CISA Warns of Actively Exploited Critical Zoho ManageEngine ServiceDesk Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2021-40539 | Unauthenticated RCE via REST API auth bypass in Zoho ManageEngine ADSelfService Plus CVE-2021-40539 is a critical (CVSS 9.8) authentication bypass in the REST API of Zoho ManageEngine ADSelfService Plus, caused by use of an incorrectly resolved name or reference (CWE-706). An unauthenticated, network-adjacent or internet-reachable attacker sends specially crafted requests to the product's REST API, bypassing authentication, and can chain the bypass to full remote code execution with no privileges or user interaction required. Successful exploitation yields complete compromise of the self-service portal server (high impact to confidentiality, integrity and availability); public reporting and vendor notes document attackers dropping malicious code and web shells onto vulnerable servers. Any organization running ManageEngine ADSelfService Plus build 6113 or earlier is affected, which typically means enterprise Microsoft Active Directory environments running this widely deployed self-service password/SSO portal. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, EPSS puts the 30-day exploitation probability at 99% (100th percentile), Microsoft warned that Chinese threat actors were actively exploiting it, a public proof-of-concept is available, and it ranked among CISA's most routinely exploited vulnerabilities. Do: Immediately upgrade ManageEngine ADSelfService Plus to a fixed build newer than 6113 per the vendor's update instructions, as required by CISA. Because exploitation predates patching and the flaw has been used to drop malicious code, check ADSelfService Plus servers for web shells, unexpected scheduled tasks, and unexplained accounts/processes, and hunt for indicators from the published analyses. Where possible, restrict internet exposure of the ADSelfService Plus REST API while patching, prioritized for externally reachable instances. | 9.8 | 99% | KEV ransomware PoC |
| largetens of thousands of enterprise server installations (unknown precise count) | |
| CVE-2021-44077 | Unauthenticated RCE in Zoho ManageEngine ServiceDesk Plus and SupportCenter Plus CVE-2021-44077 is a critical (CVSS 9.8) unauthenticated remote code execution flaw in Zoho ManageEngine ServiceDesk Plus, ServiceDesk Plus MSP, and SupportCenter Plus, rooted in missing authentication (CWE-306) on /RestAPI servlet URLs, specifically the ImportTechnicians action in the Struts configuration. A remote attacker can trigger it by sending crafted unauthenticated requests to the RestAPI endpoints, requiring no credentials or user interaction. Successful exploitation yields arbitrary code execution in the context of the application, giving attackers full control of the help desk server as a foothold for further network compromise. Any organization running affected versions before ServiceDesk Plus 11306, ServiceDesk Plus MSP 10530, or SupportCenter Plus 11014 is affected, particularly where the console is internet-facing. Exploitation is confirmed in the wild: the flaw was added to CISA's KEV on 2021-12-01, carries a 93.3% EPSS probability of near-term exploitation, and headlines point to active APT campaigns and mass exploitation against ManageEngine ServiceDesk deployments. Do: Upgrade to the fixed releases: ServiceDesk Plus 11306 or later, ServiceDesk Plus MSP 10530 or later, and SupportCenter Plus 11014 or later, per vendor instructions (CISA KEV requires this action). Until patched, restrict or firewall internet access to /RestAPI endpoints, and review access logs for unauthenticated requests to the ImportTechnicians action along with unexpected processes, files, or webshells on the server. Given the 93.3% EPSS score, active APT exploitation, and concurrent zero-day activity against other ManageEngine products, treat exposed instances as potentially compromised and hunt for post-exploitation activity. | 9.8 | 93% | KEV PoC |
| largetens of thousands of on-prem help desk deployments worldwide, with thousands of instances directly internet-exposed (estimate) |
Full article530 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananDec 03, 2021
The U.S. Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are warning of active exploitation of a newly patched flaw in Zoho's ManageEngine ServiceDesk Plus product to deploy web shells and carry out an array of malicious activities.
Tracked as CVE-2021-44077 (CVSS score: 9.8), the issue relates to an unauthenticated, remote code execution vulnerability affecting ServiceDesk Plus versions up to and including 11305 that, if left unfixed, "allows an attacker to upload executable files and place web shells that enable post-exploitation activities, such as compromising administrator credentials, conducting lateral movement, and exfiltrating registry hives and Active Directory files," CISA said.
"A security misconfiguration in ServiceDesk Plus led to the vulnerability," Zoho noted in an independent advisory published on November 22. "This vulnerability can allow an adversary to execute arbitrary code and carry out any subsequent attacks." Zoho addressed the same flaw in versions 11306 and above on September 16, 2021.
CVE-2021-44077 is also the second flaw to be exploited by the same threat actor that was formerly found exploiting a security shortcoming in Zoho's self-service password management and single sign-on solution known as ManageEngine ADSelfService Plus (CVE-2021-40539) to compromise at least 11 organizations, according to a new report published by Palo Alto Networks' Unit 42 threat intelligence team.
"The threat actor expand[ed] its focus beyond ADSelfService Plus to other vulnerable software," Unit 42 researchers Robert Falcone and Peter Renals said. "Most notably, between October 25 and November 8, the actor shifted attention to several organizations running a different Zoho product known as ManageEngine ServiceDesk Plus."
The attacks are believed to be orchestrated by a "persistent and determined APT actor" tracked by Microsoft under the moniker "DEV-0322," an emerging threat cluster that the tech giant says is operating out of China and has been previously observed exploiting a then zero-day flaw in SolarWinds Serv-U managed file transfer service earlier this year. Unit 42 is monitoring the combined activity as the "TiltedTemple" campaign.
Post-exploitation activities following a successful compromise involve the actor uploading a new dropper ("msiexec.exe") to victim systems, which then deploys the Chinese-language JSP web shell named "Godzilla" for establishing persistence in those machines, echoing similar tactics used against the ADSelfService software.
Unit 42 identified that there are currently over 4,700 internet-facing instances of ServiceDesk Plus globally, of which 2,900 (or 62%) spanning across the U.S., India, Russia, Great Britain, and Turkey are assessed to be vulnerable to exploitation.
Over the past three months, at least two organizations have been compromised using the ManageEngine ServiceDesk Plus flaw, a number that's expected to climb further as the APT group ramps up its reconnaissance activities against technology, energy, transportation, healthcare, education, finance, and defense industries.
Zoho, for its part, has made available an exploit detection tool to help customers identify whether their on-premises installations have been compromised, in addition to recommending that users "upgrade to the latest version of ServiceDesk Plus (12001) immediately" to mitigate any potential risk arising out of exploitation.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/12/cisa-warns-of-actively-exploited.html