comparemela.com

Latest Breaking News On - Cesanta software mongoose - Page 1 : comparemela.com

BadAlloc: Microsoft Flags Major Security Holes in OT, IoT Devices

By Ryan Naraine on April 29, 2021 Security researchers at Microsoft are raising the alarm for multiple gaping security holes in a wide range of enterprise internet-connected devices, warning that the high-risk bugs expose  businesses to remote code execution attacks. According to an advisory from Redmond’s Azure Defender for IoT security research group, there are at least 25 documented vulnerabilities (CVEs) affecting a wide range of IoT and operational technology (OT) devices the industrial, medical, and enterprise networks. Microsoft is calling the family of vulnerabilities BadAlloc . “Our research shows that memory allocation implementations written throughout the years as part of IoT devices and embedded software have not incorporated proper input validations. Without these input validations, an attacker could exploit the memory allocation function to perform a heap overflow, resulting in execution of malicious code on a target device,” Microsoft explained.

© 2024 Vimarsana

vimarsana © 2020. All Rights Reserved.