SecPod Labs
Security Research
In-depth CVE write-ups, vulnerability analysis, and security intelligence from the SecPod Research team.

CVE Research
Microsoft’s May 2024 Patch Tuesday: Microsoft patches three zero-days under active exploit and 61 flaws.
Microsoft released its May edition of Patch Tuesday, in which 61 vulnerabilities and three actively exploited zero days were addressed. Of the 61 vulnerabilities, 59 fall under the Important severity, while one each in the Moderate and Critical severity.

CVE Research
Adobe Critical Security Updates June 2024
In June 2024, Adobe released security updates addressing 13 critical vulnerabilities in software like Experience Manager, Adobe Commerce, Photoshop, etc. In total, 168 security flaws were patched using a patch manager. These vulnerabilities could lead to various issues, such as arbitrary code execut...

CVE Research
How to fully patch CVE-2018-3639, Speculative Store Bypass Vulnerability
January 2018 saw the rise of Meltdown and Spectre vulnerabilities concerning speculative execution side channels. A subclass of speculative execution side-channel vulnerability, termed as Speculative Store Bypass (SSB) was announced by Microsoft in collaboration with Google researchers and was assig...

CVE Research
Top 5 Vulnerability Scanners for Enterprises in 2023
Enterprises are constantly challenged to protect their data and assets from malicious attacks requiring many efforts to identify and address vulnerabilities. According to research conducted in 2022, 70% of businesses worldwide fell victim to a Ransomware attack, and only 38% of global organizations ...

CVE Research
VMWare Catches New Critical ESXi Sandbox Escape Bugs
VMWare’s latest advisory reveals four new vulnerabilities affecting its ESXi, Workstation, Fusion, and Cloud Foundation products. Each vulnerability has been patched, with support even being extended for end-of-life products – an unusual but vital decision for this unprecedented situation.

CVE Research
How to Fully Fix CVE-2017-8529, Microsoft Browser Information Disclosure Vulnerability
Microsoft has re-released a patch for CVE-2017-8529 to fix a print issue related to this vulnerability. The patch is not fully applied unless certain registry keys are set even after installing the respective Operating System patches. This article describes the steps to update registry settings to b...

CVE Research
Fortinet Fixes Actively Exploited FORTICLIENT EMS Flaw Allowing Unauthorised Code Execution
Fortinet has issued an advisory warning about a new critical vulnerability in Fortinet’s FortiClient Enterprise Management Server (EMS) software. This flaw, identified as CVE-2023-48788, has been assigned a severity score of 9.3 on the CVSS scale, underlining its potential for serious impact. Horizo...

CVE Research
Cracking the Code: Understanding Why Organizations Can’t Ignore Vulnerability Prioritization
In today’s world, organizations constantly face cyber threats and vulnerabilities that can compromise their sensitive data, disrupt operations, and damage their reputations. The biggest challenge for IT Security Teams is to handle the mountainous volumes of vulnerabilities being detected by vulnerab...

CVE Research
Discover The High Severity Heap buffer Overflow Vulnerability in cURL (CVE-2023-38545)
The cURL development team has recently disclosed a high-severity heap buffer overflow vulnerability (CVE-2023-38545), which poses a substantial risk of enabling remote code execution in applications utilizing the impacted iterations of the cURL library.
