ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Red Cross Attackers Exploited Zoho Bug Used by China

highData breachimportance 60CVE-2021-40539

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-40539
Unauthenticated RCE via REST API auth bypass in Zoho ManageEngine ADSelfService Plus

CVE-2021-40539 is a critical (CVSS 9.8) authentication bypass in the REST API of Zoho ManageEngine ADSelfService Plus, caused by use of an incorrectly resolved name or reference (CWE-706). An unauthenticated, network-adjacent or internet-reachable attacker sends specially crafted requests to the product's REST API, bypassing authentication, and can chain the bypass to full remote code execution with no privileges or user interaction required. Successful exploitation yields complete compromise of the self-service portal server (high impact to confidentiality, integrity and availability); public reporting and vendor notes document attackers dropping malicious code and web shells onto vulnerable servers. Any organization running ManageEngine ADSelfService Plus build 6113 or earlier is affected, which typically means enterprise Microsoft Active Directory environments running this widely deployed self-service password/SSO portal. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS puts the 30-day exploitation probability at 99% (100th percentile), Microsoft warned that Chinese threat actors were actively exploiting it, a public proof-of-concept is available, and it ranked among CISA's most routinely exploited vulnerabilities.

Do: Immediately upgrade ManageEngine ADSelfService Plus to a fixed build newer than 6113 per the vendor's update instructions, as required by CISA. Because exploitation predates patching and the flaw has been used to drop malicious code, check ADSelfService Plus servers for web shells, unexpected scheduled tasks, and unexplained accounts/processes, and hunt for indicators from the published analyses. Where possible, restrict internet exposure of the ADSelfService Plus REST API while patching, prioritized for externally reachable instances.

9.899% KEV ransomware PoC
  • Zoho (zohocorp) ManageEngine ADSelfService Plus 6113 and prior
largetens of thousands of enterprise server installations (unknown precise count)
Full article325 words · extracted from infosecurity-magazine.com · click to collapse

A major data breach at the International Committee of the Red Cross (ICRC) in January began with the exploitation of a Zoho vulnerability previously used by Chinese state-backed hackers in attacks.

The ICRC released more details of the attack yesterday in the interests of transparency and responsibility to its stakeholders.

It claimed that the breach was highly targeted and sophisticated, beginning with the exploitation of CVE-2021-40539 in password management system Zoho ManageEngine ADSelfService Plus.

“This vulnerability allows malicious cyber-actors to place web shells and conduct post-exploitation activities such as compromising administrator credentials, conducting lateral movement and exfiltrating registry hives and Active Directory files,” the ICRC explained.

“Once inside our network, the hackers were able to deploy offensive security tools which allowed them to disguise themselves as legitimate users or administrators. This in turn allowed them to access the data, despite this data being encrypted.”

Other indications of a highly targeted APT attack included the use of “a very specific set of advanced hacking tools,” “sophisticated obfuscation techniques” to hide malicious activity and malicious files specially crafted to bypass the organization’s anti-malware defenses.

“We determined the attack to be targeted because the attackers created a piece of code designed purely for execution on the targeted ICRC servers,” the non-profit continued. “The tools used by the attacker explicitly referred to a unique identifier on the targeted servers (its MAC address).”

It was only when the Red Cross installed endpoint detection and response (EDR) agents that it detected the intrusion. It’s believed the breach occurred on November 9 2021, with the attackers present inside the ICRC network for around 70 days.

That tallies with a report from Microsoft of Chinese state actors exploiting the same vulnerability to target organizations in various sectors. However, the ICRC has yet to formally attribute the attack.

Data was stolen on 515,000 “highly vulnerable” people worldwide, including names, locations and contact information. The Restoring Family Links service, which reunites separated families, was impacted.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/red-cross-attackers-exploited-zoho/