ZeroHour
Security Affairspublished ()ingested @securityaffairs

Experts warn of critical RCE in ConnectWise Server Backup Solution

criticalVulnerability exploited in the wildimportance 60CVE-2022-36537

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-36537
Unauthenticated Information Disclosure in ZK Framework AuUploader

ZK Framework versions 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2 and 8.6.4.1 fail to properly handle requests to the AuUploader servlet component, allowing unauthenticated attackers to access sensitive information. The flaw is triggered by sending a crafted POST request to the AuUploader endpoint over the network; no privileges or user interaction are required, and per the CVSS vector the impact is limited to confidentiality (no tampering or denial of service). An attacker gains the ability to read sensitive data served by Java web applications built on the affected ZK releases, potentially yielding details that enable follow-on intrusions. Any organization running or hosting a web application that embeds one of the affected ZK Framework versions is exposed, including third-party products that bundle the framework. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-02-27 with known ransomware use and required federal agencies to apply vendor updates, and its top-percentile EPSS score of 95.3% indicates a very high likelihood of continued exploitation.

Do: Upgrade ZK Framework to a patched release per vendor instructions, replacing the affected builds (8.6.4.1, 9.0.1.2, 9.5.1.3, 9.6.0.1 and 9.6.1). Inventory web applications and bundled products that use ZK, determine whether the AuUploader servlet is reachable, and restrict or filter access to that endpoint at the application server, reverse proxy, or WAF as an interim mitigation. Given the known ransomware-linked exploitation, prioritize patching internet-facing applications first.

7.595% KEV ransomware
  • zkoss ZK Framework 9.6.1, 9.6.0.1, 9.5.1.3, 9.0.1.2, 8.6.4.1
large≈ tens of thousands of internet-exposed Java web applications embedding ZK (estimate)
Full article298 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini November 01, 2022

ConnectWise has addressed a critical remote code execution vulnerability impacting Recover and R1Soft Server Backup Manager (SBM).

According to the advisory published by ConnectWise, the vulnerability is an Improper Neutralization of Special Elements in Output Used by a Downstream Component.

An attacker can exploit the vulnerability to execute remote code or directly access confidential data.

The vulnerability impacts ConnectWise Recover v2.9.7 and earlier versions and R1Soft SBM v6.16.3 and earlier versions.

Huntress researchers explained that the authentication bypass and sensitive file leak (CVE-2022-36537) affect the Java framework “ZK” Ajax web application framework used within the ConnectWise R1Soft software Server Backup Manager SE.

The experts published a video PoC that demonstrates the exploitation of the issue to 1) bypass authentication, 2) upload a backdoored JDBC database driver to gain code execution, and 3) use the REST API to trigger commands to registered agents to ultimately push the recently leaked Lockbit 3.0 ransomware to all downstream endpoints.

The good news is that the company is not aware of active exploitation of the vulnerability in the wild.

“It is important to note that the upstream ZK vulnerability not only affects R1Soft, but also any application utilizing an unpatched version of the ZK framework. The access an attacker can gain by using this authentication bypass vulnerability is specific to the application being exploited, however there is serious potential for other applications to be affected in a similar way to R1Soft Server Backup Manager.” concludes the post published by Huntress. “Huntress is working closely with our DIVD partners to continue the larger hunt and help secure other ZK applications that are at risk.”

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, ConnectWise)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/137946/uncategorized/connectwise-rce.html