-
-
Critical Privilege Escalation Vulnerability in Zoom Clients for Windows (CVE-2025-49457)
BACKGROUND
CVSS Score Base 9.6 Critical
An untrusted search path vulnerability has been found in Zoom Clients for Windows operating
system, allowing an unauthenticated attacker to escalate privileges via network access. This can
be achieved by placing a malicious DLL in a location that the Zoom client search without
specifying absolute paths. This vulnerability can lead to privilege escalation, arbitrary code
execution, and compromise of system integrity and availability.IMPACT
- Unauthorized attackers can gain elevated privileges on a target Windows system through
network exploitation. - Attackers may potentially execute arbitrary code.
- Sensitive systems may be exposed and compromised without proper authentication.
AFFECTED PRODUCTS
Product Affected Versions 1 Zoom Workplace Earlier than 6.3.10 2 Zoom Workplace VDI Earlier than 6.3.10 (except 6.1.16 & 6.2.12) 3 Zoom Rooms Earlier than 6.3.10 4 Zoom Rooms Controller Earlier than 6.3.10 5 Zoom Meeting SDK Earlier than 6.3.10
RECOMMENDATIONS- Immediately update Zoom Clients for Windows to the latest version (6.3.0 or later) that
contains the patch for this vulnerability. Latest updates can be downloaded at
https://zoom.us/download - Enable automatic updates for the Zoom client software to ensure timely patching in the
future. - Monitor network access and investigate any signs of unauthorized privilege escalation
attempts. - Review and implement network access controls to limit exposure of Zoom client
installations. - Enforce least-privilege access controls to limit the potential impact if a system is
compromised. - Install antivirus software and keep it up to date.
REFERENCES
https://www.zoom.com/en/trust/security-bulletin/zsb-25030/https://zeropath.com/blog/cve-2025-49457-zoom-untrusted-search-path-summary
https://securityonline.info/zoom-patches-critical-flaw-cve-2025-49457-windows-usersface-
privilege-escalation-risk/ - Unauthorized attackers can gain elevated privileges on a target Windows system through
-
Microsoft SharePoint Zero-Day RCE Vulnerability (CVE-2025-53770)
BACKGROUND
CVSS Score: Base 9.8 Critical
A critical remote code execution vulnerability, tracked as CVE-2025-53770, has been
actively exploited in the wild. It targets on-premises Microsoft SharePoint Server
deployments. The flaw involves deserialization of untrusted data, allowing attackers to
execute arbitrary code remotely without authentication. This vulnerability has led to
mass attacks, compromising over 75 organizations, enabling threat actors to move
laterally, persist, and blend with legitimate SharePoint activity, making detection more
difficult.Note: SharePoint Online (Microsoft 365) is not affected.
IMPACT
- Enables unauthorized attackers to execute code over a network.
- Bypasses identity controls, including Multi Factor Authentication (MFA) and Single Sign-On (SSO).
- Allows theft of MachineKey theft.
AFFECTED PRODUCTS
Affected Products Fixed Versions 1 Microsoft SharePoint Server Subscription Edition KB5002768 2 Microsoft SharePoint Server 2019 KB5002741
(16.0.10417.20027)3 Microsoft SharePoint Server 2019 Core KB5002754 4 Microsoft SharePoint Enterprise Server 2016 KB5002744
(16.0.5508.1000)5 Microsoft SharePoint Server 2016 Pending RECOMMENDATIONS
- To mitigate potential attacks, customers should:
- Use supported versions of on-premises SharePoint Server.
- Apply the latest security patches with immediate eect.
- Ensure the Antimalware Scan Interface (AMSI) is turned on and configured correctly, with an antivirus solution such as Microsoft Defender Antivirus.
- Deploy Microsoft Defender for Endpoint protection, or equivalent threat solutions
- Rotate SharePoint Server ASP.NET machine keys.
- NOTE: SharePoint Server 2016 users should monitor Microsoft’s update guidance
and apply patches once available.
REFERENCES
- https://msrc.microsoft.com/blog/2025/07/customer-guidance-for-sharepointvulnerability-
cve-2025-53770/ - https://support.microsoft.com/en-us/topic/description-of-the-security-updatefor-
sharepoint-server-2019-july-8-2025-kb5002741-d860f51b-fcdf-41e4-89de-
9ce487c06548 - https://support.microsoft.com/en-us/topic/description-of-the-security-updatefor-
sharepoint-enterprise-server-2016-july-8-2025-kb5002744-9196e240-c76d-
4bb0-b16c-6f7d6645a1f0 - https://www.microsoft.com/en-us/download/details.aspx?id=108285
- https://www.microsoft.com/en-us/download/details.aspx?id=108286
- https://www.cisa.gov/news-events/alerts/2025/07/20/microsoft-releasesguidance-
exploitation-sharepoint-vulnerability-cve-2025-53770
-
Chrome Zero-Day Vulnerability (CVE-2025-6554)
BACKGROUND
CVSS Score: Base 8.1 High
Google has released a security update to address an actively exploited zero-day vulnerability in the V8
JavaScript engine used in Google Chrome. This vulnerability enables remote code execution (RCE) if
exploited successfully.IMPACT
- May allow remote attackers to execute arbitrary code which could result in the execution of
malicious code, spyware, or conduct further system compromise. - May cause memory corruption and crashes.
