Showing posts with label Rapid7. Show all posts
Showing posts with label Rapid7. Show all posts

Tuesday, February 9, 2021

10 Advisories Published – 2-9-21

Today CISA’s NCCIC-ICS published ten control system security advisories for products from Siemens (8), Advantech, and GE Digital. NCCIC-ICS also published 12 advisory updates for products from Siemens that I will cover in a separate post tomorrow.

DIGSI 4 Advisory

This advisory describes an incorrect default permissions vulnerability in the Siemens DIGSI 4 product. The vulnerability was reported by Rich Davy from ECSC Group. Siemens has newer versions that mitigate the vulnerability. There is no indication that Davy has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow a low privileged attacker to execute arbitrary code with SYSTEM privileges.

WinCC Advisory

This advisory describes an authentication bypass using an alternate path or channel vulnerability in the Siemens WinCC Graphics Designer. The vulnerability was reported by Enrique Murias Fernandez from Tecdesoft Automation. Siemens has an update that mitigates the vulnerability. There is no indication that Fernandez has been provided with an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker unauthenticated access to protected files.

SIMARIS Advisory

This advisory describes an incorrect default permissions vulnerability in the Siemens SIMARIS configuration electrical planning software. The vulnerability was reported by Rich Davy from ECSC Group. Siemens has provided generic workarounds for the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow an attacker to gain persistence or escalate privileges within the system.

SCALANCE Advisory

This advisory describes an allocation of resources without limits or throttling in the Siemens SCALANCE W780 and W740 family. The vulnerability is self-reported. Siemens has a new version that mitigates the vulnerability.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit this vulnerability to allow an attacker to cause a denial-of-service condition.

JT2Go Advisory

This advisory describes 21 vulnerabilities in the Siemens JT2Go and Teamcenter Visualization products. The vulnerabilities were reported by Michael DePlante (@izobashi), Francis Provencher {PRL}, and rgod via the Zero Day Initiative. Siemens has updates available that mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The 21 reported vulnerabilities are:

• Out-of-bounds read (7) - CVE-2020-26998, CVE-2020-26999, CVE-2020-27002, CVE-2020-27004, CVE-2020-27007, CVE-2020-27008, and CVE-2020-28394,

• Improper restriction of operations within the bounds of a memory buffer (3) - CVE-2020-27000, CVE-2020-27006, and CVE-2021-25174,

• Stack-based buffer overflow (3) - CVE-2020-27001, CVE-2020-26989, and CVE-2021-25178,

• Untrusted pointer dereference (3) - CVE-2020-27003, CVE-2020-26991, and CVE-2021-25176,

• Out-of-bounds write - CVE-2020-27005,

• Type confusion (2) - CVE-2020-26990 and CVE-2021-25177,

• Incorrect type conversion or cast - CVE-2021-25175,

• Memory allocation with excessive size value - CVE-2021-25173

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit these vulnerabilities to lead to arbitrary code execution.

TIA Advisory

This advisory describes an improper access control vulnerability in the Siemens TIA Portal and PCS neo products. The vulnerability was reported [link added 2-10-21 08:11 EST] by Will Dormann from CERT Coordination Center. Siemens has an update that mitigates the vulnerability. There is no indication that Dormann has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerability to allow local users to escalate privileges and execute code as a local SYSTEM user.

RUGGEDCOM Advisory

This advisory describes six vulnerabilities in the Siemens RUGGEDCOM ROX IIB products. Siemens is self-reporting these vulnerabilities. Siemens has an update that mitigates the vulnerabilities.

• Improper input validation - CVE-2018-12404,

• Null pointer dereference - CVE-2018-18508,

• Out-of-bounds write - CVE-2019-11745,

• Insufficient verification of data authenticity - CVE-2019-17006,

• Improper certificate validation - CVE-2019-17007, and

• Out-of-bounds read - CVE-2020-1763

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerabilities to allow the decryption of encrypted content, possible code execution, or cause a system crash, resulting in a denial-of-service condition.

