Remote Code Execution

リモートコード実行 (RCE) ⚔️ 攻撃タイプ 関連 19
slug: rce

解説

RCE (Remote Code Execution) は「攻撃者が遠隔から、サーバー上で任意のプログラムを実行できる」最も深刻な脆弱性です。 これが成立すると、サーバー全体が乗っ取られ、データ全削除・暗号通貨マイニング・ランサムウェア感染・他社攻撃の踏み台化など何でもされます。 セキュリティ業界では「最悪レベル」「最優先で塞ぐべき」と扱われます。
📌 具体例
Log4Shell (CVE-2021-44228), Heartbleed (CVE-2014-0160) の後継 OpenSSL系, MOVEit Transfer (CVE-2023-34362) など。被害規模は数千億円〜兆円単位。

🔖 関連タグ

🛡 このタグに関連する脆弱性 2,172

ID タイトル
CVE-2020-1067 microsoft に バッファオーバーフロー (CVE-2020-1067)
CVE-2020-1069 csharp に バッファオーバーフロー (CVE-2020-1069)
CVE-2020-0901 microsoft に バッファオーバーフロー (CVE-2020-0901)
CVE-2020-1023 microsoft に 危険なファイルアップロード (CVE-2020-1023)
CVE-2020-1024 microsoft に 危険なファイルアップロード (CVE-2020-1024)
CVE-2020-1035 microsoft に バッファオーバーフロー (CVE-2020-1035)
CVE-2020-1037 microsoft に 境界外書き込み (CVE-2020-1037)
CVE-2020-1051 microsoft に バッファオーバーフロー (CVE-2020-1051)
CVE-2020-9484 org.apache.tomcat:tomcat-catalina に 安全でないデシリアライゼーション (CVE-2020-9484)
CVE-2020-11111 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.activemq.* (aka activemq-jms, activemq-core, activemq-pool, an...
CVE-2020-11112 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.commons.proxy.provider.remoting.RmiProvider (aka apache/common...
CVE-2020-11113 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.openjpa.ee.WASRegistryManagedRuntime (aka openjpa).
CVE-2020-10969 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to javax.swing.JEditorPane.
CVE-2020-10968 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.aoju.bus.proxy.provider.remoting.RmiProvider (aka bus-proxy).
CVE-2020-10672 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to org.apache.aries.transaction.jms.internal.XaPooledConnectionFactory (aka...
CVE-2020-10673 FasterXML jackson-databind 2.x before 2.9.10.4 mishandles the interaction between serialization gadgets and typing, related to com.caucho.config.types.ResourceRef (aka caucho-quercus).
CVE-2019-12675 Multiple vulnerabilities in the multi-instance feature of Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to escape the container for their FTD instance and...
CVE-2019-1068 KEV 【KEV】Microsoft sql-server の脆弱性 (CVE-2019-1068)
CVE-2017-14854 orpak に バッファオーバーフロー (CVE-2017-14854)
CVE-2017-14853 The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attac...
CVE-2019-7386 dos の脆弱性 (CVE-2019-7386)
CVE-2018-18861 Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
CVE-2018-1258 Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauth...
CVE-2017-5641 apache に 安全でないデシリアライゼーション (CVE-2017-5641)
CVE-2017-15311 dos に バッファオーバーフロー (CVE-2017-15311)
CVE-2017-16717 we-con の脆弱性 (CVE-2017-16717)
CVE-2017-4933 vmware に 境界外書き込み (CVE-2017-4933)
CVE-2017-4941 vmware に バッファオーバーフロー (CVE-2017-4941)
CVE-2017-11935 microsoft に バッファオーバーフロー (CVE-2017-11935)
CVE-2017-11885 microsoft の脆弱性 (CVE-2017-11885)

🍪 Cookie について

当サイトはログイン状態の保持・言語設定・サービス改善のために Cookie を使用します。詳細は下記リンクをご確認ください。

詳細 →