Critical Tinyproxy Flaw Opens Over 50,000 Hosts to Remote Code Execution
ID: 75fea961-f32e-5f39-a7b9-dcbac0332188
STIX ID: report--75fea961-f32e-5f39-a7b9-dcbac0332188
Feed Name: The Hacker News
Threat Score
More than 50% of 90,310 internet-exposed Tinyproxy hosts were found running versions vulnerable to CVE-2023-49606, a critical (CVSS 9.8) unauthenticated use-after-free that can enable remote code execution; Talos published a PoC and Tinyproxy maintainers have released version 1.11.2 as a patch, with guidance to update or avoid exposing the service publicly.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
