

SANS Stormcast Wednesday Mar 26th: XWiki Exploit; File Converter Correction; VMWare Vulnerability; Draytek Router Reboots; MMC Exploit Details;
Mar 26, 2025
Discover the surge in exploit attempts targeting an XWiki vulnerability that allows command injection. Learn about the FBI's warning regarding unsafe online file converters. Follow the latest on a VMWare Tools flaw that could escalate user privileges within virtual machines. Hear about issues with Draytek routers stuck in a reboot loop and the advised fixes. Finally, get insights into the recent exploitation of a Microsoft Management Console vulnerability patched just days ago.
AI Snips
Chapters
Transcript
Episode notes
XWiki Update
- Update XWiki to patch a year-old vulnerability.
- This vulnerability allows remote code execution through the search feature.
Online File Converter Warning
- Be cautious of online file converters.
- Uploaded files may be exfiltrated, and downloaded files may contain malware.
VMWare Vulnerability
- VMware Tools has a vulnerability that allows privilege escalation.
- This vulnerability lets normal users gain admin access on Windows VMs.