Results for vulnerability

Threat Research

“BlueKeep” Vulnerability (CVE-2019-0708) within Cloud/Datacenter Machines: How to Safeguard Yourself?

Recently, FortiGuard Labs conducted its own research on Microsoft Azure datacenter IP ranges and found several instances of unpatched machines still vulnerable to the critical “BlueKeep” RDP vulnerability. Learn more about how to protect against this vulnerability.

By Kushal Arvind ShahJune 12, 2019

Threat Research

CVE-2019-0708 – Remote Desktop Protocol and Remote Code Execution #Bluekeep

The FortiGuard Labs SE Team has drafted a brief Threat Advisory alerting customers to immediately apply the latest patches from Microsoft for CVE-2019-0708 on any affected machines, read for more information.

By FortiGuard SE TeamMay 23, 2019

Threat Research

Detailed Analysis of macOS Vulnerability CVE-2019-8507

On March 25, 2019, Apple released macOS Mojave 10.14.4 and iOS 12.2. These two updates fixed a number of security vulnerabilities, including CVE-2019-8507 in QuartzCore (aka CoreAnimation), which was reported to Apple on January 3, 2019 using our FortiGuard Labs responsible disclosure process. Find out more in this detailed analysis of the macOS vulnerability CVE-2019-8507.

By Kai LuApril 23, 2019

Threat Research

Patch Your Adobe Shockwave Player: Fortinet Discovers Seven Zero-Day Remote Code Execution Vulnerabilities

Adobe released security bulletin APSB19-20, which patches seven Adobe Shockwave Player vulnerabilities. All of them were discovered by FortiGuard Labs researcher Honggang Ren and reported to Adobe by following Fortinet’s responsible disclosure process.

By Honggang RenApril 11, 2019

Threat Research

WordPress WooCommerce XSS Vulnerability – Hijacking a Customer Account with a Crafted Image

The FortiGuard Labs team recently discovered a Cross-Site Scripting (XSS) vulnerability in WooCommerce. WooCommerce is an open-source eCommerce platform built on WordPress.

By Zhouyuan YangMarch 04, 2019

Threat Research

Oracle VirtualBox NAT Network DoS Vulnerability

The FortiGuard Labs team recently discovered a network Denial of Service (DoS) vulnerability in Oracle VirtualBox (CVE-2019-2527).

By Zhouyuan YangJanuary 31, 2019

Threat Research

A Deep Analysis of the Microsoft Outlook Vulnerability CVE-2018-8587

This blog is a detailed analysis of a Heap Corruption vulnerability in Office Outlook assigned the vulnerability identifier CVE-2018-8587.

By Yonghui Han December 16, 2018

Threat Research

Exploiting an RCE bug in the UDP Protocol implemented in FreeRTOS

Recently, we saw a report about several bugs that were found on FreeRTOS. Curiosity got the best of us, and we started to take a look to see what can be done from the IPS side to protect our customers because of the importance of IoT devices and the popularity of this operating system.

By Amir ZaliDecember 04, 2018

Industry Trends

Predictions: AI Fuzzing and Machine Learning Poisoning

2019 Predictions from the FortiGuard Labs team reveal methods and techniques that Fortinet researchers anticipate cybercriminals will employ in the near future, along with important strategy changes that will help defend against these oncoming attacks.

By FortiGuard SE TeamNovember 15, 2018

Threat Research

Patch Your Microsoft Outlook: Fortinet Discovered Four Outlook Remote Code Execution Vulnerabilities

This Patch Tuesday, November 13, 2018, Microsoft patched six vulnerabilities discovered in Microsoft Outlook. Four of them were discovered and reported on by Fortinet researcher Yonghui Han by following Fortinet’s responsible disclosure process.

By Yonghui HanNovember 13, 2018