A **vulnerability** is a weakness that can be exploited by a [[Threats|threat]]. Therefore, organisations need to regularly inspect for vulnerabilities within their systems. Some vulnerabilities include: - **ProxyLogon**: A pre-authenticated vulnerability that affects the Microsoft Exchange server. This means a threat actor can complete a user authentication process to deploy malicious code from a remote location. - **ZeroLogon**: A vulnerability in Microsoft’s Netlogon authentication protocol. An authentication protocol is a way to verify a person's identity. Netlogon is a service that ensures a user’s identity before allowing access to a website's location. - **Log4Shell**: Allows attackers to run Java code on someone else’s computer or leak sensitive information. It does this by enabling a remote attacker to take control of devices connected to the internet and run malicious code. - **PetitPotam**: Affects Windows New Technology Local Area Network (LAN) Manager (NTLM). It is a theft technique that allows a LAN-based attacker to initiate an authentication request. - **Security logging and monitoring failures**: Insufficient logging and monitoring capabilities that result in attackers exploiting vulnerabilities without the organization knowing it - **Server-side request forgery**: Allows attackers to manipulate a server-side application into accessing and updating backend resources. It can also allow threat actors to steal data. There are arguably five main categories of vulnerabilities: - *Operating System*: These types of vulnerabilities are found within Operating Systems (OSs) and often result in privilege escalation. - *(Mis)Configuration-based*: These types of vulnerability stem from an incorrectly configured application or service. For example, a website exposing customer details. - *Weak or Default Credentials*: Applications and services that have an element of authentication will come with default credentials when installed. For example, an administrator dashboard may have the username and password of "admin". These are easy to guess by an attacker. - *Application Logic*: These vulnerabilities are a result of poorly designed applications. For example, poorly implemented authentication mechanisms that may result in an attacker being able to impersonate a user. - *Human-Factor*: Human-Factor vulnerabilities are vulnerabilities that leverage human behaviour. For example, phishing emails are designed to trick humans into believing they are legitimate.