Skip to main content
  • Critical Privilege Escalation Vulnerability in Zoom Clients for Windows (CVE-2025-49457)

    BACKGROUND

    CVSS Score Base 9.6 Critical

    An untrusted search path vulnerability has been found in Zoom Clients for Windows operating
    system, allowing an unauthenticated attacker to escalate privileges via network access. This can
    be achieved by placing a malicious DLL in a location that the Zoom client search without
    specifying absolute paths. This vulnerability can lead to privilege escalation, arbitrary code
    execution, and compromise of system integrity and availability.

    IMPACT

    • Unauthorized attackers can gain elevated privileges on a target Windows system through
      network exploitation.
    • Attackers may potentially execute arbitrary code.
    • Sensitive systems may be exposed and compromised without proper authentication.

    AFFECTED PRODUCTS

     Product Affected Versions
    1Zoom WorkplaceEarlier than 6.3.10
    2Zoom Workplace VDIEarlier than 6.3.10 (except 6.1.16 & 6.2.12)
    3Zoom RoomsEarlier than 6.3.10
    4Zoom Rooms ControllerEarlier than 6.3.10
    5Zoom Meeting SDKEarlier than 6.3.10


    RECOMMENDATIONS

    • Immediately update Zoom Clients for Windows to the latest version (6.3.0 or later) that
      contains the patch for this vulnerability. Latest updates can be downloaded at
      https://zoom.us/download
    • Enable automatic updates for the Zoom client software to ensure timely patching in the
      future.
    • Monitor network access and investigate any signs of unauthorized privilege escalation
      attempts.
    • Review and implement network access controls to limit exposure of Zoom client
      installations.
    • Enforce least-privilege access controls to limit the potential impact if a system is
      compromised.
    • Install antivirus software and keep it up to date.

    REFERENCES


    https://www.zoom.com/en/trust/security-bulletin/zsb-25030/

    https://zeropath.com/blog/cve-2025-49457-zoom-untrusted-search-path-summary

    https://securityonline.info/zoom-patches-critical-flaw-cve-2025-49457-windows-usersface-
    privilege-escalation-risk/

     

  • Microsoft SharePoint Zero-Day RCE Vulnerability (CVE-2025-53770)

    BACKGROUND

    CVSS Score: Base 9.8 Critical

    A critical remote code execution vulnerability, tracked as CVE-2025-53770, has been
    actively exploited in the wild. It targets on-premises Microsoft SharePoint Server
    deployments. The flaw involves deserialization of untrusted data, allowing attackers to
    execute arbitrary code remotely without authentication. This vulnerability has led to
    mass attacks, compromising over 75 organizations, enabling threat actors to move
    laterally, persist, and blend with legitimate SharePoint activity, making detection more
    difficult.

    Note: SharePoint Online (Microsoft 365) is not affected.

    IMPACT

    • Enables unauthorized attackers to execute code over a network.
    • Bypasses identity controls, including Multi Factor Authentication (MFA) and Single Sign-On (SSO).
    • Allows theft of MachineKey theft.

    AFFECTED PRODUCTS

     Affected ProductsFixed Versions
    1Microsoft SharePoint Server Subscription EditionKB5002768
    2Microsoft SharePoint Server 2019KB5002741
    (16.0.10417.20027)
    3Microsoft SharePoint Server 2019 CoreKB5002754
    4Microsoft SharePoint Enterprise Server 2016KB5002744
    (16.0.5508.1000)
    5Microsoft SharePoint Server 2016Pending

    RECOMMENDATIONS

    • To mitigate potential attacks, customers should:
    • Use supported versions of on-premises SharePoint Server.
    • Apply the latest security patches with immediate e􀆯ect.
    • Ensure the Antimalware Scan Interface (AMSI) is turned on and configured correctly, with an antivirus solution such as Microsoft Defender Antivirus.
    • Deploy Microsoft Defender for Endpoint protection, or equivalent threat solutions
    • Rotate SharePoint Server ASP.NET machine keys.
    • NOTE: SharePoint Server 2016 users should monitor Microsoft’s update guidance
      and apply patches once available.

    REFERENCES

  • Chrome Zero-Day Vulnerability (CVE-2025-6554)

    BACKGROUND


    CVSS Score: Base 8.1 High
     

    Google has released a security update to address an actively exploited zero-day vulnerability in the V8
    JavaScript engine used in Google Chrome. This vulnerability enables remote code execution (RCE) if
    exploited successfully.

    IMPACT

    • May allow remote attackers to execute arbitrary code which could result in the execution of
      malicious code, spyware, or conduct further system compromise.
    • May cause memory corruption and crashes.

    AFFECTED OPERATING SYSTEMS & FIXED VERSIONS

    The vulnerability affects all major platforms running Chrome, including Windows, macOS, and Linux.