SINEMA Advisory

This advisory describes a path traversal vulnerability in the Siemens SINEMA Server and SINEC NMS products. The vulnerability was reported by rgod via ZDI. Siemens has a new version that mitigates the vulnerability. There is no indication that rgod has been provided an opportunity to verify the efficacy of the fix.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to  allow arbitrary code execution on an affected system.

Advantech Advisory

This advisory describes four vulnerabilities in the Advantech iView device management application. The vulnerability was reported by Anonymous and rgod via ZDI, and William Vu of Rapid7. Advantech has a new version that mitigates the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The four reported vulnerabilities are:

• SQL injection (2) - CVE-2021-22654 and CVE-2021-22658,

• Path traversal - CVE-2021-22656, and

• Missing authentication for critical function - CVE-2021-22652

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit the vulnerability to allow an attacker to disclose information, escalate privileges to Administrator, perform an arbitrary file read, and remotely execute commands.

GE Digital Advisory

This advisory describes two incorrect permission assignment for critical resource vulnerability for the GE HMI/SCADA iFIX. The vulnerabilities were reported by William Knowles of Applied Risk. The GE Digital advisory also credits Sharon Brizinov of Claroty for reporting the three undescribed vulnerabilities, only one of which is apparently referenced in the NCCIC-ICS advisory. The Applied Risk advisory lists two vulnerabilities with significantly different CVSS v3 base scores; 7.8 for the Applied Risk advisory and 6.1 for the NCCIC-ICS advisory with minor differences in the vector strings.

NCCIC-ICS reports that a relatively low-skilled attacker with uncharacterized access could exploit the vulnerabilities to allow an attacker to escalate their privileges.

NOTE: I briefly discussed the GE Digital advisory this last weekend.

Other Siemens Advisory

Siemens also published one more advisory today. I will discuss that this weekend.

Tuesday, July 30, 2019

2 Advisories and 1 Alert Published – 07-30-19


Today the DHS NCCIC-ICS published a control system security alert for CAN bus network implementation in avionics and two control system security advisories for products from Prima Systems ad Wind River.

CAN Bus Alert


This alert briefly describes a public report about insecure implementation of CAN bus networks affecting aircraft. The report was published by Patrick Kiley of Rapid7.

Prima Systems Advisory


This advisory describes nine vulnerabilities in the Prima Systems FlexAir access control platform. The vulnerabilities were reported by Gjoko Krstic of Applied Risk. Prima Systems has a new version that mitigates the vulnerabilities. There is no indication that Krstic has been provided an opportunity to verify the efficacy of the fix.

The nine reported vulnerabilities are:

OS command injection - CVE-2019-7670;
Unrestricted upload of file with dangerous type (2) - CVE-2019-7669 and CVE-2019-9189;
Cross-site request forgery - CVE-2019-7281;
Small space of random values - CVE-2019-7280;
Cross-site scripting - CVE-2019-7671;
Exposure of a backup file to an unauthorized control sphere - CVE-2019-7667;
Improper authentication - CVE-2019-7666; and
Use of hard-coded credentials - CVE-2019-7672

NOTE 1: NCCIC-ICS does not include a default credentials vulnerability, CVE-2019-7668, reported by Krstic.

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow an attacker to execute commands directly on the operating system, upload malicious files, perform actions with administrative privileges, execute arbitrary code in a user’s browser, discover login credentials, bypass normal authentication, and have full system access.

NOTE 2: I briefly described the Rapid7 report back in May.

Wind River Advisory


This advisory describes eleven vulnerabilities in the Wind River VxWorks operating system. The vulnerabilities were reported by Armis researchers Gregory Vishnepolsky, Dor Zusman, and Ben Seri. Wind River has patches to mitigate the vulnerabilities. There is no indication that the researchers have been provided an opportunity to verify the efficacy of the fix.