AFFECTED OPERATING SYSTEMS & FIXED VERSIONS
The vulnerability affects all major platforms running Chrome, including Windows, macOS, and Linux.
Affected OS Fixed Version 1 Windows 138.0.7204.96 / 138.0.7204.97 2 Mac OS 138.0.7204.92 / 138.0.7204.93 3 Linux 138.0.7204.9 RECOMMENDATIONS
Users and administrators are advised to install the latest available Chrome updates accordingly.
REFERENCE
https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.htmlhttps://nvd.nist.gov/vuln/detail/CVE-2025-6554
- May allow remote attackers to execute arbitrary code which could result in the execution of
-
GlobalProtect: Authenticated Code Injection Through Wildcard on macOS (CVE-2025-4232)
BACKGROUND
CVSSv3 Score: Base 8.5 High
Palo Alto Networks has issued an advisory regarding a critical vulnerability, tracked as CVE-2025-4232,
affecting its GlobalProtect app on macOS.
An improper neutralization of wildcard characters exists in the log collection feature of the GlobalProtect
app. This flaw can be exploited by an authenticated but non-administrative user to execute arbitrary code
with root privileges.Exploiting this vulnerability can result in privilege escalation to root, granting the attacker full control over
the aected macOS system. This includes the ability to install programs, view, modify, or delete data, and
create new user accounts with full privileges.IMPACT
- Successful exploitation may allow privilege escalation to root access, granting the attacker full
control over the aected macOS system - Ability to install software, view, modify or delete data, and create new user accounts with full
privileges.
SYSTEMS AFFECTED
Affected Versions Affected Minor Versions Fixed Versions 1 GlobalProtect App 6.3 on
macOS6.3.0 through 6.3.2 Upgrade to 6.3.3 or later. 2 GlobalProtect App 6.2 on
macOS6.2.0 through 6.2.8-h2 Upgrade to 6.2.8-h2 [ETA June 2025] or
6.3.3 or later.3 GlobalProtect App 6.1 on
macOSUpgrade to 6.2.8-h2 [ETA June 2025] or
6.3.3 or later.4 GlobalProtect App 6.0 on
macOSUpgrade to 6.2.8-h2 [ETA June 2025] or
6.3.3 or laterRECOMMENDATIONS
- Apply updates to the aected versions as soon as possible.
- Upgrade to the fixed or latest version released by Palo Alto Networks.
REFERENCES
https://security.paloaltonetworks.com/CVE-2025-4232
- Successful exploitation may allow privilege escalation to root access, granting the attacker full
-
Phishing Attacks Leveraging Microsoft 365 Infrastructure
A new phishing campaign, including Business Email Compromise (BEC), has been discovered using Microsoft 365’s legitimate infrastructure. It poses a significant threat to user credentials and account security, leading to credential theft, data breaches, financial fraud, and malware spread.
Targeted Users:
- High-level targets
- Organizations handling sensitive data
- Users with privileged access (administrative)
- Organizations using Microsoft ADFS (Active Directory Federation Services)
- General Microsoft 365 users
Recommendations:- Implement Multi-Factor Authentication (MFA)
- Regularly review and audit Microsoft 365 tenant configuration
- Educate users about phishing tactics and security best practice
- Implement robust email and application security solutions
- Enforce sign-in risk policies
References:
https://www.securityweek.com/microsoft-365-targeted-in-new-phishing-account-takeover-attacks/
-
Phishing Attacks Leveraging Microsoft 365 Infrastructure
A new phishing campaign, including Business Email Compromise (BEC), has been discovered using Microsoft 365’s legitimate infrastructure. It poses a significant threat to user credentials and account security, leading to credential theft, data breaches, financial fraud, and malware spread.
Targeted Users:
- High-level targets
- Organizations handling sensitive data
- Users with privileged access (administrative)
- Organizations using Microsoft ADFS (Active Directory Federation Services)
- General Microsoft 365 users
Recommendations:
- Implement Multi-Factor Authentication (MFA)
- Regularly review and audit Microsoft 365 tenant configuration
- Educate users about phishing tactics and security best practice
- Implement robust email and application security solutions
- Enforce sign-in risk policies
References:
https://www.securityweek.com/microsoft-365-targeted-in-new-phishing-account-takeover-attacks/
https://www.securitymagazine.com/articles/101483-phishing-campaign-leverages-microsoft-365-infrastructure-for-attacks/ -
Critical Vulnerability on Synology Products CVE-2024-10441
BACKGROUND
CVSS Score: Base 9.8 Critical
Synology has disclosed a critical security vulnerability affecting several of its products, including Synology BeeStation Manager (BSM), Synology DiskStation Manager (DSM), and Synology Unified Controller (DSMUC).
