Skip to main content

Security Advisories

A collection of security advisories disclosed by Evolved Threat researchers.

Apple Music Arbitrary JavaScript Execution

MEDIUM CVE-2024-23829
By Dominik Penner

DESCRIPTION

A vulnerability in Apple Music for Windows allows arbitrary JavaScript execution through maliciously crafted content.

AFFECTING

  • Apple Music • TBD for Windows

BYOB (Bring Your Own Botnet) Unauthenticated Remote Code Execution

HIGH CVE-2024-45256
By chebuya

DESCRIPTION

An unauthenticated remote code execution vulnerability in BYOB (Bring Your Own Botnet) allows attackers to execute arbitrary code.

AFFECTING

  • BYOB (Bring Your Own Botnet) • All versions

Havoc C2 Team Server Unauthenticated SSRF

HIGH CVE-2024-41570
By chebuya

DESCRIPTION

An unauthenticated Server-Side Request Forgery (SSRF) vulnerability in Havoc C2 Team Server allows attackers to make arbitrary HTTP requests.

AFFECTING

  • Havoc C2 Team Server • All versions

Pexip Infinity Connect Arbitrary JavaScript Execution

MEDIUM CVE-2024-25973
By Dominik Penner & Jake Bolam

DESCRIPTION

A vulnerability in Pexip Infinity Connect allows arbitrary JavaScript execution through the application's interface.

AFFECTING

  • Pexip Infinity Connect • 1.13.0 for Windows, macOS, Linux, Android, iOS

CHAOS RAT Multiple Remote Code Execution Vulnerabilities

HIGH CVE-2024-30850 CVE-2024-31839
By chebuya

DESCRIPTION

Multiple remote code execution vulnerabilities in CHAOS RAT allow attackers to execute arbitrary code on affected systems.

AFFECTING

  • CHAOS RAT • All versions

Maltego XML External Entity Injection

MEDIUM CVE-2020-35707
By Dominik Penner

DESCRIPTION

A vulnerability in Maltego allows XML external entity injection attacks through malformed input.

AFFECTING

  • Maltego • 4.2.12