CVE-2024-10924: Really Simple Security’s 2FA Betrayal

On November 6, 2024, Wordfence researcher István Márton disclosed CVE-2024-10924 — a CVSS 9.8 authentication bypass in Really Simple Security, the plugin securing four million WordPress sites, whose two-factor onboarding endpoint failed to validate the requesting user, granting attackers admin sessions on sites with incomplete 2FA enrollment. Patched same-day in 9.1.2, NVD-published November 14, the flaw became 2024’s definitive case study in security-plugin risk. This account walks the vulnerable code path, the four-million-site patch sprint, and why the ecosystem’s auth surface extends far past WordPress core.

Continue ReadingCVE-2024-10924: Really Simple Security’s 2FA Betrayal

Internet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

On 17 January 2020, Microsoft published ADV200001, a rare out-of-band advisory for CVE-2020-0674, a remote code execution flaw in the scripting engine used by Internet Explorer 9 and 11 that the company confirmed was being exploited in limited targeted attacks. There was no patch yet, only mitigations and workarounds, and defenders spent nearly a month exposed until the 11 February 2020 cumulative update shipped the fix. This piece reconstructs the advisory, the memory-corruption mechanics in the script engine, why IE was still a live attack surface in 2020, and what the episode taught about mitigations-first disclosure.

Continue ReadingInternet Explorer CVE-2020-0674: The Zero-Day Advisory That Opened 2020

Exchange CVE-2020-0688: A Default Key Made Every Server Alike

On 11 February 2020, Microsoft disclosed CVE-2020-0688, a remote code execution vulnerability in Microsoft Exchange Server’s Unified Messaging service that scored 9.8 on CVSS because every installation shipped with the same cryptographic validation key by default. Any authenticated user could send a specially crafted viewstate to the Exchange Control Panel and achieve RCE as SYSTEM, and because service accounts and weak credentials were everywhere, authenticated was a low bar. This analysis walks the vulnerable request path, the viewstate forgery mechanics, the patch, and the long tail of scanning and exploitation that followed for months.

Continue ReadingExchange CVE-2020-0688: A Default Key Made Every Server Alike

Kia’s Web Portal: Register Any Car’s Account, Control It From Your Phone

On September 25, 2024, researchers Karan Saini and Sam Curry published an access-control flaw in Kia’s dealer and consumer web infrastructure: given only a license plate, an attacker could register an account with remote lock, unlock, start, stop, locate and horn control over 2014-2025 connected vehicles they did not own. Kia patched in August before disclosure. This account walks the plate-to-command chain, the ownership-verification gap, the threat model for tracking and theft, and the automotive-API authorization lesson that outlasts the brand.

Continue ReadingKia’s Web Portal: Register Any Car’s Account, Control It From Your Phone

Cisco BroadWorks CVE-2023-20237: The SSO Bypass Scare

In September 2023 Cisco rushed out patches for CVE-2023-20237, a critical authentication bypass in BroadWorks’ single-sign-on flows that could let attackers authenticate as any user. With evidence of active scanning, carrier admins ran an emergency patch marathon.

Continue ReadingCisco BroadWorks CVE-2023-20237: The SSO Bypass Scare