ZeroHour

CVE-2021-42237

KEV ransomware PoC large

Unauthenticated Deserialization RCE in Sitecore XP 7.5-8.2

CISA: Sitecore XP Remote Command Execution Vulnerability

CVSS 3.1
9.8 critical
EPSS
98%p100
Published
()
KEV added
AI analysis

Sitecore Experience Platform (XP) 7.5 Initial Release through 8.2 Update-7 contains an insecure deserialization flaw (CWE-502) that allows unauthenticated remote command execution on the server. An attacker triggers it simply by sending crafted serialized input to an affected Sitecore instance over the network; no authentication, special configuration, or user interaction is required (CVSS 9.8). Successful exploitation yields arbitrary command execution with the privileges of the web application, giving attackers full control of the CMS server to steal data, deploy malware, or pivot into the corporate network. Any organization running the affected Sitecore XP releases is exposed, particularly content management or delivery servers reachable from the internet. The flaw is actively exploited: it was added to CISA's KEV on 2022-03-25 with known ransomware use, EPSS puts the 30-day exploitation probability at 97.9%, and contemporaneous reporting describes access brokers such as 'Gold Melody' selling compromised network access to ransomware operators.

What to do: Apply updates per vendor instructions: upgrade to a fixed release or install the hotfix Sitecore provided for each affected 7.5-8.2 version, as required by CISA's KEV entry. Prioritize internet-facing Sitecore servers, review logs for signs of exploitation, and restrict network access to Sitecore endpoints as an interim measure, since ransomware operators are known to exploit this flaw.

Affected
Sitecore XP (Experience Platform)7.5 Initial Release through 8.2 Update-7
Estimated exposure
largetens of thousands of internet-exposed Sitecore XP servers worldwide, with the affected subset running 7.5-8.2 — Sitecore is a widely deployed enterprise CMS with thousands of enterprise customers, and public internet scans around disclosure found on the order of tens of thousands of exposed Sitecore instances, though only those on the 7.5-8.2 line…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sitecore XP 7.5 Initial Release to Sitecore XP 8.2 Update-7 is vulnerable to an insecure deserialization attack where it is possible to achieve remote command execution on the machine. No authentication or special configuration is required to exploit this vulnerability.

CISA Known Exploited Vulnerability
Affected
Sitecore XP
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
sitecore
Products
experience platform
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news