ZeroHour
The Recordpublished ()ingested

Hackers exploiting vulnerability affecting Zoho ManageEngine products: Rapid7

highVulnerability exploited in the wildimportance 60CVE-2022-47966CVE-2021-40539

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-40539
Unauthenticated RCE via REST API auth bypass in Zoho ManageEngine ADSelfService Plus

CVE-2021-40539 is a critical (CVSS 9.8) authentication bypass in the REST API of Zoho ManageEngine ADSelfService Plus, caused by use of an incorrectly resolved name or reference (CWE-706). An unauthenticated, network-adjacent or internet-reachable attacker sends specially crafted requests to the product's REST API, bypassing authentication, and can chain the bypass to full remote code execution with no privileges or user interaction required. Successful exploitation yields complete compromise of the self-service portal server (high impact to confidentiality, integrity and availability); public reporting and vendor notes document attackers dropping malicious code and web shells onto vulnerable servers. Any organization running ManageEngine ADSelfService Plus build 6113 or earlier is affected, which typically means enterprise Microsoft Active Directory environments running this widely deployed self-service password/SSO portal. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS puts the 30-day exploitation probability at 99% (100th percentile), Microsoft warned that Chinese threat actors were actively exploiting it, a public proof-of-concept is available, and it ranked among CISA's most routinely exploited vulnerabilities.

Do: Immediately upgrade ManageEngine ADSelfService Plus to a fixed build newer than 6113 per the vendor's update instructions, as required by CISA. Because exploitation predates patching and the flaw has been used to drop malicious code, check ADSelfService Plus servers for web shells, unexpected scheduled tasks, and unexplained accounts/processes, and hunt for indicators from the published analyses. Where possible, restrict internet exposure of the ADSelfService Plus REST API while patching, prioritized for externally reachable instances.

9.899% KEV ransomware PoC
  • Zoho (zohocorp) ManageEngine ADSelfService Plus 6113 and prior
largetens of thousands of enterprise server installations (unknown precise count)
CVE-2022-47966
Unauthenticated SAML RCE in Zoho ManageEngine On-Premise Products

CVE-2022-47966 is a critical (CVSS 9.8), unauthenticated remote code execution flaw in roughly two dozen Zoho ManageEngine on-premise products caused by their bundled Apache Santuario xmlsec (XML Security for Java) 1.4.1 library, in which the XSLT features leave security protections to the application and ManageEngine did not provide them. An attacker triggers the flaw by sending a crafted SAML response containing a malicious XSLT transform to the SAML single sign-on (SSO) endpoint; exploitation is only possible if SAML SSO has ever been configured for the product (for some products, SAML SSO must be currently active). Successful exploitation yields arbitrary code execution in the context of the affected ManageEngine application, typically full compromise of the server and a foothold into the wider enterprise network. Any organization running an affected product version with SAML SSO enabled is affected, with internet-exposed ITSM/identity-management servers the most likely targets. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, Rapid7 reported broad attacker interest, North Korea's Lazarus Group used it to deploy QuiteRAT, and Iranian government-backed actors have targeted U.S. energy and transit-sector organizations.

Do: Apply vendor updates immediately, upgrading each installed product to at least the fixed version listed (e.g., ServiceDesk Plus 14004+, ADSelfService Plus 6211+, Endpoint Central/Endpoint Central MSP 10.1.2228.11+, Password Manager Pro 12124+, ServiceDesk Plus MSP 13001+, ADAudit Plus 7081+, ADManager Plus 7162+, AD360 4310+); this is a CISA KEV required action. As an interim mitigation, disable or restrict SAML SSO (or limit access to the product's SSO endpoints), since SAML SSO must have been configured for exploitation. Prioritize patching internet-exposed instances and review those servers for signs of compromise, given documented use by Lazarus Group, ransomware operators, and Iranian nation-state actors.

9.8100% KEV ransomware PoC ×6
  • zohocorp ManageEngine Access Manager Plus before 4308
  • zohocorp ManageEngine Active Directory 360 (AD360) before 4310
  • zohocorp ManageEngine ADAudit Plus before 7081
  • +9 more
largetens of thousands of installations plausibly affected (thousands of instances internet-exposed), out of ManageEngine's very large on-prem install base
Full article522 words · extracted from therecord.media · click to collapse

Researchers at cybersecurity firm Rapid7 have observed exploitation of a vulnerability affecting two dozen ManageEngine products from software company Zoho.

The bug – CVE-2022-47966 – was patched in waves starting on October 27, with the last product receiving a patch on November 7.

Discovered by a researcher from Viettel Cyber Security, the vulnerability allows an unauthenticated adversary to execute code on a system.

On Thursday, experts from the Horizon3.ai Attack Team published a proof of concept and said it was “low in complexity and easy to exploit.” Horizon3.ai initially said it had not seen exploitation of the bug in the wild based on data from cybersecurity company GreyNoise.

— Horizon3 Attack Team (@Horizon3Attack) January 19, 2023

But on Thursday afternoon Rapid7 published its own blog post saying it was responding to “various compromises arising from the exploitation of CVE-2022-47966.”

“Organizations using any of the affected products listed in ManageEngine’s advisory should update immediately and review unpatched systems for signs of compromise, as exploit code is publicly available and exploitation has already begun,” the researchers said, adding that they saw exploitation as early as January 18.

The ManageEngine IT service management solutions suite is used by hundreds of organizations – including nine of every 10 Fortune 100 organizations – for IT infrastructure, networks, servers, applications, endpoints and more.

The exploit only works if Security Assertion Markup Language (SAML) single-sign-on has been previously enabled. 

Horizon3.ai said organizations that use SAML tend to be larger and more mature, and are likely to be higher value targets for attackers. 

“Its primary role in online security is enabling access to multiple web applications using a single set of login credentials,” Horizon3.ai researchers said. 

Eric Fredrickson, head of attack engineering at Horizon3.ai, said data from Shodan shows that there are likely more than 1,000 instances of ManageEngine products exposed to the internet with SAML currently enabled. 

“Looking just at the ServerDesk Plus and Endpoint Central products, the Horizon3.ai Attack Team found: 5,255 exposed instances of ServiceDesk Plus, of which 509 have SAML enabled, and 3,105 exposed instances of Endpoint Central, of which 345 have SAML enabled,” Fredrickson said.  

“In a worst case scenario, an attacker would gain complete control of the system running the vulnerable ManageEngine project. From there, an attacker can pivot to other machines in the network, dump credentials, and deploy malware/ransomware.”

Horizon3.ai exploit developer James Horseman added that the bug is a result of using an outdated version of Apache Santuario – a tool used for security. 

There have been several Zoho ManageEngine vulnerabilities exploited over the last two years.

The Red Cross was hacked through CVE-2021-40539 and a state-sponsored group used the same bug to target the Port of Houston. The German government also warned last year of Chinese state-sponsored groups using the bug to target businesses in the country.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/hackers-exploiting-vulnerability-affecting-zoho-manageengine-products-rapid7