ZeroHour

CVE-2019-10068

KEV PoC large

Unauthenticated RCE in Kentico Xperience Staging Service

CISA: Kentico Xperience Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.8 critical
EPSS
95%p100
Published
()
KEV added
AI analysis

CVE-2019-10068 is a .NET deserialization flaw (CWE-502) in the Kentico Xperience staging service that stems from a failure to validate security headers on incoming requests. Because of this, a specially crafted request can bypass the staging service's initial authentication and reach the deserialization routine with attacker-controlled .NET object data. Successful exploitation yields unauthenticated remote code execution on the server hosting the Kentico instance, with full confidentiality, integrity, and availability impact (CVSS 3.1: 9.8). All Kentico 9.x releases and 10.0.x, 11.0.x, and 12.0.x branches prior to the fixed builds (10.0.52, 11.0.48, 12.0.15) are affected. Exploitation is confirmed: the flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2022-03-25), carries a very high EPSS score of 95.1%, and a public proof-of-concept for Kentico CMS 12.0.14 remote command execution is available.

What to do: Upgrade affected instances immediately: 12.x to 12.0.15 or later, 11.x to 11.0.48 or later, and 10.x to 10.0.52 or later; for 9.x, apply the vendor-provided patch per Kentico's update instructions. Until patched, restrict access to the staging service (limit it to trusted internal networks/synchronization peers) and review logs for unauthenticated or anomalous requests to the staging endpoint.

Affected
Kentico Xperience (Kentico CMS)9.x (all); 10.0.x before 10.0.52; 11.0.x before 11.0.48; 12.0.x before 12.0.15
Estimated exposure
large≈tens of thousands of deployments (commercial enterprise CMS, commonly tens of thousands of licensed sites, with the staging service often internet-reachable) — No install-count data was provided in the source data, so this is an estimate based on Kentico's positioning as a widely licensed commercial .NET CMS for enterprise websites and the common deployment pattern of exposing the staging service…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions. Due to a failure to validate security headers, it was possible for a specially crafted request to the staging service to bypass the initial authentication and proceed to deserialize user-controlled .NET object input. This deserialization then led to unauthenticated remote code execution on the server where the Kentico instance was hosted.

CISA Known Exploited Vulnerability
Affected
Kentico Xperience
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
kentico
Products
xperience
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

FBI Disrupts China-Linked QTFY Infrastructure Used to Steal Data From U.S. Organizations

FBI and Lumen disrupted QTFY's QScan and QTRouter botnet platforms used by Chinese state-sponsored hackers to conceal intrusions into U.S. agencies.

The U.S. DoJ announced court-authorized seizure of domains behind QScan and QTRouter, operated by the Chinese state-sponsored group QTFY and employed by Nanjing Xinjiuwei Network Technology Company. QTFY has been active since May 2018 and targeted NASA, the Federal Reserve, the Department of Energy, DoJ, HHS, NIH, the U.S. Senate, and academic institutions. QScan exploits vulnerable IoT devices, feeding them into QTRouter, an OpenWrt-based proxy obfuscation network likened to an operational relay box (ORB) that masks attack origins. The group exploited zero-days such as Ivanti CSA flaws CVE-2024-8190, CVE-2024-8963, and CVE-2024-9380, plus numerous N-days, and maintained persistence with RATs, web shells, and legitimate credentials.

The Hacker News · 13d agoThreat actor in the wildCVE-2018-13379CVE-2019-10068CVE-2019-19781+10 CVEs