CVE-2017-1182
published 2017-07-17CVE-2017-1182: IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default…
PriorityP274high7.5CVSS 3.0
AVAACHPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEV
Exploited in the wild
EPSS
8.54%
94.4th percentile
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring | — | — |
| ibm | tivoli_monitoring_v6 | — | — |
| ibm | tivoli_monitoring_v6 | — | — |
| ibm | tivoli_monitoring_v6 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →CVE-2017-1182 affects IBM Tivoli Monitoring Portal v6 and is exploitable by a local (network adjacent) attacker when default HTTP client-server communications are in use — monitor for unexpected command execution originating from HTTP-based Tivoli Monitoring Portal traffic on the network segment. ↗
- ·The vulnerability is only exploitable when the IBM Tivoli Monitoring Portal v6 is configured to use the default HTTP (not HTTPS) client-server communication channel; deployments using encrypted/non-default transport may not be exposed. ↗
CVSS provenance
nvdv3.07.5HIGHCVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.05.4MEDIUMAV:A/AC:M/Au:N/C:P/I:P/A:P
vulncheck7.5HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-p2fv-2h5q-jvfw: IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-serve
ghsa_unreviewed·2022-05-13
CVE-2017-1182 [HIGH] GHSA-p2fv-2h5q-jvfw: IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-serve
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.
VulnCheck
IBM Tivoli Monitoring Portal v6 HTTP Arbitrary Command Execution Vulnerability
vulncheck·2017·CVSS 7.5
CVE-2017-1182 [HIGH] IBM Tivoli Monitoring Portal v6 HTTP Arbitrary Command Execution Vulnerability
IBM Tivoli Monitoring Portal v6 HTTP Arbitrary Command Execution Vulnerability
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to execute arbitrary commands on the system, when default client-server default communications, HTTP, are being used. IBM X-Force ID: 123493.
Affected: IBM tivoli_monitoring
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if remediation or mitigations are unavailable.
Exploitation References: https://www.tenable.com/blog/daisy-chaining-how-vulnerabilities-can-be-greater-than-the-sum-of-their-parts
Exploit PoC: https://vulncheck.com/xdb/ace639ec0bc1
Exploit-DB
LibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds Read
exploitdb·2017-07-06
CVE-2017-9147 LibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds Read
LibTIFF - '_TIFFVGetField (tiffsplit)' Out-of-Bounds Read
---
Source: http://bugzilla.maptools.org/show_bug.cgi?id=2693
On 4.0.7:
# tiffsplit $FILE
==2007== Invalid read of size 4
==2007== at 0x40CD1A: _TIFFVGetField (tif_dir.c:1072)
==2007== by 0x41B2C5: TIFFVGetField (tif_dir.c:1198)
==2007== by 0x41B2C5: TIFFGetField (tif_dir.c:1182)
==2007== by 0x404CCF: tiffcp (tiffsplit.c:220)
==2007== by 0x404CCF: main (tiffsplit.c:89)
==2007== Address 0x0 is not stack'd, malloc'd or (recently) free'd
------- Comment #1 From zhangtan 2017-05-15 01:20:26 -------
The place of Out of bound read:
ret_val = 0;
for (i = 0; i td_customValueCount; i++) {
TIFFTagValue *tv = td->td_customValues + i;
if (tv->info->field_tag != tag)
continue;
------- Comment #2 From zhangtan 2017-05-15 01:29:10 ------
Exploit-DB
Microsoft Windows 7 Kernel - 'win32k!xxxClientLpkDrawTextEx' Stack Memory Disclosure
exploitdb·2017-05-15
CVE-2017-0245 Microsoft Windows 7 Kernel - 'win32k!xxxClientLpkDrawTextEx' Stack Memory Disclosure
Microsoft Windows 7 Kernel - 'win32k!xxxClientLpkDrawTextEx' Stack Memory Disclosure
---
/*
Source: https://bugs.chromium.org/p/project-zero/issues/detail?id=1182
We have discovered that it is possible to disclose portions of uninitialized kernel stack memory to user-mode applications in Windows 7 (other platforms untested) indirectly through the win32k!NtUserCreateWindowEx system call. The analysis shown below was performed on Windows 7 32-bit.
The full stack trace of where uninitialized kernel stack data is leaked to user-mode is as follows:
--- cut ---
8a993e28 82ab667d nt!memcpy+0x35
8a993e84 92c50063 nt!KeUserModeCallback+0xc6
8a994188 92c5f436 win32k!xxxClientLpkDrawTextEx+0x16b
8a9941f4 92c5f72e win32k!DT_GetExtentMinusPrefixes+0x91
8a994230 92c5f814 win32k!NeedsEndEllipsis+0x3
Tenable
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
blogs_tenable·2021-01-21
Daisy Chaining: How Vulnerabilities Can Be Greater Than the Sum of Their Parts
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Securelist
APT trends report Q3 2020
blogs_securelist·2020-11-03
APT trends report Q3 2020
Table of Contents
- The most remarkable findings
- Europe
- Russian-speaking activity
- Chinese-speaking activity
- Middle East
- Southeast Asia and Korean Peninsula
- Other interesting discoveries
- Final thoughts
Authors
- GReAT
For more than three years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q3 2020.
Readers who
Securelist
APT trends report Q3 2020
blogs_securelist·2020-11-03
APT trends report Q3 2020
Table of Contents
The most remarkable findings
Europe
Russian-speaking activity
Chinese-speaking activity
Middle East
Southeast Asia and Korean Peninsula
Other interesting discoveries
Final thoughts
Authors
GReAT
For more than three years, the Global Research and Analysis Team (GReAT) at Kaspersky has been publishing quarterly summaries of advanced persistent threat (APT) activity. The summaries are based on our threat intelligence research and provide a representative snapshot of what we have published and discussed in greater detail in our private APT reports. They are designed to highlight the significant events and findings that we feel people should be aware of.
This is our latest installment, focusing on activities that we observed during Q3 2020.
Readers who would like
Zscaler
Malspam Campaigns Use Malicious RTF Documents | Zscaler Blog
blogs_zscaler·2018-04-26·CVSS 7.8
[HIGH] Malspam Campaigns Use Malicious RTF Documents | Zscaler Blog
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
http://www.ibm.com/support/docview.wss?uid=swg22003402http://www.securitytracker.com/id/1038913https://exchange.xforce.ibmcloud.com/vulnerabilities/123493http://www.ibm.com/support/docview.wss?uid=swg22003402http://www.securitytracker.com/id/1038913https://exchange.xforce.ibmcloud.com/vulnerabilities/123493
2017-07-17
Published
Exploited in the wild