The eleven reported vulnerabilities are:

Stack-based buffer overflow - CVE-2019-12256;
Heap-based buffer overflow - CVE-2019-12257;
Integer underflow - CVE-2019-12255;
Improper restrictions of operations within the bounds of a memory buffer (2) - CVE-2019-12260 and CVE-2019-12261;
Race condition - CVE-2019-12263;
Argument injection or modification (4) - CVE-2019-12258, CVE-2019-12262, CVE-2019-12264 and CVE-2019-12265; and
Null pointer dereference - CVE-2019-12259;

Since the affected operating systems are used in a large number of IoT and ICS systems we can expect advisories from affected vendors implementing the Wind River mitigations measures. The NCCIC-ICS advisory already lists 2 vendor advisories and the Armis report adds a third. The three vendor advisories available to date include:

Rockwell,
Xerox, and

NCCIC-ICS reports that a relatively low-skilled attacker could remotely exploit these vulnerabilities to allow remote code execution.

Tuesday, April 25, 2017

DHS Publishes Three Advisories

Today the DHS ICS-CERT published three control system security advisories for products from Hyundai Motor, Sierra Wireless and BLF-Tech.

Hyundai Motor Advisory


This advisory describes two vulnerabilities in the Hyundai Motor Blue Link. The vulnerabilities were reported by Will Hatzer and Arjun Kumar working with Rapid7. Hyundai produced a new version that mitigates the vulnerability. There is no indication that the researchers have been provided the opportunity to verify the efficacy of the fix.

The two reported vulnerabilities are:

• Man-in-the-Middle – CVE-2017-6052; and
• Use of Hard-Coded Cryptographic Key – CVE-2017-6054

ICS-CERT reports that an attacker (no characterization of the skill level is provided) could remotely exploit this vulnerability to gain access to insecurely transmitted sensitive information, which could allow the attacker to locate, unlock, and start a vehicle associated with the affected application.

NOTE: A Rapid7 blog post provides more details about the vulnerability.

Sierra Wireless Advisory


NOTE: This advisory provides additional information on vulnerabilities that were initially reported by ICS-CERT in an Alert last June.

This advisory describes three vulnerabilities in the Sierra Wireless AirLink Raven XE and XT. The vulnerabilities were reported by Karn Ganeshen. Sierra Wireless has produced new firmware that mitigates two of the three reported vulnerabilities. There is no indication that Ganeshen was provided an opportunity to verify the efficacy of the fix.

The three reported vulnerabilities were:

• Improper Authorization – CVE-2017-6044;
• Cross-Site Request Forgery – CVE-2017-6042; and
• Insufficiently Protected Credentials (Not mitigated) – CVE-2017-6046

Neither this advisory nor the Sierra Wireless Technical Bulletin [.DOC download] from last summer address the fourth vulnerability reported by Ganeshen in his disclosure; unauthenticated access to directories and arbitrary file upload.

ICS-CERT reports that a relatively unskilled attacker could use the publicly available exploits for these vulnerabilities to remotely attack these devices to perform unauthorized sensitive functions compromising the confidentiality, integrity, and availability of the affected system.

BLF-Tech Advisory


This advisory describes an uncontrolled search path element vulnerability in the BLF-Tech VisualView HMI. The vulnerability was reported by Karn Ganeshen. BLF-Tech has produced a new version to mitigate the vulnerability. There is no indication that Ganeshen was provided an opportunity to verify the efficacy of the fix.


ICS-CERT reports that a relatively unskilled attacker (access requirements not characterized) could exploit the vulnerability to to execute arbitrary code within the system.

Wednesday, October 5, 2016

ICS-CERT Publishes Medical Device Advisory

This morning the DHS ICS-CERT published a medical control system advisory for multiple vulnerabilities in the Animas OneTouch Ping insulin pump system. The vulnerabilities were reported by Jay Radcliff of Rapid7 (Note: ICS-CERT does not credit Jay, just Rapid7). Animas (a subsidiary of Johnson and Johnson) has published compensating controls, but will not (apparently) be releasing a patch or new version to mitigate the vulnerabilities. Animas is directly notifying patients and health care professionals about the vulnerabilities and compensating controls.

The vulnerabilities reported are:

• Cleartext transmission of sensitive information - CVE-2016-5084;
• Use of insufficiently random values - CVE-2016-5085; and
• Authentication bypass by capture-replay - CVE-2016-5086

While ICS-CERT reports that detailed “vulnerability information is publicly available that could be used to develop an exploit that targets these vulnerabilities”, they claim that it would take a skilled attacker to remotely exploit the vulnerabilities. This may because an RF transceiver and relatively close access (normally 10 meters) would be required to exploit these vulnerabilities.

