SilentGrid / Security advisories

Vulnerabilities we found, and fixed.

Offensive capability is easier to claim than to evidence. These are vulnerabilities our consultants found in commercial software and reported to the vendors, alongside exploit development against issues other researchers found. Every entry links to the write-up and, where one exists, to the vendor or CERT record that corroborates it.

Vulnerabilities we discovered

Found during research or client work, reported to the vendor, and published once a fix was available or the disclosure window had closed.

  1. The Id parameter inside the sourceItems array of the stateless map service was vulnerable to stacked queries and time-based blind injection, reachable without authentication.

    Claudio Moletta August 2021 CVE-2021-37749

    Vendor
    Hexagon
    Affected
    GeoMedia WebMap 2020
    Class
    Blind SQL injection
    Impact
    Unauthenticated database interference
  2. A flaw in the key exchange of the Commvault Communication Service (cvd) allowed crafted packets on TCP 8400 to execute arbitrary code with the highest privileges, without authentication. Tracked by the vendor as Commvault SEC0013.

    Claudio Moletta January 2020 CERT/CC VU#214283Exploit-DB 41823

    Vendor
    Commvault
    Affected
    Commvault Edge 11 SP6
    Class
    Stack-based buffer overflow
    Impact
    Unauthenticated remote code execution as root or SYSTEM
  3. Reachable remotely against the component that terminates external connections into the virtual desktop environment. Published by VMware as VMSA-2017-0008 and fixed in Unified Access Gateway 2.8.1, Horizon View 7.1.0 and 6.2.4.

    Claudio Moletta January 2020 CVE-2017-4907

    Vendor
    VMware
    Affected
    Unified Access Gateway 2.5.x–2.8.0, Horizon View 6.x and 7.x
    Class
    Heap-based buffer overflow
    Impact
    Remote code execution on the security gateway
  4. Certificate generation endpoints accepted learner and certificate identifiers straight into the query. The vendor states the issue is patched; SilentGrid was not involved in the retest.

    August 2022

    Vendor
    Global Vision Media
    Affected
    Blueprint Learning Management System
    Class
    Time-based blind SQL injection
    Impact
    Unauthenticated database access

Exploit development

Publicly known vulnerabilities taken from an advisory description to working code. The bugs are other researchers’ findings, credited in each write-up; the exploitation is ours.

  1. A full working exploit chaining the two Internet Explorer bugs below: a type confusion and a use-after-free used to defeat ASLR. Both were found by Ivan Fratric of Google Project Zero; the exploitation work is ours.

    Claudio Moletta February 2020

    Vendor
    Microsoft
    Affected
    Internet Explorer 11 ≤ 11.0.37
    Class
    Type confusion chained with a use-after-free
    Impact
    Reliable remote code execution across 32- and 64-bit targets
  2. A crafted CSS token sequence operating on a table header element. Found by Ivan Fratric of Google Project Zero; the proof-of-concept and exploitation work is ours.

    Claudio Moletta February 2020 CVE-2017-0037

    Vendor
    Microsoft
    Affected
    Internet Explorer 10 and 11, Microsoft Edge
    Class
    Type confusion in mshtml.dll
    Impact
    Remote code execution
  3. A use-after-free on a textarea text value, leaking memory. Found by Ivan Fratric of Google Project Zero; the proof-of-concept and exploitation work is ours.

    Claudio Moletta February 2020 CVE-2017-0059

    Vendor
    Microsoft
    Affected
    Internet Explorer
    Class
    Use-after-free
    Impact
    Memory disclosure, defeating ASLR for a paired bug
  4. Reconstructing a working proof of concept from the advisory text alone, against software that typically sits between operational and analytical systems.

    Claudio Moletta January 2020 CVE-2016-0450

    Vendor
    Oracle
    Affected
    Oracle GoldenGate 11.2 and 12.1.2
    Class
    Unauthenticated denial of service
    Impact
    Denial of service against a real-time data replication tier
  5. Multiple overflows in the activation and startup handlers, taken from advisory text to a working exploit.

    Claudio Moletta January 2020 CVE-2015-6946

    Vendor
    Borland
    Affected
    AccuRev, Reprise License Manager service
    Class
    Stack-based buffer overflow
    Impact
    Remote code execution

Want the detail behind one of these, or have something to disclose to us? Get in touch.

More write-ups, including engagement stories and technique research, are in the research archive.