https://reddit.com/r/cybersecurity/comments/1irkd81/a_postgresql_zeroday_was_also_exploited_in_us/: A PostgreSQL zero-day was also exploited in US Treasury hack (CVE-2025-1094)
Published Feb 17, 2025
·Updated
Affected Software
1 affected component
PostgreSQL postgresql
Frequently Asked Questions
1
What is the severity of CVE-2025-1094?
CVE-2025-1094 has been classified as a critical severity vulnerability due to its exploitation potential in PostgreSQL systems.
2
How do I fix CVE-2025-1094?
To fix CVE-2025-1094, you should update PostgreSQL to the latest version that addresses this zero-day vulnerability.
3
What systems are affected by CVE-2025-1094?
CVE-2025-1094 affects all versions of PostgreSQL prior to the patched version released on February 17, 2025.
4
What are the potential impacts of CVE-2025-1094?
The potential impacts of CVE-2025-1094 include unauthorized access to sensitive data and disruption of database services.
5
How was CVE-2025-1094 exploited in the US Treasury hack?
CVE-2025-1094 was exploited in the US Treasury hack by allowing attackers to gain escalated privileges within the PostgreSQL database.