Customize Consent Preferences

We use cookies to help you navigate efficiently and perform certain functions. You will find detailed information about all cookies under each consent category below.

The cookies that are categorized as "Necessary" are stored on your browser as they are essential for enabling the basic functionalities of the site. ... 

Always Active

Necessary cookies are required to enable the basic features of this site, such as providing secure log-in or adjusting your consent preferences. These cookies do not store any personally identifiable data.

No cookies to display.

Functional cookies help perform certain functionalities like sharing the content of the website on social media platforms, collecting feedback, and other third-party features.

No cookies to display.

Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics such as the number of visitors, bounce rate, traffic source, etc.

No cookies to display.

Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.

No cookies to display.

Advertisement cookies are used to provide visitors with customized advertisements based on the pages you visited previously and to analyze the effectiveness of the ad campaigns.

No cookies to display.

URL has been copied successfully!
CISA, FBI call software with buffer overflow issues ‘unforgivable’
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

CISA, FBI call software with buffer overflow issues ‘unforgivable’

Microsoft, VMWare, Ivanti flaws called out: The feds highlighted a list of buffer overflow bugs affecting leading vendors like Microsoft, Ivanti, VMWare, Citrix and RedHat, ranging from high to critical severity, and some already having in-the-wild exploits.The list included two Microsoft flaws that could allow, local attackers in container-based environments to gain system privileges (CVE-2025-21333), and privilege escalation on the Windows Common Log File System Driver (CLFS) that could lead to full system access (CVE-2024-49138). The latter was picked up by threat actors for zero-day exploit and was assigned a CVSS rating of 7.8/10.Most critical in the list is a VMWare vCentre flaw (CVE-2024-38812) that Broadcom had to plug for a second time in months after it admitted the first patch did not completely fix the issue. The flaw was a heap overflow issue in an implementation of the DCERPC (distributed computing environment/ remote procedure call) protocol of the vCenter server.Another critical flaw (CVSS 9/10) listed in the advisory is the stack-overflow bug in Ivanti’s Connect Secure (CVE-2025-0282) that the IT software maker fixed in January after it was exploited in zero-day attacks. While historically dependent on vulnerable coding languages like C, and C++, all these vendors are gradually moving towards memory-safe languages like Rust, Go, Swift, and Python.

First seen on csoonline.com

Jump to article: www.csoonline.com/article/3823937/cisa-fbi-call-software-with-buffer-overflow-issues-unforgivable.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link