Microsoft links Serv-U zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-10148 | Authentication Bypass in SolarWinds Orion API (CVE-2020-10148) The SolarWinds Orion API contains a critical authentication bypass (CWE-288/CWE-306, CVSS 9.8) that allows a remote, unauthenticated attacker to execute API commands on the Orion Platform. It is triggered by specially crafted requests to the Orion API that reach endpoints with authorization skipped, requiring no privileges or user interaction. By issuing these API commands, an attacker can take control of the SolarWinds instance; in observed intrusions, the flaw was used to install the SUPERNOVA webshell on Orion servers. Any organization running Orion Platform 2019.4 HF 5, 2020.2 with no hotfix installed, or 2020.2 HF 1 is affected. Exploitation is in the wild: the flaw is listed in CISA's KEV (added 2021-11-03), has been linked to the China-nexus actor DEV-0322 per public reporting, and EPSS assigns it a 92% probability of exploitation within 30 days. Do: Apply the Orion Platform updates/hotfixes per SolarWinds' instructions and move all installations off the affected builds (2019.4 HF 5, 2020.2 without hotfix, 2020.2 HF 1). Until patched, restrict access to the Orion web console and API to trusted networks only. Hunt for compromise by checking for the SUPERNOVA webshell in the Orion web root and reviewing API logs for unauthenticated API command execution. | 9.8 | 92% | KEV |
| largetens of thousands of Orion deployments (roughly 25,000-33,000 customer sites) | |
| CVE-2021-35211 | Unauthenticated RCE (Remote Memory Escape) in SolarWinds Serv-U Microsoft researchers discovered a remote code execution flaw in SolarWinds Serv-U, an out-of-bounds write (CWE-787) described as a "Remote Memory Escape" in the Windows-based Serv-U products. A remote, unauthenticated attacker can trigger the flaw over the network against servers running a version before 15.2.3 HF2 and gain privileged access to the machine hosting Serv-U, with a maximum CVSS 10.0 score reflecting no required privileges, no user interaction, and impact beyond the application's security scope. Both Serv-U Managed File Transfer and Serv-U Secure FTP for Windows are affected. The vulnerability has been exploited in the wild: Microsoft attributed July 2021 attacks exploiting the Serv-U zero-day to Chinese threat actors, later warned of an uptick in exploitation attempts, and the flaw was added to CISA KEV on 2021-11-03 with known ransomware use. Do: Upgrade Serv-U to 15.2.3 Hotfix 2 (HF2) or later per SolarWinds' instructions immediately, as the flaw is in CISA KEV with known exploitation including ransomware use. Audit Serv-U servers and their logs for signs of exploitation or compromise, and restrict internet exposure of Serv-U/FTP and SSH ports to trusted parties. | 10.0 | 91% | KEV ransomware |
| largeestimated tens of thousands of Serv-U deployments worldwide, with a few thousand instances directly internet-exposed |
Full article453 words · extracted from therecord.media · click to collapse
Microsoft said today that the recent wave of attacks that have targeted SolarWinds file transfer servers are the work of a Chinese hacking group the company has been tracking under the name of DEV-0322. News of the attacks first surfaced on Friday, July 9, when embattled software provider SolarWinds released a security update to patch a zero-day vulnerability in its Serv-U technology that was being exploited in the wild. At the time, SolarWinds said it learned of the zero-day (CVE-2021-35211) and the ongoing attacks from Microsoft but did not release any additional details beyond the Serv-U patch (v15.2.3 HF2). Initially, Microsoft declined to comment following the SolarWinds patch in emails sent by The Record. However, following pressure from the cyber-security community on Tuesday, which kept asking the OS maker for additional details so they could deploy countermeasures to detect and block ongoing attacks, Microsoft published a blog post today with an in-depth description of the zero-day's entire exploitation chain. According to the report, Microsoft said it discovered the DEV-0322 attacks after its Defender antivirus began detecting malicious processes spawning from Serv-U's main application, which eventually led its security team to investigate and discover the zero-day and the ongoing attacks. While Microsoft couldn't comment on the targets of this most recent campaign, the OS maker said that past DEV-0322 attacks had targeted software companies and entities in the US Defense Industrial Base Sector. These attacks also mark the second time that a Chinese hacking group has abused SolarWinds software to breach corporate and government networks. Back in December 2020, while the Russian-orchestrated SolarWinds supply chain attack was coming to light, Chinese hacking groups were also busy abusing the CVE-2020-10148 vulnerability to install web shells on SolarWinds Orion IT monitoring platforms. Because the CVE-2020-10148 came to light during the more broad supply chain investigation, it took security firms some time to separate the two incidents and eventually make the connection to a Chinese group tracked as Spiral. All in all, companies that run SolarWinds Serv-U file transfer servers can protect themselves against DEV-022 attacks by either installing the company's patch or by disabling SSH access to the server, which is how the group is compromising servers. According to a Censys search query, there are more than 8,200 SolarWinds Serv-U systems exposing their SSH port online, a number that had remained steady since last week, when the patches were released.DEV-0322 previously targeted the US Defense Industrial Base
No previous article
No new articles
Catalin Cimpanu
is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.
Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/microsoft-links-serv-u-zero-day-attacks-to-chinese-hacking-group