Vulnerability Watch

Forum Discussion

Anonymous's avatar
Anonymous
Not applicable
6 years ago

New critical zero-day pre-auth RCE exploit code published...

New critical zero-day pre-auth RCE exploit code published on Full Disclosure mailing list for 5.x versions of vBulletin (CVE-2019-16759).

A preauthentication remote code execution (RCE) zero-day exploit was recently disclosed anonymously for vBulletin 5.x. This zero-day does not seem to have followed coordinated disclosure procedures. VBulletin released a new security patch for vBulletin versions 5.5.2, 5.5.3, and 5.5.4.

The vBulletin team has issued a patch for CVE-2019-16759 for vBulletin versions 5.5.2, 5.5.3, and 5.5.4. Users on earlier versions of vBulletin 5.x will need to update to one of the currently supported versions in order to apply the patch. VBulletin cloud users don’t need to perform any additional actions as the fix has already been applied to the cloud version.

For more information, please visit our blog.

4 Replies

  • Anonymous's avatar
    Anonymous
    Not applicable

    Thank you for the information.

  • Anonymous's avatar
    Anonymous
    Not applicable

    Thanks for sharing

  • Anonymous's avatar
    Anonymous
    Not applicable

    Thanks for the info ​