Critical Zero-Day Flaw Exploited in MOVEit Transfer

A serious security threat has been discovered in the file transfer software MOVEit Transfer, which could allow an attacker to steal data from your organization.

A zero-day vulnerability discovered by Progress last week is a SQL injection weakness found in managed file transfer (MFT) products.

This flaw (CVE-2023-34362) could allow elevated privileges and unauthorized access.

“An attacker may be able to infer information about the structure and content of the MOVEit Transfer database, or modify or delete database elements,” explains Zane Bond, Head of Product at Keeper Security.

Progress did not mention any cases of abuse in its original advisory. However, according to a recent blog post by Rapid7 (and most recent Progress blog post), we are currently seeing active exploitation of this vulnerability.

“Since the disclosure of the vulnerability on May 31, 2023, we have observed an increase in related cases. [it] It has exploited a wide range of organizations, especially in North America,” the blog post reads.

As of May 31, the company said there were about 2,500 publicly accessible instances of MOVEit Transfer.

This vulnerability affects all MOVEit Transfer versions released before May 31, 2023. Rapid7 warned that it is important to promptly apply available fixes and patches released by MOVEit.

Additionally, customers using the MOVEit Transfer integration with Microsoft Azure should take immediate steps to rotate their Azure storage keys.

“The MOVEit Transfer incident is very similar to a number of SQLi attacks on file storage and transfer systems, the most recent being Clop’s high-profile attack on QNAP devices and Fortra’s GoAnywhere file transfer software.” said Vice President Craig Jones. Security activities at Ontinue.

For more information on GoAnywhere’s flaws, see Brightline Hack, which exposes data from over 780,000 child mental health patients.

From an application security perspective, the security expert said, the vulnerabilities found in MOVEit Transfer are a reminder of the importance of thorough input validation, robust access controls, and secure coding practices to prevent such exploits. I added that it is.

Source link

Leave a Reply

Your email address will not be published. Required fields are marked *