Skip to content
Threat Feed

Tag

Remote-Execution

8 briefs RSS
high threat

Unauthenticated SQL Injection in Weaver E-cology

Weaver E-cology is vulnerable to an unauthenticated SQL injection via the 'userIdentifiers' GET parameter, allowing attackers to extract sensitive database information including administrator credentials.

E-cology web-application-vulnerability sqli remote-execution
1r 2t 1c
medium advisory

Abuse of AWS Systems Manager Session Manager for Remote Execution

Adversaries abuse AWS Systems Manager (SSM) Session Manager to gain interactive shell access and perform remote command execution on EC2 instances or managed hybrid nodes.

AWS Systems Manager +1 cloud-security remote-execution lateral-movement cloud aws discovery reconnaissance
2r 5t updated
high advisory

SSRF Vulnerability in PowerJob Transport Endpoint

PowerJob versions up to 5.1.2 contain a server-side request forgery vulnerability in the MuConnectionManager component that allows remote, unauthenticated attackers to perform unauthorized network requests.

PowerJob web-vulnerability ssrf remote-execution
1t 1c
critical advisory

Unauthenticated Denial of Service in Ground Station

Ground Station versions prior to 0.6.0 are susceptible to an unauthenticated denial-of-service vulnerability in the Socket.IO service_control event handler, allowing remote attackers to terminate critical satellite-tracking processes via a restart_service command.

Ground Station vulnerability remote-code-execution sql-injection ground-station ssrf remote-execution webserver
5t 1c updated
high advisory

FreeRDP Denial of Service via Smartcard Cache Request

A null pointer dereference vulnerability in FreeRDP prior to 3.29.0 allows remote attackers to trigger a crash in the client process via crafted smartcard cache requests.

FreeRDP +1 denial-of-service vulnerability remote-execution
2t 6c
medium advisory

Suspicious WSMAN Provider Image Loads

A detection engineering rule targets suspicious loading of Windows Management (WSMAN) provider DLLs by unusual processes, indicating potential local or remote execution and lateral movement through Windows Remote Management (WinRM) by threat actors.

lateral-movement remote-execution windows-management winrm
1r 2t
medium advisory

Incoming Execution via WinRM Remote Shell

This rule detects incoming execution via Windows Remote Management (WinRM) remote shell on a target host, which could be an indication of lateral movement by monitoring network traffic on ports 5985 or 5986 and processes initiated by WinRM.

Elastic Defend +1 lateral-movement windows winrm remote-execution
2r 1t
high advisory

Suspicious Remote Process Instantiation via WMI

Detection of wmic.exe execution with parameters indicative of spawning a process on a remote system, a technique often used for lateral movement and remote code execution.

Windows wmi lateral-movement remote-execution
2r 1t