Researchers Warn Against Zoho ManageEngine Exploit Attacks
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-47966 | Unauthenticated SAML RCE in Zoho ManageEngine On-Premise Products CVE-2022-47966 is a critical (CVSS 9.8), unauthenticated remote code execution flaw in roughly two dozen Zoho ManageEngine on-premise products caused by their bundled Apache Santuario xmlsec (XML Security for Java) 1.4.1 library, in which the XSLT features leave security protections to the application and ManageEngine did not provide them. An attacker triggers the flaw by sending a crafted SAML response containing a malicious XSLT transform to the SAML single sign-on (SSO) endpoint; exploitation is only possible if SAML SSO has ever been configured for the product (for some products, SAML SSO must be currently active). Successful exploitation yields arbitrary code execution in the context of the affected ManageEngine application, typically full compromise of the server and a foothold into the wider enterprise network. Any organization running an affected product version with SAML SSO enabled is affected, with internet-exposed ITSM/identity-management servers the most likely targets. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, Rapid7 reported broad attacker interest, North Korea's Lazarus Group used it to deploy QuiteRAT, and Iranian government-backed actors have targeted U.S. energy and transit-sector organizations. Do: Apply vendor updates immediately, upgrading each installed product to at least the fixed version listed (e.g., ServiceDesk Plus 14004+, ADSelfService Plus 6211+, Endpoint Central/Endpoint Central MSP 10.1.2228.11+, Password Manager Pro 12124+, ServiceDesk Plus MSP 13001+, ADAudit Plus 7081+, ADManager Plus 7162+, AD360 4310+); this is a CISA KEV required action. As an interim mitigation, disable or restrict SAML SSO (or limit access to the product's SSO endpoints), since SAML SSO must have been configured for exploitation. Prioritize patching internet-exposed instances and review those servers for signs of compromise, given documented use by Lazarus Group, ransomware operators, and Iranian nation-state actors. | 9.8 | 100% | KEV ransomware PoC ×6 |
| largetens of thousands of installations plausibly affected (thousands of instances internet-exposed), out of ManageEngine's very large on-prem install base |
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| domain | horizon3.ai | ast several years by threat actors to gain initial access.” Horizon3.ai has also released Indicators of Compromise (IOCs) associate |
Full article322 words · extracted from infosecurity-magazine.com · click to collapse
Horizon3.ai researchers have urged Zoho ManageEngine users to patch their software against a critical security vulnerability (tracked CVE-2022-47966) after designing and releasing a proof-of-concept (PoC) exploit code.
Writing in the company’s blog last Friday, Horizon3.ai researcher and exploit developer James Horseman said the team has successfully reproduced the exploit and is now providing additional insight into the vulnerability to help users determine if they have been compromised.
Patched by Zoho between the last week of October and the first of November 2022, the bug affects multiple Zoho ManageEngine products. It can be exploited over the internet to launch remote code execution (RCE) exploits if security assertion markup language (SAML) single sign-on (SSO) is enabled or has been enabled before.
“Once an attacker has SYSTEM-level access to the endpoint, attackers are likely to begin dumping credentials via LSASS or leverage existing public tooling to access stored application credentials to conduct lateral movement,” Horseman explained.
“Shodan data shows that there are likely more than a thousand instances of ManageEngine products exposed to the internet with SAML currently enabled.”
The company added that organizations that use SAML, generally speaking, tend to be larger and more mature and are likely to be higher-value targets for attackers.
“ManageEngine products have been highly targeted in the past several years by threat actors to gain initial access.”
Horizon3.ai has also released Indicators of Compromise (IOCs) associated with the flaw and is urging customers to update their instances before threat actors exploit it.
“We encourage all ManageEngine users to heed the ManageEngine advisory and patch immediately,” Horseman warned.
“We want to highlight that in some cases, the vulnerability is exploitable even if SAML is not currently enabled but was enabled sometime in the past. The safest course of action is to patch regardless of the SAML configuration of the product.”
More information about SAML and identity management is available in this analysis by JumpCloud CTO Greg Keller.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/zoho-manageengine-exploit-attack/