Rapid7 published their report on these vulnerabilities on their web site on September 28th. The Animas patient letter was dated yesterday.

Commentary


I noted in a TWEET® this morning: “Inefficient but effective workarounds, how about an update to correct the problem? Or would that require complete redesign?” ICS-CERT briefly addresses this efficiency issue by noting that the “compensating controls may impact device functionality”. Radcliffe reminds us in the Rapid7 report that:

“First, know that we take risks every day. We leave the house. We drive a car. We eat a muffin. We guess the amount of carbs. All entail risk. This research uncovers a previously unknown risk. This is similar to saying that there is risk of an asteroid hitting you, a car accident occurring or miscalculating the amount of insulin for that muffin you ate. Some of those risks are low (asteroid) some are high (insulin). This knowledge of risk allows individuals to make personal decisions. Most people are at limited risk of any of the issues related to this research. These are sophisticated attacks that require being physically close to a pump. Some people will choose to see this as significant, and for that they can turn off the rf/remote features of the pump and eliminate that risk.”


Individuals can assess their personal risk that someone would conduct an attack on their person using these vulnerabilities to personally harm them by inducing hypoglycemia through an insulin overdose; most people would rate this risk of a personal attack as very low. What would be harder for an individual to assess is the risk of someone using this set of vulnerabilities to conduct an attack on Animas or Johnson and Johnson. Even a small number of publicized attacks on individual OneTouch Ping system owners could have a very serious financial impact on Johnson and Johnson in both liability costs and negative publicity costs. Individual device owners would probably have a difficult time assessing that risk to the operation of their insulin pumps. What is sad is that I suspect that Johnson and Johnson have not really evaluated the possibility of that sort of a corporate attack since their advisory letter sounds as if it had been written by the sales department, not the legal department.

Thursday, December 10, 2015

ICS-CERT Updates XZERES Advisory and Publishes 2 New Advisories

This afternoon the DHS ICS-CERT updated the XZERES advisory published earlier this week. It also published controls system advisories for products from Open Automation and Advantech.

XZERES Update

This update revises the description of the potential impact of the vulnerability. Originally it said that: “Successful exploitation of this vulnerability allows the ID to be retrieved from the browser and will allow the default ID to be changed.” Now it reads: “Successful exploitation of this vulnerability could allow the injection of malicious script.” That is a significant change in impact.

The description of the cross-site scripting vulnerability has also been changed. Originally it said: “The 442SR OS recognizes both the POST and GET methods for data input. By using the GET method, an attacker may retrieve the ID from the browser and will allow the default user ID to be changed. The default user has admin rights to the entire system.” It now reads: “The 442SR OS does not provide adequate input validation. This could allow malicious script to be injected into the program.” The CVSS v3 base score remains 9.8.

NOTE: This update is listed on the ICS-CERT landing page, but just because the original would still be there and the change was made to the original listing. I still recommend following @ICSCERT on TWITTER to get notified of these updates.

Open Automation Advisory

This advisory describes an uncontrolled search path element vulnerability in the Open Automation Software OPC Systems.NET application. The vulnerability was reported by Ivan Sanchez from Nullcode Team. ICS-CERT reports that Open Automation Software does not intend to patch the vulnerability at this time.

ICS-CERT reports that a social engineering attack is required to exploit this DLL hijacking vulnerability. A successful exploit would give the attacker access at the same privilege level as the application.

ICS-CERT reports that: “Open Automation Software has passed the researcher information to its support team to assist customers in the event that they encounter this vulnerability.”

Advantech Advisory

This advisory describes three vulnerabilities in the Advantech EKI-132x platform devices. This was an uncoordinated disclosure made by Tod Beardsley of Rapid7. Advantech plans to release updated firmware to fix these vulnerabilities by the end of this month.

