CVE-2024-38077: Windows Remote Desktop Licensing Service Remote Code Execution Vulnerability
Microsoft:
Exploitation less likely
Security Researchers:
Hold my beerโฆ
https://t.co/lQzxWdrTFd
So far @lemonodor has the trophy for best find... Pilots & Jets on tarmac at "31.92458, 117.66220" CN-0147 Feidong Air Base as seen from the @djiglobal@djienterprise@djisupport@djiflysafe 2017 AWS leak. https://t.co/OblNEHKlFJ
F5 BIGIP is vulnerable to a smuggling request vulnerability that an attacker can exploit to achieve unauthorized RCE. Our vulnerability research team responsibly disclose this to F5, which released a hotfix today. https://t.co/dSMv9w6ga9 #vulnerabilityresearch#f5#cve
One cool thing I didn't mention in the presentation is that you can also use the single-packet attack via Burp Repeater, even in the free edition. This should make testing & creating replication steps for triagers a bit easier!
We've just published 'Smashing the state machine: the true potential of web race conditions' by @albinowax! Dive in to arm yourself with novel techniques & tooling, and help reshape this attack class:
https://t.co/GJOOn4Wmab
If you're on an engagement, keep an eye out for the SPN HTTP/<company>.kerberos.okta.com. It provides delegated auth to Okta for a compromised AD user (and usually doesn't require MFA when proxied). https://t.co/j9ZNZXnN9T -spn HTTP/company.kerberos.okta.com.
Mad props to @_cablethief, @TH3_GOAT_FARM3R, @singe (and the rest of the @sensepost crew) for giving an awesome 4 days Wi-Fi hacking class full of realistic labs using nothing but cloud instances ! ๐คฏ
We've analyzed the patch diffs for CVE-2023-3519 (Citrix Pre-Auth RCE) and have published our findings so far on our blog post here:
https://t.co/EnmD568WFB
So far, we haven't found an endpoint where this issue is exploitable without SAML being enabled. Will update blog if we do.