MOVEit Systems Face Fresh Attack Risk Following Scanning Activity
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-34362 | Unauthenticated SQL Injection in Progress MOVEit Transfer CVE-2023-34362 is an unauthenticated SQL injection flaw (CWE-89) in Progress MOVEit Transfer that allows an attacker with no credentials to gain unauthorized access to the product's database. It is triggered remotely via crafted input submitted to the MOVEit Transfer web application, with the impact varying by the backend database engine in use (MySQL, Microsoft SQL Server, or Azure SQL). A successful attacker can infer the structure and contents of the database and, depending on the engine, execute SQL statements that alter or delete database elements, exposing data handled by the file-transfer service. Any organization running an internet-reachable MOVEit Transfer instance is affected; public internet-exposure scans around disclosure identified on the order of a few thousand servers, each typically serving enterprise or government user bases. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2023-06-02 with known ransomware use and an EPSS exploitation probability of 99.9% (100th percentile), while no public PoC is known. Do: Apply the vendor's updates immediately, per Progress instructions and CISA's required action. Until patched, restrict internet exposure of MOVEit Transfer and check the backend database for unexpected structure or content changes and deletions. Because in-the-wild exploitation and ransomware use are confirmed, treat any unpatched, internet-facing instance as potentially compromised and review stored transfer data and access logs for anomalies. | 9.8 | 100% | KEV ransomware PoC |
| large≈2,000-3,000 internet-exposed MOVEit Transfer servers (public internet-exposure scans) | |
| CVE-2023-36934 | In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL In Progress MOVEit Transfer before 2020.1.11 (12.1.11), 2021.0.9 (13.0.9), 2021.1.7 (13.1.7), 2022.0.7 (14.0.7), 2022.1.8 (14.1.8), and 2023.0.4 (15.0.4), a SQL injection vulnerability has been identified in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to the MOVEit Transfer database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content. NVD description · AI analysis pending | 9.1 | 95% |
| — |
Full article418 words · extracted from infosecurity-magazine.com · click to collapse
A significant rise in scanning activity targeting MOVEit Transfer systems has been detected, indicating the software could face a resurgence in attacks.
Threat intelligence provider GreyNoise detected a massive jump in unique IPs triggering its MOVEit Transfer Scanner Tag, beginning on May 27, 2025. On that day, 100 unique IPs were detected, followed by 319 on May 28.
“Since that initial jump, the daily scanner IP volume has remained intermittently elevated between 200 to 300 IPs per day – a significant deviation from baseline and an indicator that MOVEit Transfer is once again in the crosshairs,” the researchers noted.
Prior to May 27, scanning activity targeting MOVEit was minimal, at less than 10 addresses observed per day.
In the summer of 2023, the notorious Clop ransomware gang exploited a vulnerability in MOVEit file transfer software, allowing it to target hundreds of downstream customers, including high profile names such as the BBC, British Airways and pharmacy chain Boots.
In total, GreyNoise detected 682 unique IPs undertaking MOVEit scanning activity in the 90 days up to June 24, 2025. The most active infrastructure was Tencent Cloud, used by 44% of the IPs detected.
Other source providers included Cloudflare (17%), Amazon (14%) and Google (5%).
The “overwhelming majority” of scanner IPs geolocated to the US.
The researchers believe the activity could be laying the groundwork for a renewed targeting of MOVEit Transfer systems by enabling attackers to discover new zero days or exploiting undisclosed vulnerabilities.
They noted that such scanning patterns often coincide with new vulnerabilities emerging two to four weeks later.
“This level of infrastructure concentration – particularly within a single autonomous system number (ASN) – suggests that the scanning is deliberate and programmatically managed, rather than random or distributed probing,” they commented.
The company added that it is continuing to monitor the situation and will provide updates as necessary.
Confirmed MOVEit Exploitation Attempts
GreyNoise also revealed it observed two low-volume exploitation attempts on June 12, 2025. These were associated with two previously disclosed SQL injection vulnerabilities affecting MOVEit transfer systems – CVE-2023-34362 and CVE-2023-36934.
“These events occurred during the period of heightened scanning and may represent target validation or exploit testing, but at this time, no widespread exploitation has been observed,” the researchers noted.
The firm provided the following recommendations for MOVEit customers to protect against exploitation attempts:
- Block any malicious and suspicious IPs
- Audit public exposure of any MOVEit Transfer systems
- Apply patches for known vulnerabilities, including CVE-2023-34362 and CVE-2023-36934
- Monitor real-time attacker activity against MOVEit Transfer
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/moveit-attack-risk-scanning-surge/