It involves improper encoding or escaping of output vulnerabilities in the system plugin daemon within the affected products, allowing remote attackers to execute arbitrary code without user interaction.IMPACT
- Allows remote attackers to execute arbitrary code via unspecified vectors.
- Enables unauthorized file access and modification.
- Poses a significant risk of system compromise and data breaches.
Products Fixed Versions 1 BeeStation OS 1.1 Upgrade to 1.1-65374 or above 2 BeeStation OS 1.0 Upgrade to 1.1-65374 or above 3 DSM 6.2.4 Upgrade to 6.2.4-25556-8 or above 4 DSM 7.1.1 Upgrade to 7.1.1-42962-7 or above 5 DSM 7.2 Upgrade to 7.2-64570-4 or above 6 DSM 7.2.1 Upgrade to 7.2.1-69057-6 or above 7 DSM 7.2.2 Upgrade to 7.2.2-72806-1 or above 8 DSMUC 3.1.4 Upgrade to 3.1.4-23079 or above RECOMMENDATIONS
- Immediately update to the latest versions of BSM, DSM, and DSMUC.
- Implement network segmentation to limit remote access to vulnerable systems.
- Configure firewalls to restrict unnecessary network exposure.
- Regularly monitor systems and networks for signs of unauthorized access or unusual activity.
- Conduct regular vulnerability scans on Synology devices to identify and address potential security weaknesses.
REFERENCES
https://www.synology.com/en-global/security/advisory/Synology_SA_24_23 -
Critical Vulnerability in FortiSwitch (CVE-2023-37936)
CVSSv3 Score: Base 9.6 Critical
BACKGROUND
Another critical vulnerability addressed by Fortinet is CVE-2023-37936, a hard-coded cryptographic key in Fortinet FortiSwitch. This flaw allows a remote, unauthenticated attacker with access to the hard-coded key to execute unauthorized code via crafted cryptographic requests.
IMPACT
- Unauthorized code execution by exploiting the hard-coded cryptographic key flaw.
- Bypassing authentication mechanisms through crafted cryptographic requests, allowing
attackers to gain unauthorized access to the system. - Gaining control over FortiSwitch devices, potentially compromising the entire internal
network they manage. - Attackers can intercept or manipulate sensitive data transmitted through or stored on
compromised devices. - Attackers can disrupt the network by sending harmful data, changing settings, or shutting
down devices using the compromised devices.
AFFECTED PRODUCTS
Product Affected Versions 1 FortiSwitch 7.4 7.4.0 2 FortiSwitch 7.2 7.2.0 through 7.2.5 3 FortiSwitch 7.0 7.0.0 through 7.0.7 4 FortiSwitch 6.4 6.4.0 through 6.4.13 5 FortiSwitch 6.2 6.2.0 through 6.2.7 6 FortiSwitch 6.0 6.0.0 through 6.0.7 RECOMMENDATIONS
- Apply the appropriate updates provided by Fortinet to vulnerable systems after thorough
testing. - Regularly review system logs and monitor for any unauthorized access or unusual activities.
- Limit access to management interfaces and ensure they are not exposed to untrusted
networks.
REFERENCES
https://www.fortiguard.com/psirt/FG-IR-23-260
https://www.securityweek.com/fortinet-confirms-new-zero-day-exploitation/
-
Mirai Botnet Targeting Routers and Home Devices
The Mirai botnet has returned, this time targeting vulnerabilities in industrial routers, smart home
devices, and DVRs. It spreads using known flaws in internet-exposed devices.Targeted Devices:
- ASUS, Huawei, Neterbit, LB-Link, and Four-Faith industrial routers
- PZT cameras
- Kguard and Lilin DVRs, as well as generic DVRs
- Vimar smart home devices
- 5G/LTE devices
Recommendations:
- Regularly update software to patch security vulnerabilities.
- Disable remote access to devices where possible.
- Change default passwords to strong ones with at least 12 characters, using uppercase, lowercase, numbers, and symbols.
- Scan your network for security gaps.
Note: You can find steps to protect your router here:
https://www.secureverifyconnect.info/securing-your-home-wi-fi-networkReferences:
https://www.csa.gov.sg/alerts-advisories/alerts/2025/al-2025-002
https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial
routers-with-zero-day-exploits/?fbclid=IwZXh0bgNhZW0CMTEAAR3xqEgQYdW5kVB5dxsoS30gMnbBiVAXP0c6mC
KrqzQY-Q90bEiMXrtQVVo_aem_W0Wxytlx2XRUFvTt6b9ryw