News, tips, advice, support for Windows, Office, PCs & more
Home icon Home icon

We're community supported and proud of it!

  • USB Over Ethernet | Multiple Vulnerabilities in AWS and Other Major Cloud..

    Home » Forums » Networking – routers, firewalls, network configuration » USB Over Ethernet | Multiple Vulnerabilities in AWS and Other Major Cloud..

    Author
    Topic
    #2415748

    USB Over Ethernet | Multiple Vulnerabilities in AWS and Other Major Cloud Services

    Executive Summary
    SentinelLabs has discovered a number of high severity flaws in driver software affecting numerous cloud services.
    Cloud desktop solutions like Amazon Workspaces rely on third-party libraries, including Eltima SDK, to provide ‘USB over Ethernet’ capabilities that allow users to connect and share local devices like webcams. These cloud services are in use by millions of customers worldwide.
    Vulnerabilities in Eltima SDK, derivative products, and proprietary variants are unwittingly inherited by cloud customers.
    These vulnerabilities allow attackers to escalate privileges enabling them to disable security products, overwrite system components, corrupt the operating system, or perform malicious operations unimpeded.
    SentinelLabs’ findings were proactively reported to the vulnerable vendors during Q2 2021 and the vulnerabilities are tracked as CVE-2021-42972, CVE-2021-42973, CVE-2021-42976, CVE-2021-42977, CVE-2021-42979, CVE-2021-42980, CVE-2021-42983, CVE-2021-42986, CVE-2021-42987, CVE-2021-42988, CVE-2021-42990, CVE-2021-42993, CVE-2021-42994, CVE-2021-42996, CVE-2021-43000, CVE-2021-43002, CVE-2021-43003, CVE-2021-43006, CVE-2021-43637, CVE-2021-43638, CVE-2021-42681, CVE-2021-42682, CVE-2021-42683, CVE-2021-42685, CVE-2021-42686, CVE-2021-42687, CVE-2021-42688.
    Vendors have released security updates to address these vulnerabilities. Some of these are automatically applied while others require customer actions.
    At this time, SentinelLabs has not discovered evidence of in-the-wild abuse…

    Reply To: USB Over Ethernet | Multiple Vulnerabilities in AWS and Other Major Cloud..

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.