vulnerability Type: Deserialization of Untrusted Data

CWE: [[CWE-502]]

Sources: Elastic Security Advisory

Synopsis

CVE-2024-37285 impacts Kibana versions 8.10.0 to 8.15.0, where a deserialization flaw allows remote code execution if an attacker injects malicious YAML payloads. This vulnerability requires that an attacker has elevated Elasticsearch and Kibana privileges.

Issue Summary

The vulnerability arises from improper YAML deserialization within Kibana. A malicious actor can craft a YAML payload and execute arbitrary code, provided they have specific Elasticsearch index and Kibana privileges. This issue affects Kibana from versions 8.10.0 through 8.15.0 and is critical due to its ease of exploitation and the potential for widespread impact.

Technical Key Findings

Attackers exploit this flaw by submitting a specially crafted YAML document that Kibana deserializes without proper validation. Once the malicious code is parsed, it can run on the server with elevated privileges, enabling arbitrary code execution.

The attacker must have the following Elasticsearch indices permissions;

  • write access to system indices .kibana_ingest*
  • The allow_restricted_indices flag needs to be set to true

The attacker must also have ANY of the following Kibana privileges;

  • Under Fleet the All privilege is granted
  • Under Integration the Read or All privilege is granted
  • Access to the fleet-setup privilege is gained through the Fleet Server’s service account token## Vulnerable Products
  • Kibana versions 8.10.0 to 8.15.0.

Impact Assessment

Successful exploitation could allow an attacker to execute arbitrary commands, leading to a complete system compromise. This could affect confidentiality, integrity, and availability, making it a high-risk issue for organizations relying on Kibana for data visualization and exploration.

Patches or Workaround

Upgrading to Kibana version 8.15.1 resolves this vulnerability. Additionally, limiting access to Elasticsearch indices and restricting Kibana privileges reduces exposure.

Tags

#CVE-2024-37285 #Kibana #ArbitraryCodeExecution #YAML #Deserialization #ElasticStack #CyberSecurity

2023-09-08

dnSpyEX contributors (Elliesaur and @washi) has discovered critical security concern involving arbitrary code execution. If you are .NET (software) reverse engineer, you should update to this new release:
github.com/dnSpyEx/dnSpy/relea
#vulnerability #arbitrarycodeexecution

2020-12-11

Security Issues in PoS Terminals Open Consumers to Fraud - Point-of-sale terminal vendors Verifone and Ingenico have issued mitigations after researchers fou... threatpost.com/security-issues #arbitrarycodeexecution #ingenicotelium2series #includeverifonevx520 #verifonemxseries #vulnerabilities #defaultpassword #pointofsale #posterminal #ingenico #password #verifone

2020-12-08

Adobe Warns Windows, macOS Users of Critical-Severity Flaws - Adobe fixed three critical-severity flaws in Adobe Prelude, Adobe Experience Manager and Adobe Lig... threatpost.com/adobe-windows-m #blindserver-siderequestforgery #adobeexperiencemanager #arbitrarycodeexecution #vulnerabilities #adobelightroom #cve-2020-24440 #cve-2020-24444 #cve-2020-24445 #cve-2020-24447 #vulnerability #adobeprelude #criticalflaw #windows #adobe #macos

2020-11-03

Adobe Warns Windows, MacOS Users of Critical Acrobat and Reader Flaws - The critical-severity Adobe Acrobat and Reader vulnerabilities could enable arbitrary code executi... threatpost.com/adobe-windows-m #november2020patchupdate #securityvulnerabilities #arbitrarycodeexecution #adobeacrobatandreader #informationdisclosure #acrobatandreader #vulnerabilities #cve-2020-24430 #cve-2020-24435 #cve-2020-24436 #cve-2020-24437 #criticalbugs

2020-10-13

Authentication Bug Opens Android Smart-TV Box to Data Theft - The streaming box allows arbitrary code execution as root, paving the way to pilfering social-medi... threatpost.com/authentication- #localprivilegeescalation #arbitrarycodeexecution #securityvulnerability #androiddebugbridge #vulnerabilities #websecurity #commandline #serialport #set-topbox #sick.codes #hindotech #critical #hk1tvbox #smarttv #root #uart #iot

2020-09-15

IBM Spectrum Protect Plus Security Open to RCE - Two bugs (CVE-2020-4703 and CVE-2020-4711) in IBM's Spectrum Protect Plus data-storage protection ... threatpost.com/ibm-flaws-spect #arbitrarycodeexecution #remotecodeexecution #spectrumprotectplus #pathtraversalflaw #highseverityflaw #vulnerabilities #cve-2020-4470 #cve-2020-4703 #cve-2020-4711 #ibmspectrum #patch #ibm

2020-09-14

TikTok Fixes Flaws That Opened Android App to Compromise - The flaws are disclosed as Oracle reportedly partners with TikTok as concerns in the U.S. over spy... threatpost.com/tiktok-android- #arbitrarycodeexecution #vulnerabilities #mobilesecurity #appsecurity #appprivacy #googleplay #datatheft #mobileapp #tiktokapp #android #tiktok #update

2020-07-29

Billions of Devices Impacted by Secure Boot Bypass - The "BootHole" bug could allow cyberattackers to load malware, steal information and move laterall... more: threatpost.com/billions-of-dev #arbitrarycodeexecution #securityvulnerability #vulnerabilities #bufferoverflow #cve-2020-10713 #bootloader #secureboot #eclypsium #microsoft #boothole #bypass #grub2 #linux #iot #bug

2020-06-18

Adobe drops slew of critical patches - Adobe released another set of patches for its products on Tuesday, a week after dropping its first... more: nakedsecurity.sophos.com/2020/ #arbitrarycodeexecution #adobecampaignclassic #adobeaftereffects #adobeillustrator #adobeaudition #premiererush #criticalcve #premierepro #adobe

2020-04-28
2020-02-13

Dell fixes privilege elevation bug in support software - Users of Dell SupportAssist should patch their software immediately to fix a software bug that cou... more: nakedsecurity.sophos.com/2020/ #arbitrarycodeexecution #dynamic-linklibraries #securitythreats #vulnerability #supportassist #update #patch #dell #bug #dll

Client Info

Server: https://mastodon.social
Version: 2025.04
Repository: https://github.com/cyevgeniy/lmst