ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

New Drupal RCE vulnerability under active exploitation, patch ASAP!

criticalVulnerability exploited in the wildimportance 60CVE-2018-7602CVE-2018-7600

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2018-7600
Unauthenticated Remote Code Execution in Drupal Core (Drupalgeddon 2)

CVE-2018-7600, widely known as 'Drupalgeddon 2', is an unauthenticated remote code execution flaw in Drupal Core caused by insufficient input validation (CWE-20) in how the CMS processes certain structured request data. It can be triggered through multiple attack vectors, such as crafted parameters submitted to commonly used form and rendering features that are reachable by anonymous users with a single HTTP request. Successful exploitation lets an attacker run arbitrary code under the web application, typically resulting in complete site compromise, and CISA notes the flaw has been used in ransomware operations. Any site running unpatched Drupal 7.x or 8.x core is affected; Drupal's installed base at the time of disclosure was on the order of one million sites. Exploitation is confirmed in the wild (CISA KEV, added 2021-11-03), EPSS assigns a 100% probability of exploitation within 30 days, and no public PoC is recorded in the supplied data.

Do: Upgrade immediately per vendor instructions: Drupal 7.58, 8.5.1, or the corresponding 8.4.6/8.3.9 updates if you remain on older 8.x branches, prioritizing internet-facing sites. Because this flaw has been exploited in the wild and used in ransomware operations, also check patched sites for backdoors, unexpected administrator accounts, modified core files, and rotate credentials.

9.8100% KEV ransomware PoC ×4
  • Drupal Core Drupal 7.x prior to 7.58 and Drupal 8.x prior to 8.5.1 (prior to 8.4.6 on the 8.4.x branch and prior to 8.3.9 on the 8.3.x branch); version ranges per vendor ad
mass≈1,000,000 sites (Drupal's self-reported installed base at time of disclosure)
CVE-2018-7602
Drupal Core Remote Code Execution Vulnerability

A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vulnerability is related to Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-002. Both SA-CORE-2018-002 and this vulnerability are being exploited in the wild.

NVD description · AI analysis pending
9.899% KEV ransomware PoC ×2
  • Drupal Core
Full article495 words · extracted from helpnetsecurity.com · click to collapse

Yet another Drupal remote code execution vulnerability has been patched by the Drupal security team, who urge users to implement the offered updates immediately as the flaw is being actively exploited in the wild.

The vulnerability (CVE-2018-7602) affects Drupal versions 7.x and 8.x. Users should upgrade to v7.59 and 8.5.3.

Those who, for whatever reason, can’t implement the update can implement standalone patches, but before doing so they have to apply the fix from SA-CORE-2018-002 (dating back to March 28, 2018).

Drupal CVE-2018-7602

Drupal CVE-2018-7602 and CVE-2018-7600

This is the second time in less than a month that a critical remote code execution flaw has been plugged.

The first one – CVE-2018-7600 – affected Drupal 8, 7, and 6 sites, estimated to number approximately one million.

Although the flaw was discovered and responsibly disclosed by a researcher, it didn’t take long for attackers to develop an exploit once the security updates and patches had been released.

“Sites not patched by Wednesday, 2018-04-11 may be compromised. This is the date when evidence emerged of automated attack attempts. It is possible targeted attacks occurred before that,” the Drupal security team recently shared.

“With the March update, Drupal added a global sanitation function. This approach is often difficult to implement correctly,” SANS ISC CTO Johannes Ullrich commented.

“It is very difficult to sanitize and validate data before it is clear how it is being used, in particular if this is done for an existing and complex application like Drupal. We will see how this will work for Drupal in the long run.”

The second flaw – CVE-2018-7602 – is related to the previous one, was unearthed by the same researcher and members of the Drupal security team, and is also being actively exploited in the wild.

Attacks in the wild

China-based Netlab 360 recently observed a large number of scans on the internet against CVE-2018-7600.

The attackers search for vulnerable Drupal installations, exploit the flaw, and install cryptocurrency miners and DDoS-capable software on the compromised servers, as well as backdoors that make it possible for them to access the system whenever they want.

It is to be expected that CVE-2018-7602 will be exploited with the same goals in mind.

The Drupal team warns that, once the critical updates/patches are installed, administrators should check whether their installation has been compromised and a backdoor installed on the host.

“Simply updating Drupal will not remove backdoors or fix compromised sites. You should assume that the host is also compromised and that any other sites on a compromised host are compromised as well,” they noted.

“If you find that your site is already patched, but you didn’t do it, that can be a symptom that the site was compromised. Some attacks in the past have applied the patch as a way to guarantee that only that attacker is in control of the site.”

Instructions on what users should do if they find their Drupal site has been hacked are available here.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2018/04/26/drupal-cve-2018-7602/