     Affected OSFixed Version
    1Windows138.0.7204.96 / 138.0.7204.97
    2Mac OS138.0.7204.92 / 138.0.7204.93
    3Linux138.0.7204.9

    RECOMMENDATIONS

    Users and administrators are advised to install the latest available Chrome updates accordingly.

    REFERENCE
    https://chromereleases.googleblog.com/2025/06/stable-channel-update-for-desktop_30.html

    https://nvd.nist.gov/vuln/detail/CVE-2025-6554

     

     

  • GlobalProtect: Authenticated Code Injection Through Wildcard on macOS (CVE-2025-4232)

    BACKGROUND


    CVSSv3 Score: Base 8.5 High


    Palo Alto Networks has issued an advisory regarding a critical vulnerability, tracked as CVE-2025-4232,
    affecting its GlobalProtect app on macOS.

    An improper neutralization of wildcard characters exists in the log collection feature of the GlobalProtect
    app. This flaw can be exploited by an authenticated but non-administrative user to execute arbitrary code
    with root privileges.

    Exploiting this vulnerability can result in privilege escalation to root, granting the attacker full control over
    the a􀆯ected macOS system. This includes the ability to install programs, view, modify, or delete data, and
    create new user accounts with full privileges.

    IMPACT

    • Successful exploitation may allow privilege escalation to root access, granting the attacker full
      control over the a􀆯ected macOS system
    • Ability to install software, view, modify or delete data, and create new user accounts with full
      privileges.

    SYSTEMS AFFECTED

     Affected VersionsAffected Minor VersionsFixed Versions
    1GlobalProtect App 6.3 on
    macOS
    6.3.0 through 6.3.2Upgrade to 6.3.3 or later.
    2GlobalProtect App 6.2 on
    macOS
    6.2.0 through 6.2.8-h2Upgrade to 6.2.8-h2 [ETA June 2025] or
    6.3.3 or later.
    3GlobalProtect App 6.1 on
    macOS
     Upgrade to 6.2.8-h2 [ETA June 2025] or
    6.3.3 or later.
    4GlobalProtect App 6.0 on
    macOS
     Upgrade to 6.2.8-h2 [ETA June 2025] or
    6.3.3 or later

    RECOMMENDATIONS

    • Apply updates to the a􀆯ected versions as soon as possible.
    • Upgrade to the fixed or latest version released by Palo Alto Networks.
       

    REFERENCES

    https://security.paloaltonetworks.com/CVE-2025-4232

     

  • Phishing Attacks Leveraging Microsoft 365 Infrastructure

    A new phishing campaign, including Business Email Compromise (BEC), has been discovered using Microsoft 365’s legitimate infrastructure. It poses a significant threat to user credentials and account security, leading to credential theft, data breaches, financial fraud, and malware spread.

    Targeted Users:

    • High-level targets
    • Organizations handling sensitive data
    • Users with privileged access (administrative)
    • Organizations using Microsoft ADFS (Active Directory Federation Services)
    • General Microsoft 365 users


    Recommendations:

    • Implement Multi-Factor Authentication (MFA)
    • Regularly review and audit Microsoft 365 tenant configuration
    • Educate users about phishing tactics and security best practice
    • Implement robust email and application security solutions
    • Enforce sign-in risk policies
       

    References:

    https://www.securityweek.com/microsoft-365-targeted-in-new-phishing-account-takeover-attacks/

    https://www.securitymagazine.com/articles/101483-phishing-campaign-leverages-microsoft-365-infrastructure-for-attacks/

     

  • Phishing Attacks Leveraging Microsoft 365 Infrastructure

    A new phishing campaign, including Business Email Compromise (BEC), has been discovered using Microsoft 365’s legitimate infrastructure. It poses a significant threat to user credentials and account security, leading to credential theft, data breaches, financial fraud, and malware spread.

    Targeted Users:

    • High-level targets
    • Organizations handling sensitive data
    • Users with privileged access (administrative)
    • Organizations using Microsoft ADFS (Active Directory Federation Services)
    • General Microsoft 365 users
       

    Recommendations:

    • Implement Multi-Factor Authentication (MFA)
    • Regularly review and audit Microsoft 365 tenant configuration
    • Educate users about phishing tactics and security best practice
    • Implement robust email and application security solutions
    • Enforce sign-in risk policies
       

    References:

    https://www.securityweek.com/microsoft-365-targeted-in-new-phishing-account-takeover-attacks/
    https://www.securitymagazine.com/articles/101483-phishing-campaign-leverages-microsoft-365-infrastructure-for-attacks/

  • Critical Vulnerability on Synology Products CVE-2024-10441

    BACKGROUND
     

    CVSS Score: Base 9.8 Critical
    Synology has disclosed a critical security vulnerability affecting several of its products, including Synology BeeStation Manager (BSM), Synology DiskStation Manager (DSM), and Synology Unified Controller (DSMUC).
    It involves improper encoding or escaping of output vulnerabilities in the system plugin daemon within the affected products, allowing remote attackers to execute arbitrary code without user interaction.