The three vulnerabilities are:

• OS command injection (Shellshock) - CVE-2014-6271;
• Improper restriction of operations within the bounds of a memory buffer (Heartbleed) - CVE-2014-0160; and
• Improper restriction of operations within the bounds of a memory buffer - CVE-2012-2152

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities using publicly available exploit code to execute arbitrary code, to obtain private keys, or to impersonate the authenticated user and perform a man-in-the-middle attack.


NOTE: This is the ‘missing’ advisory that I reported on last week. Interestingly there is no mention in the advisory of the apparent fact that these vulnerabilities worked their way back into the system as part of the update to fix an earlier vulnerability.

Thursday, December 3, 2015

ICS-CERT Published Two Advisories

This afternoon the DHS ICS-CERT published to control system advisories for products from Honeywell and SearchBlox.


Honeywell Advisory

This advisory describes two vulnerabilities in the Honeywell Midas gas detector. The vulnerabilities were reported by Maxim Rupp. Honeywell has produced new firmware versions to mitigate the vulnerabilities, but there is no indication that Rupp was provided the opportunity to verify the efficacy of the fix.

The two vulnerabilities are:

• Path traversal - CVE-2015-7907; and
• Clear text transmission of sensitive information - CVE-2015-7908.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit these vulnerabilities to make unauthorized configuration changes to the device.

This advisory was originally released to the US CERT Secure Portal on November 5, 2015. Again, if you were authorized access to the Secure Portal (see the bottom of the ICS-CERT landing page for instructions on how to request access) you could have already applied the new firmware to your detectors.

Note: The link in the ICS-CERT advisory for the Honeywell Security Notice is incorrect. It should be: http://www.honeywellanalytics.com/en/support/product-notifications/midas-security-notification-firmware-update-available

SearchBlox Advisory

This advisory describes an information exposure vulnerability in the SearchBlox web-based proprietary search engine application. The vulnerability was reported by Oana Murarasu of Ixia. SearchBlox has developed a new version that mitigates the vulnerability, but there is no indication that Murarasu has been provided the opportunity to verify the efficacy of the fix.

ICS-CERT reports that a relatively unskilled attacker could remotely exploit this vulnerability to export of the config file without admin login, overwrite the config file without admin login, and add or delete (nonadmin) users.

Missing Alert?


I was really expecting to see ICS-CERT publish an alert today on the Advantech EKI vulnerabilities that were reported on Tuesday by Rapid7, especially since there is already a Metasploit module available for the vulnerabilities. The reason might be that these are actually ‘old’ vulnerabilities (Heartbleed, Shellshock and a previously reported buffer overflow) that apparently made their way back into the firmware update for the latest ICS-CERT reported advisory (ISCA-15-309-01).

Tuesday, July 8, 2014

ICS-CERT Updates ABB HeartBleed and Publishes Yokogawa Overflow

Today the DHS ICS-CERT updated a two-month old HeartBleed advisory for the ABB 650 Series application and issued a new buffer overflow advisory for Yokogawa Centum products. Yokogawa also updated an earlier advisory that has not yet been noticed by ICS-CERT.

ABB HeartBleed Update

This advisory update provides notice that ABB has produced a maintenance Release (available through customer service) that mitigates the OpenSSL bug in the 650 Series application. ABB has also updated their Cyber Security Advisory for the HeartBleed bug in their equipment. Interestingly the ABB published advisory can’t make up its mind (at the top of page 2) if the CVSS Score is 5.0 or 4.8 (not that there is much difference). ICS-CERT reports a score of 5.0.

Yokogawa Advisory

This advisory reports a single buffer stack overflow vulnerability in Yokogawa Centum products that was reported by Rapid7 in a coordinated disclosure. Yokogawa has produced a patch that mitigates the vulnerability but there is no indication in the advisory that Rapid7 has been able to verify the efficacy of the patch.

ICS-CERT reports that a moderately skilled attacker could remotely exploit this vulnerability to execute arbitrary code. Yokogawa reports that the vulnerability only is accessible when the Expanded Test Functions Package is in use.

A Yokogawa Update

While following the ICS-CERT link to the Yokogawa report referenced above, I noticed that the Company had also updated an earlier report about four buffer overflow vulnerabilities reported earlier. I don’t know why ICS-CERT is reporting on the update (yet?).


