Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » PostgreSQL vulnerability was exploited beyond Trust Zero-Day in a target attack
Identity

PostgreSQL vulnerability was exploited beyond Trust Zero-Day in a target attack

userBy userFebruary 14, 2025No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

February 14, 2025Ravi LakshmananZero Day/Vulnerability

POSTGRESQL vulnerability

According to research from Rapid7, in December 2024, zero-day vulnerability (PRA) and remote support (RS) products were found to be zero-day vulnerability (PRA) and remote support (RS) products. The threat actors behind the exploitation were likely misused.

The vulnerability tracked as CVE-2025-1094 (CVSS score: 8.1) affects the PostgreSQL interactive tool PSQL.

“Attackers who can generate SQL injections via CVE-2025-1094 can achieve arbitrary code execution (ACE) by leveraging the ability of interactive tools to execute meta commands.”

Cybersecurity

The cybersecurity company also noted that it made the discovery as part of its investigation into CVE-2024-12356.

Specifically, we found out that “the exploit of CVE-2024-12356 was successful, so we need to include the abuse of CVE-2025-1094 to achieve remote code execution.”

With a tuned disclosure, PostgreSQL maintainers have released an update to address the issue of the following versions –

PostgreSQL 17 (fixed to 17.3) PostgreSQL 16 (fixed to 16.7) PostgreSQL 15 (fixed to 15.11) PostgreSQL 14 (fixed to 14.16) PostgreSQL 13 (fixed to 13.19)

The vulnerability stems from the way PostgreSQL handles invalid UTF-8 characters, and therefore attackers exploit SQL injection by using the shortcut command “\!”, which allows shell commands to be executed. Open the door to a possible scenario.

Cybersecurity

“Attackers can take advantage of CVE-2025-1094 to execute this meta command and control the operating system shell commands that are executed,” he said. “Alternatively, an attacker who can generate SQL injections via CVE-2025-1094 can execute any attacker-controlled SQL statement.”

This development has added security flaws that affect the SimpleHelp Remote Support Software (CVE-2024-57727, CVSS score: 7.5) and has announced that the US Cybersecurity and Infrastructure Security Agency (CISA) will add security flaws that affect the SimpleHelp Remote Support Software (CVE-2024-57727, CVSS score: 7.5) and that the company has announced that it has a known exploitation vulnerability ( KEV) Request that the catalogue requires federal agencies be applied. Corrections made until March 6, 2025.

Did you find this article interesting? Follow us on Twitter and LinkedIn to read exclusive content you post.

Source link

Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleWhy are Elon Musk and Sam Altman engaged in a war of words over open alleys? | Technology News
Next Article Banana is LINE ON LINE’s DAPP portal, pioneering AI-powered data sovereignty and rewards
user
  • Website

Related Posts

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

July 20, 2025

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

July 20, 2025

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

July 20, 2025
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Important unpaid SharePoint Zero-Day will be actively utilized and violated global organizations over the age of 75

Malware injected into 6 npm package after maintainer token was stolen in a phishing attack

Hackers exploit critical CrushFTP flaws to gain admin access on unearned servers

Astronomer CEO resigns following Cold Play Concert Scandal

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Next-Gen Digital Identity: How TwinH and Avatars Are Redefining Creation

BREAKING: TwinH Set to Revolutionize Legal Processes – Presented Today at ICEX Forum 2025

Building AGI: Zuckerberg Commits Billions to Meta’s Superintelligence Data Center Expansion

ICEX Forum 2025 Opens: FySelf’s TwinH Showcases AI Innovation

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2025 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.