{"id":700,"date":"2020-03-02T17:53:47","date_gmt":"2020-03-02T16:53:47","guid":{"rendered":"https:\/\/www.upgreat.pl\/blog\/?p=286"},"modified":"2020-03-02T17:53:47","modified_gmt":"2020-03-02T16:53:47","slug":"nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci","status":"publish","type":"post","link":"https:\/\/www.upgreat.pl\/en\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/","title":{"rendered":"New year, new threats - review of fresh vulnerabilities"},"content":{"rendered":"<p>\t\t\t\tThe beginning of the year will probably be associated with the threat of coronavirus. This topic has dominated the media reports in recent weeks. It is also an excellent example of the fact that new threats may always appear in business, which have not been included in the risk analysis so far.<\/p>\n<p>However, there is just as much going on in the world of cyber threats. On January 14, the end of support for the operating systems from the Windows 7 and Windows Server 2008 family, which was announced for a long time by Microsoft, took place. This means that for one of the most popular systems that are still used, unfortunately, also on company computers, security patches related to new discoveries will no longer be delivered. vulnerabilities.<br \/>\nThe proof that this problem cannot be underestimated is the vulnerability found in the Remote Desktop Gateway service at the beginning of the year. <!--more-->It is true that it does not apply to the no longer supported Windows 7 and Windows Server 2008 systems, and to slightly newer editions of Windows Server 2012-2019, but it makes us realize that even in mature operating systems, serious vulnerabilities will still be found. The vulnerability, marked with the CVE-2020-0609 identifier, is, what is important, a critical vulnerability as it allows remote code execution (RCE).<\/p>\n<p>The vulnerability in Microsoft SQL Server Reporting Services (CVE-2020-0618) identified in February is of exactly the same nature. And that&#039;s not all in the case of Microsoft, unfortunately. Another remote code execution is possible in the Exachange server, and more precisely in the Exchange Control Panel component. And this is also a vulnerability from the beginning of this year (CVE-2020-0688).<\/p>\n<p>As you can see, users of Microsoft&#039;s systems must be vigilant when it comes to security. But is it only them?<\/p>\n<p>Another noteworthy vulnerability found at the beginning of this year is the CVE-2020-0022 identifier that allows remote code execution via the bluetooth protocol in Android. It applies to devices with Android 8 and 9 and partially 10 (in this case it is only possible to stop the service).<br \/>\nLet us remember that today various versions of the Android system, or its alternatives, can be found on devices such as TV sets, smartwatches, cameras, voip phones, household appliances, web cameras, toys and many, many others. Their manufacturers usually do little when it comes to user safety. Therefore, it is difficult to expect updates patching the above vulnerability in all available systems.<\/p>\n<p>Speaking of Android, it is also worth mentioning another product from Google - the Chrome browser. In version 80.0.3987.122, three security-critical vulnerabilities have been patched. And as can be easily deduced from the CVE ID, they too were identified early this year (CVE-2020-6418).<\/p>\n<p>So we have bugs in Microsoft&#039;s systems, bugs in Android mobile devices and bugs in the popular browser. If someone was not within the range of any of these vulnerabilities, then he could still fall victim to a vulnerability in NAS, Firewall or UTM devices produced by Zyxell. They have identified a command injection vulnerability that allows running system commands with root rights from the login form.<\/p>\n<p>As you can see, the beginning of the year is a series of serious threats, which, importantly, are very actively used by intruders. Exploits for most of the vulnerabilities described above are already available. The vulnerability in Zyxell devices was available in the form of a 0-day before its official announcement and publication of the update.