SilentGrid / Security advisories
Vulnerabilities we found, and fixed.
Offensive capability is easier to claim than to evidence. These are vulnerabilities our consultants found in commercial software and reported to the vendors, alongside exploit development against issues other researchers found. Every entry links to the write-up and, where one exists, to the vendor or CERT record that corroborates it.
Vulnerabilities we discovered
Found during research or client work, reported to the vendor, and published once a fix was available or the disclosure window had closed.
-
Hexagon GeoMedia WebMap 2020 blind SQL injection
CVE-2021-37749The Id parameter inside the sourceItems array of the stateless map service was vulnerable to stacked queries and time-based blind injection, reachable without authentication.
- Vendor
- Hexagon
- Affected
- GeoMedia WebMap 2020
- Class
- Blind SQL injection
- Impact
- Unauthenticated database interference
-
Commvault Edge remote code execution
VU#214283A flaw in the key exchange of the Commvault Communication Service (cvd) allowed crafted packets on TCP 8400 to execute arbitrary code with the highest privileges, without authentication. Tracked by the vendor as Commvault SEC0013.
- Vendor
- Commvault
- Affected
- Commvault Edge 11 SP6
- Class
- Stack-based buffer overflow
- Impact
- Unauthenticated remote code execution as root or SYSTEM
-
Reachable remotely against the component that terminates external connections into the virtual desktop environment. Published by VMware as VMSA-2017-0008 and fixed in Unified Access Gateway 2.8.1, Horizon View 7.1.0 and 6.2.4.
- Vendor
- VMware
- Affected
- Unified Access Gateway 2.5.x–2.8.0, Horizon View 6.x and 7.x
- Class
- Heap-based buffer overflow
- Impact
- Remote code execution on the security gateway
-
Certificate generation endpoints accepted learner and certificate identifiers straight into the query. The vendor states the issue is patched; SilentGrid was not involved in the retest.
- Vendor
- Global Vision Media
- Affected
- Blueprint Learning Management System
- Class
- Time-based blind SQL injection
- Impact
- Unauthenticated database access
Exploit development
Publicly known vulnerabilities taken from an advisory description to working code. The bugs are other researchers’ findings, credited in each write-up; the exploitation is ours.
-
A full working exploit chaining the two Internet Explorer bugs below: a type confusion and a use-after-free used to defeat ASLR. Both were found by Ivan Fratric of Google Project Zero; the exploitation work is ours.
- Vendor
- Microsoft
- Affected
- Internet Explorer 11 ≤ 11.0.37
- Class
- Type confusion chained with a use-after-free
- Impact
- Reliable remote code execution across 32- and 64-bit targets
-
CVE-2017-0037: Internet Explorer and Edge type confusion
CVE-2017-0037A crafted CSS token sequence operating on a table header element. Found by Ivan Fratric of Google Project Zero; the proof-of-concept and exploitation work is ours.
- Vendor
- Microsoft
- Affected
- Internet Explorer 10 and 11, Microsoft Edge
- Class
- Type confusion in mshtml.dll
- Impact
- Remote code execution
-
A use-after-free on a textarea text value, leaking memory. Found by Ivan Fratric of Google Project Zero; the proof-of-concept and exploitation work is ours.
- Vendor
- Microsoft
- Affected
- Internet Explorer
- Class
- Use-after-free
- Impact
- Memory disclosure, defeating ASLR for a paired bug
-
CVE-2016-0450: Oracle GoldenGate denial of service
CVE-2016-0450Reconstructing a working proof of concept from the advisory text alone, against software that typically sits between operational and analytical systems.
- Vendor
- Oracle
- Affected
- Oracle GoldenGate 11.2 and 12.1.2
- Class
- Unauthenticated denial of service
- Impact
- Denial of service against a real-time data replication tier
-
Multiple overflows in the activation and startup handlers, taken from advisory text to a working exploit.
- Vendor
- Borland
- Affected
- AccuRev, Reprise License Manager service
- Class
- Stack-based buffer overflow
- Impact
- Remote code execution