Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

New Maturing Model for Browser Security: Close the Risk of the Last Mile

Advance the optical network of the 6G revolution

CloudFlare launches a market where websites can claim AI bots for scraping

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » PostgreSQL vulnerability was exploited beyond Trust Zero-Day in a target attack
Identity

PostgreSQL vulnerability was exploited beyond Trust Zero-Day in a target attack

userBy userFebruary 14, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 14, 2025Ravi LakshmananZero Day/Vulnerability

POSTGRESQL vulnerability

According to research from Rapid7, in December 2024, zero-day vulnerability (PRA) and remote support (RS) products were found to be zero-day vulnerability (PRA) and remote support (RS) products. The threat actors behind the exploitation were likely misused.

The vulnerability tracked as CVE-2025-1094 (CVSS score: 8.1) affects the PostgreSQL interactive tool PSQL.

“Attackers who can generate SQL injections via CVE-2025-1094 can achieve arbitrary code execution (ACE) by leveraging the ability of interactive tools to execute meta commands.”

Cybersecurity

The cybersecurity company also noted that it made the discovery as part of its investigation into CVE-2024-12356.

Specifically, we found out that “the exploit of CVE-2024-12356 was successful, so we need to include the abuse of CVE-2025-1094 to achieve remote code execution.”

With a tuned disclosure, PostgreSQL maintainers have released an update to address the issue of the following versions –

PostgreSQL 17 (fixed to 17.3) PostgreSQL 16 (fixed to 16.7) PostgreSQL 15 (fixed to 15.11) PostgreSQL 14 (fixed to 14.16) PostgreSQL 13 (fixed to 13.19)

The vulnerability stems from the way PostgreSQL handles invalid UTF-8 characters, and therefore attackers exploit SQL injection by using the shortcut command “\!”, which allows shell commands to be executed. Open the door to a possible scenario.

Cybersecurity

“Attackers can take advantage of CVE-2025-1094 to execute this meta command and control the operating system shell commands that are executed,” he said. “Alternatively, an attacker who can generate SQL injections via CVE-2025-1094 can execute any attacker-controlled SQL statement.”

This development has added security flaws that affect the SimpleHelp Remote Support Software (CVE-2024-57727, CVSS score: 7.5) and has announced that the US Cybersecurity and Infrastructure Security Agency (CISA) will add security flaws that affect the SimpleHelp Remote Support Software (CVE-2024-57727, CVSS score: 7.5) and that the company has announced that it has a known exploitation vulnerability ( KEV) Request that the catalogue requires federal agencies be applied. Corrections made until March 6, 2025.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWhy are Elon Musk and Sam Altman engaged in a war of words over open alleys? | Technology News
Next Article Banana is LINE ON LINE’s DAPP portal, pioneering AI-powered data sovereignty and rewards
user
  • Website

Related Posts

New Maturing Model for Browser Security: Close the Risk of the Last Mile

July 1, 2025

Google Patch is a critical zero-day flaw in Chrome’s V8 engine after active exploitation

July 1, 2025

US arrests key facilitators in North Korea’s IT Workers Scheme and seizes $7.74 million

July 1, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

New Maturing Model for Browser Security: Close the Risk of the Last Mile

Advance the optical network of the 6G revolution

CloudFlare launches a market where websites can claim AI bots for scraping

Google Patch is a critical zero-day flaw in Chrome’s V8 engine after active exploitation

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Unlocking the Power of Prediction: The Rise of Digital Twins in the IoT World

TwinH: Digital Human Twin Aims for Victory at Break the Gap 2025

The Digital Twin Revolution: Reshaping Industry 4.0

1-inch rollout expanded bug bounty features rewards up to $500,000

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.