The new data in this update is found in the Table 1 list of affected products and fixes. It reports a newer patch for the CENTUM 3000, CENTUM VP, and Exaopc Server products that addresses both the earlier vulnerabilities and the one reported by ICS-CERT today. It also reports that earlier versions of ProSafe-RS that were earlier reported as having no patches available may now be corrected.

Tuesday, March 11, 2014

ICS-CERT Publishes Yokogawa Advisory

Late this afternoon the DHS ICS-CERT published an advisory for multiple buffer overflow vulnerabilities in the Yokogawa CENTUM CS 3000 application. The vulnerabilities were reported by Juan Vazquez of Rapid7 Inc and Julian Vilas Diaz in a coordinated disclosure. In a tadbit different move for a coordinated disclosure, Rapid7 has published a Metasploit module for each of the three vulnerabilities. Yokogawa has produced a patch to mitigate the vulnerabilities, but there is no indication that anyone has independently verified the efficacy of the patch.

ICS-CERT notes that three different buffer overflow vulnerabilities are involved. They include:

• Heap-based buffer overflow, BKCLogSvr.exe service, CVE-2014-0781, Metasploit;
• Stack-based buffer overflow, BKHOdeq.exe service, CVE-2014-0783, Metasploit; and
• Stack-based buffer overflow, BKBCopyD.exe service, CVE-2014-0784, Metasploit.
NOTE: These CVE links will not be active for a couple of days.

ICS-CERT reports that a relatively low skilled attacker could remotely exploit the proof-of-concept code to execute arbitrary code. Yokogawa reports that they are still investigating whether or not other systems have the same vulnerabilities.


Yokogawa reported these vulnerabilities on Friday and Rapid7 published their Metasploit modules on Monday. According to the Rapd7 Disclosure Policy, they would have notified Carnegie Mellon CERT (CERT/CC) of this vulnerability on about January 25th and Yokogawa on about January 10th. According to ICS-CERT Japan CERT (JPCERT) was also involved in the coordination process.

Thursday, March 14, 2013

ICS-CERT Updates Honeywell Advisory as Promised


Today the DHS ICS-CERT published an update of their advisory for the Honeywell Enterprise Buildings Integrator (EBI). As was mentioned in an earlier blog posting on the original advisory, Rapid7 had notified Honeywell and ICS-CERT that they would be releasing a Metasploit module for this vulnerability. This update announces that the Metasploit module has been released. The original vulnerability was reported by Juan Vazquez of Rapid7.

Friday, February 22, 2013

ICS-CERT Publishes Honeywell EBI Advisory


Late this afternoon the DHS ICS-CERT published an advisory for an ActiveX vulnerability for the Honeywell Enterprise Buildings Integrator (EBI). The vulnerability was reported by Juan Vazquez of Rapid7 in a coordinated disclosure.

The Advisory

ICS-CERT reports that a moderately skilled attacker using a social engineering attack could remotely exploit this vulnerability to execute arbitrary code on the system. ICS-CERT maintains that the need to use a social engineering attack vector “decreases the likelihood of a successful exploit” (pg 3). Recent reports on the success rates for social engineering attacks don’t seem to support that assertion.

Honeywell recommends that the HscRemoteDeploy.dll be disabled on “any client or server computers on affected systems”. They have an update package that accomplishes this, but recommend that it be only run by a “qualified, trained resource”. Honeywell has also asked Microsoft to “issue a kill bit for the HscRemoteDeploy.dll in a future monthly Microsoft Windows security update”. This will disable the DLL on any machines running the automated Windows update.

No Public Exploit Code, Yet

The advisory reports that there is no known exploit code publicly available at this time. It also notes that Rapid7 plans on releasing a Metasploit module for this vulnerability next month. This continues a trend upon which I have recently reported that white hat researchers are publishing exploit code even on coordinated disclosure vulnerabilities. Rapid 7 is more forgiving in their publication process than is Exodus Intelligence since they are giving owners a reasonable chance to install their system updates before the exploit code is published. It would be even more forgiving if they held off their publication until Microsoft publishes the DLL kill bit in their Windows update.
 
/* Use this with templates/template-twocol.html */