\t\t<\/p>","protected":false},"excerpt":{"rendered":"<p>Pocz\u0105tek roku wszyscy kojarzy\u0107 b\u0119d\u0105 zapewne z zagro\u017ceniem w postaci koronawirusa. Temat ten zdominowa\u0142 doniesienia medialne z ostatnich tygodni. Jest te\u017c doskona\u0142ym przyk\u0142adem na to, i\u017c w biznesie zawsze mog\u0105 si\u0119 pojawi\u0107 nowe zagro\u017cenia, nieuwzgl\u0119dniane dotychczas w analizie ryzyka. W \u015bwiecie cyberzagro\u017ce\u0144 dzieje si\u0119 jednak r\u00f3wnie du\u017co. W dniu 14 stycznia nast\u0105pi\u0142o bowiem zapowiadane od [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[100,101,102,103],"class_list":["post-700","post","type-post","status-publish","format-standard","hentry","category-aktualnosci","tag-aktualizacje","tag-luki","tag-microsoft","tag-podatnosci"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.7 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci | Upgreat<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.upgreat.pl\/en\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci | Upgreat\" \/>\n<meta property=\"og:description\" content=\"Pocz\u0105tek roku wszyscy kojarzy\u0107 b\u0119d\u0105 zapewne z zagro\u017ceniem w postaci koronawirusa. Temat ten zdominowa\u0142 doniesienia medialne z ostatnich tygodni. Jest te\u017c doskona\u0142ym przyk\u0142adem na to, i\u017c w biznesie zawsze mog\u0105 si\u0119 pojawi\u0107 nowe zagro\u017cenia, nieuwzgl\u0119dniane dotychczas w analizie ryzyka. W \u015bwiecie cyberzagro\u017ce\u0144 dzieje si\u0119 jednak r\u00f3wnie du\u017co. W dniu 14 stycznia nast\u0105pi\u0142o bowiem zapowiadane od [&hellip;]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.upgreat.pl\/en\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/\" \/>\n<meta property=\"og:site_name\" content=\"Upgreat\" \/>\n<meta property=\"article:published_time\" content=\"2020-03-02T16:53:47+00:00\" \/>\n<meta name=\"author\" content=\"ridos\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"ridos\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/blog\\\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/blog\\\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\\\/\"},\"author\":{\"name\":\"ridos\",\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/#\\\/schema\\\/person\\\/d36f9c49b3812cc93a140745bf44a101\"},\"headline\":\"Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci\",\"datePublished\":\"2020-03-02T16:53:47+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/blog\\\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\\\/\"},\"wordCount\":600,\"publisher\":{\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/#organization\"},\"keywords\":[\"aktualizacje\",\"luki\",\"microsoft\",\"podatno\u015bci\"],\"articleSection\":[\"Aktualno\u015bci\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/blog\\\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\\\/\",\"url\":\"https:\\\/\\\/www.upgreat.pl\\\/blog\\\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\\\/\",\"name\":\"Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci | Upgreat\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/#website\"},\"datePublished\":\"2020-03-02T16:53:47+00:00\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/blog\\\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.upgreat.pl\\\/blog\\\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\\\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/blog\\\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Strona g\u0142\u00f3wna\",\"item\":\"https:\\\/\\\/www.upgreat.pl\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/#website\",\"url\":\"https:\\\/\\\/www.upgreat.pl\\\/\",\"name\":\"Upgreat\",\"description\":\"Bezpiecze\u0144stwo system\u00f3w IT, Outsourcing IT, Architektura system\u00f3w IT\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.upgreat.pl\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/#organization\",\"name\":\"UpGreat.pl \u2013 profesjonalne us\u0142ugi informatyczne\",\"url\":\"https:\\\/\\\/www.upgreat.pl\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.upgreat.pl\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/UpGreat_CI.svg\",\"contentUrl\":\"https:\\\/\\\/www.upgreat.pl\\\/wp-content\\\/uploads\\\/2022\\\/04\\\/UpGreat_CI.svg\",\"width\":600,\"height\":220,\"caption\":\"UpGreat.pl \u2013 profesjonalne us\u0142ugi informatyczne\"},\"image\":{\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/#\\\/schema\\\/logo\\\/image\\\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.upgreat.pl\\\/#\\\/schema\\\/person\\\/d36f9c49b3812cc93a140745bf44a101\",\"name\":\"ridos\",\"sameAs\":[\"https:\\\/\\\/www.upgreat.pl\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci | Upgreat","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.upgreat.pl\/en\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/","og_locale":"en_US","og_type":"article","og_title":"Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci | Upgreat","og_description":"Pocz\u0105tek roku wszyscy kojarzy\u0107 b\u0119d\u0105 zapewne z zagro\u017ceniem w postaci koronawirusa. Temat ten zdominowa\u0142 doniesienia medialne z ostatnich tygodni. Jest te\u017c doskona\u0142ym przyk\u0142adem na to, i\u017c w biznesie zawsze mog\u0105 si\u0119 pojawi\u0107 nowe zagro\u017cenia, nieuwzgl\u0119dniane dotychczas w analizie ryzyka. W \u015bwiecie cyberzagro\u017ce\u0144 dzieje si\u0119 jednak r\u00f3wnie du\u017co. W dniu 14 stycznia nast\u0105pi\u0142o bowiem zapowiadane od [&hellip;]","og_url":"https:\/\/www.upgreat.pl\/en\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/","og_site_name":"Upgreat","article_published_time":"2020-03-02T16:53:47+00:00","author":"ridos","twitter_card":"summary_large_image","twitter_misc":{"Written by":"ridos","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.upgreat.pl\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/#article","isPartOf":{"@id":"https:\/\/www.upgreat.pl\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/"},"author":{"name":"ridos","@id":"https:\/\/www.upgreat.pl\/#\/schema\/person\/d36f9c49b3812cc93a140745bf44a101"},"headline":"Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci","datePublished":"2020-03-02T16:53:47+00:00","mainEntityOfPage":{"@id":"https:\/\/www.upgreat.pl\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/"},"wordCount":600,"publisher":{"@id":"https:\/\/www.upgreat.pl\/#organization"},"keywords":["aktualizacje","luki","microsoft","podatno\u015bci"],"articleSection":["Aktualno\u015bci"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.upgreat.pl\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/","url":"https:\/\/www.upgreat.pl\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/","name":"Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci | Upgreat","isPartOf":{"@id":"https:\/\/www.upgreat.pl\/#website"},"datePublished":"2020-03-02T16:53:47+00:00","breadcrumb":{"@id":"https:\/\/www.upgreat.pl\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.upgreat.pl\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.upgreat.pl\/blog\/nowy-rok-nowe-zagrozenia-przeglad-swiezych-podatnosci\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Strona g\u0142\u00f3wna","item":"https:\/\/www.upgreat.pl\/"},{"@type":"ListItem","position":2,"name":"Nowy rok, nowe zagro\u017cenia \u2013 przegl\u0105d \u015bwie\u017cych podatno\u015bci"}]},{"@type":"WebSite","@id":"https:\/\/www.upgreat.pl\/#website","url":"https:\/\/www.upgreat.pl\/","name":"Upgreat","description":"Security of IT systems, IT Outsourcing, Architecture of IT systems","publisher":{"@id":"https:\/\/www.upgreat.pl\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.upgreat.pl\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.upgreat.pl\/#organization","name":"UpGreat.pl \u2013 professional IT services","url":"https:\/\/www.upgreat.pl\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.upgreat.pl\/#\/schema\/logo\/image\/","url":"https:\/\/www.upgreat.pl\/wp-content\/uploads\/2022\/04\/UpGreat_CI.svg","contentUrl":"https:\/\/www.upgreat.pl\/wp-content\/uploads\/2022\/04\/UpGreat_CI.svg","width":600,"height":220,"caption":"UpGreat.pl \u2013 profesjonalne us\u0142ugi informatyczne"},"image":{"@id":"https:\/\/www.upgreat.pl\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.upgreat.pl\/#\/schema\/person\/d36f9c49b3812cc93a140745bf44a101","name":"ridos","sameAs":["https:\/\/www.upgreat.pl"]}]}},"_links":{"self":[{"href":"https:\/\/www.upgreat.pl\/en\/wp-json\/wp\/v2\/posts\/700","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.upgreat.pl\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.upgreat.pl\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.upgreat.pl\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.upgreat.pl\/en\/wp-json\/wp\/v2\/comments?post=700"}],"version-history":[{"count":0,"href":"https:\/\/www.upgreat.pl\/en\/wp-json\/wp\/v2\/posts\/700\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.upgreat.pl\/en\/wp-json\/wp\/v2\/media?parent=700"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.upgreat.pl\/en\/wp-json\/wp\/v2\/categories?post=700"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.upgreat.pl\/en\/wp-json\/wp\/v2\/tags?post=700"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}