Microsoft Warns of Nation-State Hackers Exploiting Critical Atlassian Confluence Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-22515 | Unauthenticated Broken Access Control in Atlassian Confluence Data Center/Server Atlassian Confluence Data Center and Server contain a broken access control flaw (CWE-20) in publicly accessible instances that allows unauthenticated remote attackers to create unauthorized Confluence administrator accounts and gain access to the instance; the associated public PoC is titled 'Atlassian Confluence Unauthenticated Remote Code Execution'. The flaw is triggered over the network (CVSS 3.1 9.8, AV:N/AC:L/PR:N/UI:N) against any self-managed Confluence instance reachable from the internet, with no privileges or user interaction required. Attackers who exploit it gain administrator-level control of the Confluence instance, and the public PoC demonstrates this extends to unauthenticated code execution. Only self-managed Confluence Data Center and Server deployments are affected; Atlassian Cloud sites hosted on atlassian.net domains are not vulnerable. Exploitation is confirmed in the wild: CISA added it to the KEV on 2023-10-05 with known ransomware use, EPSS is 99.2%, Atlassian reported a handful of customers were already exploited, and Microsoft warned of nation-state (China-linked) abuse. Do: Patch all internet-facing Confluence Data Center and Server instances to a fixed release per Atlassian's advisory (specific fixed versions are not listed in this data), or restrict public access/discontinue use per CISA's required action. Audit every affected instance for evidence of compromise, especially unauthorized administrator accounts created through this flaw, and report positive findings to CISA. Treat this as urgent given active exploitation by both nation-state actors and ransomware groups. | 9.8 | 99% | KEV ransomware PoC |
| large≈ tens of thousands of internet-exposed Confluence Data Center/Server instances (order of ~30,000-50,000) |
Full article429 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 11, 2023Cyber Attack / Vulnerability
Microsoft has linked the exploitation of a recently disclosed critical flaw in Atlassian Confluence Data Center and Server to a nation-state actor it tracks as Storm-0062 (aka DarkShadow or Oro0lxy).
The tech giant's threat intelligence team said it observed in-the-wild abuse of the vulnerability since September 14, 2023.
"CVE-2023-22515 is a critical privilege escalation vulnerability in Atlassian Confluence Data Center and Server," the company noted in a series of posts on X (formerly Twitter).
"Any device with a network connection to a vulnerable application can exploit CVE-2023-22515 to create a Confluence administrator account within the application."
CVE-2023-22515, rated 10.0 on the CVSS severity rating system, allows remote attackers to create unauthorized Confluence administrator accounts and access Confluence servers. The flaw has been addressed in the following versions -
- 8.3.3 or later
- 8.4.3 or later, and
- 8.5.2 (Long Term Support release) or later
While the exact scale of the attacks is not clear, Atlassian said that it was made aware of the problem by "a handful of customers," meaning it had been exploited as a zero-day by the threat actor.
It's worth noting that Oro0lxy refers to a digital alias created by Li Xiaoyu, a Chinese hacker who was accused by the U.S. Department of Justice (DoJ) in July 2020 of infiltrating "hundreds of companies" in the U.S., Hong Kong, and China, including coronavirus vaccine research developer Moderna.
Xiaoyu, alongside DONG Jiazhi, is said to have been assigned to the Guangdong regional division of the Ministry of State Security (MSS).
"The defendants in some instances acted for their own personal financial gain, and in others for the benefit of the MSS or other Chinese government agencies," the DoJ said. "The hackers stole terabytes of data which comprised a sophisticated and prolific threat to U.S. networks."
Organizations relying on Confluence applications are highly recommended to upgrade to the latest versions to mitigate any potential threats, and also isolate them from the public internet until the fixes are in place.
CISA, FBI, and MS-ISAC Release Joint Advisory on CVE-2023-22515
On October 16, 2023, the U.S. government released a joint cybersecurity bulletin in response to active exploitation of CVE-2023-22515 to obtain access to victim systems and continue active exploitation post-patch.
It also warned of “widespread exploitation of unpatched Confluence instances in government and private networks,” considering the vulnerability allows for threat actors to create rogue admin accounts with relative ease.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/10/microsoft-warns-of-nation-state-hackers.html