Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Vulnerability postgresql used next to zero day in target attacks
Global Security

Vulnerability postgresql used next to zero day in target attacks

AdminBy AdminFebruary 14, 2025No Comments2 Mins Read
PostgreSQL Vulnerability
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


February 14, 2025Red LakshmananZero day / vulnerability

Vulnerability postgresql

The threatening subjects that stood in favor of operating vulnerability with zero day in products with privileged remote access (PRA) and remote support (RS) in December 2024. Probably also used an unknown SQL injection in Postgresql, according to the results Rapid7.

Vulnerability tracked as Cve-2025-1094 (CVSS assessment: 8.1) affects the interactive PostgreSQL PSQL tool.

“The attacker who can create SQL injection via CVE-2025-1094 can reach an arbitrary code (ACE) using the interactive tool’s ability to launch meta co-coat,” Stephen’s less security researcher – Note.

Cybersecurity

Next, the cybersecurity campaign noted that it made a discovery within its investigation Cve-2014-12356Recently fixed lack of safety in the logleTrust software that allows you to implement the distance code.

In particular, it turned out that “a successful feat for the CVE-2014-12356 must include the CVe-2025-1094 operation to achieve the remote code.”

In the coordinated disclosure of information support postgresql liberated Update to solve the problem in the following versions –

  • PostgreSQL 17 (recorded at 17.3)
  • PostgreSQL 16 (fixed at 16.7)
  • PostgreSQL 15 (fixed in 15.11)
  • PostgreSQL 14 (recorded in 14.16)
  • PostgreSQL 13 (fixed in 13.19)

The vulnerability follows from how PostgreSQL treats the invalid UTF-8 characters, opening the door to the script when the attacker can use SQL injection using A using A Fast Access Team “\!”that allows you to execute the Shell command.

Cybersecurity

“The attacker can use the CVE-2025-1094 to perform this met high, thus controlling the operating system, which is executed,” said less. “Alternatively, an attacker who can create an SQL injection via CVE-2025-1094 can fulfill arbitrary applications for SQL-controlled attacker.”

Development occurs as a cybersecurity and infrastructure agency (CISA) added Lack of security that affects the Simplehelp remote support (Cve-2024-57727CVSS assessment: 7.5) to known exploited vulnerabilities (Ship) A catalog that requires federal agencies to apply by March 6, 2025.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025

V0 AI Vercel tool, armed with cybercrime for quick creation pages to enter scale

July 2, 2025

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025

US Sanctions of Russia

July 2, 2025

V0 AI Vercel tool, armed with cybercrime for quick creation pages to enter scale

July 2, 2025

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025

A new drawback in the IDES as a Visual Studio code allows for malicious bypassing bypassing the verified status

July 1, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

North Korean Hackers Target Web3 with malicious NIM software and use Clickfix in Babyshark

July 2, 2025

Hackers using PDFs to get yourself for Microsoft, Docusign and more in phishing campaigns return call

July 2, 2025

This network traffic looks legal but it can hide a serious threat

July 2, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.