Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Vulnerability postgresql used next to zero day in target attacks
Global Security

Vulnerability postgresql used next to zero day in target attacks

AdminBy AdminFebruary 14, 2025No Comments2 Mins Read
PostgreSQL Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 14, 2025Red LakshmananZero day / vulnerability

Vulnerability postgresql

The threatening subjects that stood in favor of operating vulnerability with zero day in products with privileged remote access (PRA) and remote support (RS) in December 2024. Probably also used an unknown SQL injection in Postgresql, according to the results Rapid7.

Vulnerability tracked as Cve-2025-1094 (CVSS assessment: 8.1) affects the interactive PostgreSQL PSQL tool.

“The attacker who can create SQL injection via CVE-2025-1094 can reach an arbitrary code (ACE) using the interactive tool’s ability to launch meta co-coat,” Stephen’s less security researcher – Note.

Cybersecurity

Next, the cybersecurity campaign noted that it made a discovery within its investigation Cve-2014-12356Recently fixed lack of safety in the logleTrust software that allows you to implement the distance code.

In particular, it turned out that “a successful feat for the CVE-2014-12356 must include the CVe-2025-1094 operation to achieve the remote code.”

In the coordinated disclosure of information support postgresql liberated Update to solve the problem in the following versions –

  • PostgreSQL 17 (recorded at 17.3)
  • PostgreSQL 16 (fixed at 16.7)
  • PostgreSQL 15 (fixed in 15.11)
  • PostgreSQL 14 (recorded in 14.16)
  • PostgreSQL 13 (fixed in 13.19)

The vulnerability follows from how PostgreSQL treats the invalid UTF-8 characters, opening the door to the script when the attacker can use SQL injection using A using A Fast Access Team “\!”that allows you to execute the Shell command.

Cybersecurity

“The attacker can use the CVE-2025-1094 to perform this met high, thus controlling the operating system, which is executed,” said less. “Alternatively, an attacker who can create an SQL injection via CVE-2025-1094 can fulfill arbitrary applications for SQL-controlled attacker.”

Development occurs as a cybersecurity and infrastructure agency (CISA) added Lack of security that affects the Simplehelp remote support (Cve-2024-57727CVSS assessment: 7.5) to known exploited vulnerabilities (Ship) A catalog that requires federal agencies to apply by March 6, 2025.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025

Silver Fox Apt has on target Taiwan with sophisticated GH0Stcringe and Holdinghands Rats Malicious Programs

June 17, 2025

Google warns about scattered spider attacks focused on IT -commander by US insurance firms

June 17, 2025

Password “B” in Sitecore XP Sparks Sparks Erriss RCE when deploying businesses

June 17, 2025

Are you forgotten accounts of advertising services that leave you risk?

June 17, 2025

New Flodrix Botnet Option Operates Langflow Ai Server RCE BUG to launch DDOS ATTACKS

June 17, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Google Chrome Zero-Day Cve-2025-2783 is operated by Taxoff to expand Trinper Backdoor

June 17, 2025

Langsmith Bug can expose the Openai keys and users’ data through malicious agents

June 17, 2025

How to protect backups

June 17, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.