A significant vulnerability has been identified in libxml2, a widely utilized XML parsing library crucial for applications such as web services, data processing, and system configurations. This security flaw, cataloged as CVE-2024-40896, carries a high severity rating of 9.1 (CVSS) and impacts versions of libxml2 prior to 2.11.9, 2.12.9, and 2.13.3. The issue originates in the library's SAX parser, which inadequately blocks external entities even when developers attempt to explicitly disable them. This leaves systems vulnerable to XML External Entity (XXE) attacks, allowing attackers to access sensitive files or execute arbitrary commands. XXE attacks exploit weaknesses in XML parsers, enabling unauthorized access to local files, triggering denial-of-service (DoS) conditions, or running malicious code. Through this vulnerability, attackers could extract sensitive information, such as the [/]etc[/]passwd file, potentially compromising user credentials. In misconfigured systems, the flaw could escalate to Remote Code Execution (RCE), giving attackers complete control over the system. What makes this vulnerability particularly dangerous is its ability to bypass libxml2’s existing protections, making detection and mitigation more challenging for developers. To address this critical issue, users and administrators are strongly advised to upgrade to the latest versions of libxml2 (2.11.9, 2.12.9, or 2.13.3). Additionally, administrators should review their systems for applications reliant on libxml2, promptly apply patches, and strengthen their defenses to prevent exploitation.
Security researchers have identified a new variant of the SparkCat malware circulating on both the Apple App Store and Google Play Store, more than a year after its initial discove...
The European Union’s cybersecurity agency, CERT-EU, has attributed a significant cloud breach involving the European Commission to the TeamPCP threat group. The attack targeted t...
Microsoft has rolled out automatic updates for unmanaged Windows 11 24H2 Home and Pro edition devices to Windows 11 25H2, also known as the Windows 11 2025 Update. This transition ...