ZeroHour
The Recordpublished ()ingested 1

Chinese hackers behind July 2021 SolarWinds zero

criticalData breach exploited in the wildimportance 60CVE-2021-35211CVE-2020-10148

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-10148
Authentication Bypass in SolarWinds Orion API (CVE-2020-10148)

The SolarWinds Orion API contains a critical authentication bypass (CWE-288/CWE-306, CVSS 9.8) that allows a remote, unauthenticated attacker to execute API commands on the Orion Platform. It is triggered by specially crafted requests to the Orion API that reach endpoints with authorization skipped, requiring no privileges or user interaction. By issuing these API commands, an attacker can take control of the SolarWinds instance; in observed intrusions, the flaw was used to install the SUPERNOVA webshell on Orion servers. Any organization running Orion Platform 2019.4 HF 5, 2020.2 with no hotfix installed, or 2020.2 HF 1 is affected. Exploitation is in the wild: the flaw is listed in CISA's KEV (added 2021-11-03), has been linked to the China-nexus actor DEV-0322 per public reporting, and EPSS assigns it a 92% probability of exploitation within 30 days.

Do: Apply the Orion Platform updates/hotfixes per SolarWinds' instructions and move all installations off the affected builds (2019.4 HF 5, 2020.2 without hotfix, 2020.2 HF 1). Until patched, restrict access to the Orion web console and API to trusted networks only. Hunt for compromise by checking for the SUPERNOVA webshell in the Orion web root and reviewing API logs for unauthenticated API command execution.

9.892% KEV
  • SolarWinds Orion Platform 2019.4 HF 5; 2020.2 with no hotfix installed; 2020.2 HF 1
largetens of thousands of Orion deployments (roughly 25,000-33,000 customer sites)
CVE-2021-35211
Unauthenticated RCE (Remote Memory Escape) in SolarWinds Serv-U

Microsoft researchers discovered a remote code execution flaw in SolarWinds Serv-U, an out-of-bounds write (CWE-787) described as a "Remote Memory Escape" in the Windows-based Serv-U products. A remote, unauthenticated attacker can trigger the flaw over the network against servers running a version before 15.2.3 HF2 and gain privileged access to the machine hosting Serv-U, with a maximum CVSS 10.0 score reflecting no required privileges, no user interaction, and impact beyond the application's security scope. Both Serv-U Managed File Transfer and Serv-U Secure FTP for Windows are affected. The vulnerability has been exploited in the wild: Microsoft attributed July 2021 attacks exploiting the Serv-U zero-day to Chinese threat actors, later warned of an uptick in exploitation attempts, and the flaw was added to CISA KEV on 2021-11-03 with known ransomware use.

Do: Upgrade Serv-U to 15.2.3 Hotfix 2 (HF2) or later per SolarWinds' instructions immediately, as the flaw is in CISA KEV with known exploitation including ransomware use. Audit Serv-U servers and their logs for signs of exploitation or compromise, and restrict internet exposure of Serv-U/FTP and SSH ports to trusted parties.

10.091% KEV ransomware
  • SolarWinds Serv-U Managed File Transfer (Windows) before 15.2.3 HF2
  • SolarWinds Serv-U Secure FTP (Windows) before 15.2.3 HF2
largeestimated tens of thousands of Serv-U deployments worldwide, with a few thousand instances directly internet-exposed
Full article436 words · extracted from therecord.media · click to collapse

In mid-July this year, Texas-based software provider SolarWinds released an emergency security update to patch a zero-day in its Serv-U file transferring technology that was being exploited in the wild.

At the time, SolarWinds did not share any details about the attacks and only said that it learned of the bug from Microsoft's security team.

In a blog post on Thursday, Microsoft revealed more details about the July attacks.

The company said the zero-day was the work of a new threat actor the company was tracking as DEV-0322, which Microsoft described as "a group operating out of China, based on observed victimology, tactics, and procedures."

Microsoft said the group targeted SolarWinds Serv-U servers "by connecting to the open SSH port and sending a malformed pre-auth connection request," which allowed DEV-0322 operators to run malicious code on the targeted system and take over vulnerable devices.

The OS maker did not go into details about what the intruders did once they breached a target. It is unclear if the hackers were interested in cyber-espionage and intelligence collection or if DEV-0322 was a run-of-the-mill crypto-mining gang.

Zero-day root cause: No ASLR

On the other hand, Microsoft delved into the technical aspects of the zero-day itself, tracked as CVE-2021-35211.

Microsoft said that one of the reasons the attacks succeeded was because some of the Serv-U binaries had not been protected by ASLR (Address Space Layout Randomization), a feature that randomizes the memory location of an application in order to prevent attackers from targeting specific memory sections and corrupt an app's memory.

As ASLR protection was missing, Microsoft said that exploiting the Serv-U zero-day was "not so complicated."

"Enabling ASLR is a simple compile-time flag which is enabled by default and has been available since Windows Vista," Microsoft engineers said.

Chinese hackers exploited SolarWinds products before

After news of the major SolarWinds supply-chain attack broke last year, an attack carried out by Russian cyber-espionage teams linked to the SVR intelligence service, the subsequent investigation found unrelated SolarWinds vulnerabilities that were also exploited by Chinese hackers.

US security firm Secureworks, which discovered these attacks, codenamed the Chinese group as Spiral.

Per Secureworks, in the attacks detected at the end of 2020 and start of 2021, Spiral exploited a SolarWinds zero-day in the Orion IT monitoring platform tracked as CVE-2020-10148.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/chinese-hackers-behind-july-2021-solarwinds-zero-day-attacks