    IMPACT

    • Allows remote attackers to execute arbitrary code via unspecified vectors.
    • Enables unauthorized file access and modification.
    • Poses a significant risk of system compromise and data breaches.
     ProductsFixed Versions
    1BeeStation OS 1.1Upgrade to 1.1-65374 or above
    2BeeStation OS 1.0Upgrade to 1.1-65374 or above
    3DSM 6.2.4Upgrade to 6.2.4-25556-8 or above
    4DSM 7.1.1Upgrade to 7.1.1-42962-7 or above
    5DSM 7.2Upgrade to 7.2-64570-4 or above
    6DSM 7.2.1Upgrade to 7.2.1-69057-6 or above
    7DSM 7.2.2Upgrade to 7.2.2-72806-1 or above
    8DSMUC 3.1.4Upgrade to 3.1.4-23079 or above

    RECOMMENDATIONS

    • Immediately update to the latest versions of BSM, DSM, and DSMUC.
    • Implement network segmentation to limit remote access to vulnerable systems.
    • Configure firewalls to restrict unnecessary network exposure.
    • Regularly monitor systems and networks for signs of unauthorized access or unusual activity.
    • Conduct regular vulnerability scans on Synology devices to identify and address potential security weaknesses.

     

    REFERENCES

    https://www.synology.com/en-global/security/advisory/Synology_SA_24_23

    https://securityonline.info/cve-2024-10441-cvss-9-8-synology-patches-critical-code-execution-flaw-in-multiple-products/

     

  • Critical Vulnerability in FortiSwitch (CVE-2023-37936)

    CVSSv3 Score: Base 9.6 Critical

    BACKGROUND

    Another critical vulnerability addressed by Fortinet is CVE-2023-37936, a hard-coded cryptographic key in Fortinet FortiSwitch. This flaw allows a remote, unauthenticated attacker with access to the hard-coded key to execute unauthorized code via crafted cryptographic requests.

    IMPACT 

    • Unauthorized code execution by exploiting the hard-coded cryptographic key flaw.
    • Bypassing authentication mechanisms through crafted cryptographic requests, allowing 
      attackers to gain unauthorized access to the system.
    • Gaining control over FortiSwitch devices, potentially compromising the entire internal 
      network they manage.
    • Attackers can intercept or manipulate sensitive data transmitted through or stored on 
      compromised devices.
    • Attackers can disrupt the network by sending harmful data, changing settings, or shutting 
      down devices using the compromised devices.

    AFFECTED PRODUCTS

     ProductAffected Versions
    1FortiSwitch 7.47.4.0
    2FortiSwitch 7.27.2.0 through 7.2.5
    3FortiSwitch 7.07.0.0 through 7.0.7
    4FortiSwitch 6.46.4.0 through 6.4.13
    5FortiSwitch 6.26.2.0 through 6.2.7
    6FortiSwitch 6.06.0.0 through 6.0.7

    RECOMMENDATIONS

    • Apply the appropriate updates provided by Fortinet to vulnerable systems after thorough 
      testing.
    • Regularly review system logs and monitor for any unauthorized access or unusual activities.
    • Limit access to management interfaces and ensure they are not exposed to untrusted 
      networks.

    REFERENCES

    https://www.fortiguard.com/psirt/FG-IR-23-260 

    https://www.securityweek.com/fortinet-confirms-new-zero-day-exploitation/

     

  • Mirai Botnet Targeting Routers and Home Devices

    The Mirai botnet has returned, this time targeting vulnerabilities in industrial routers, smart home 
    devices, and DVRs. It spreads using known flaws in internet-exposed devices.

    Targeted Devices: 

    • ASUS, Huawei, Neterbit, LB-Link, and Four-Faith industrial routers
    • PZT cameras
    • Kguard and Lilin DVRs, as well as generic DVRs
    • Vimar smart home devices
    • 5G/LTE devices

    Recommendations: 

    • Regularly update software to patch security vulnerabilities.
    • Disable remote access to devices where possible.
    • Change default passwords to strong ones with at least 12 characters, using uppercase, lowercase, numbers, and symbols.
    • Scan your network for security gaps.

    Note: You can find steps to protect your router here: 
    https://www.secureverifyconnect.info/securing-your-home-wi-fi-network

    References: 

    https://www.csa.gov.sg/alerts-advisories/alerts/2025/al-2025-002 

    https://www.bleepingcomputer.com/news/security/new-mirai-botnet-targets-industrial
    routers-with-zero-day-exploits/?fbclid=IwZXh0bgNhZW0CMTEAAR3xqEgQYdW5kVB5dxsoS30gMnbBiVAXP0c6mC
    KrqzQY-Q90bEiMXrtQVVo_aem_W0Wxytlx2XRUFvTt6b9ryw

About

Brunei Computer Emergency Response Team (BruCERT) was established in 2004 as the national and government CERT to deal with computer-related and internet-related security incidents in Negara Brunei Darussalam.