ZeroHour
Security Affairspublished ()ingested @securityaffairs

Chinese hacking group DEV-0322 behind Solarwinds Serv

criticalExploit / PoC exploited in the wildimportance 60CVE-2021-35211CVE-2020-10148

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-10148
Authentication Bypass in SolarWinds Orion API (CVE-2020-10148)

The SolarWinds Orion API contains a critical authentication bypass (CWE-288/CWE-306, CVSS 9.8) that allows a remote, unauthenticated attacker to execute API commands on the Orion Platform. It is triggered by specially crafted requests to the Orion API that reach endpoints with authorization skipped, requiring no privileges or user interaction. By issuing these API commands, an attacker can take control of the SolarWinds instance; in observed intrusions, the flaw was used to install the SUPERNOVA webshell on Orion servers. Any organization running Orion Platform 2019.4 HF 5, 2020.2 with no hotfix installed, or 2020.2 HF 1 is affected. Exploitation is in the wild: the flaw is listed in CISA's KEV (added 2021-11-03), has been linked to the China-nexus actor DEV-0322 per public reporting, and EPSS assigns it a 92% probability of exploitation within 30 days.

Do: Apply the Orion Platform updates/hotfixes per SolarWinds' instructions and move all installations off the affected builds (2019.4 HF 5, 2020.2 without hotfix, 2020.2 HF 1). Until patched, restrict access to the Orion web console and API to trusted networks only. Hunt for compromise by checking for the SUPERNOVA webshell in the Orion web root and reviewing API logs for unauthenticated API command execution.

9.892% KEV
  • SolarWinds Orion Platform 2019.4 HF 5; 2020.2 with no hotfix installed; 2020.2 HF 1
largetens of thousands of Orion deployments (roughly 25,000-33,000 customer sites)
CVE-2021-35211
Unauthenticated RCE (Remote Memory Escape) in SolarWinds Serv-U

Microsoft researchers discovered a remote code execution flaw in SolarWinds Serv-U, an out-of-bounds write (CWE-787) described as a "Remote Memory Escape" in the Windows-based Serv-U products. A remote, unauthenticated attacker can trigger the flaw over the network against servers running a version before 15.2.3 HF2 and gain privileged access to the machine hosting Serv-U, with a maximum CVSS 10.0 score reflecting no required privileges, no user interaction, and impact beyond the application's security scope. Both Serv-U Managed File Transfer and Serv-U Secure FTP for Windows are affected. The vulnerability has been exploited in the wild: Microsoft attributed July 2021 attacks exploiting the Serv-U zero-day to Chinese threat actors, later warned of an uptick in exploitation attempts, and the flaw was added to CISA KEV on 2021-11-03 with known ransomware use.

Do: Upgrade Serv-U to 15.2.3 Hotfix 2 (HF2) or later per SolarWinds' instructions immediately, as the flaw is in CISA KEV with known exploitation including ransomware use. Audit Serv-U servers and their logs for signs of exploitation or compromise, and restrict internet exposure of Serv-U/FTP and SSH ports to trusted parties.

10.091% KEV ransomware
  • SolarWinds Serv-U Managed File Transfer (Windows) before 15.2.3 HF2
  • SolarWinds Serv-U Secure FTP (Windows) before 15.2.3 HF2
largeestimated tens of thousands of Serv-U deployments worldwide, with a few thousand instances directly internet-exposed
Full article660 words · extracted from securityaffairs.com · click to collapse

Microsoft attributes the recent attacks that have targeted SolarWinds file transfer servers to a China-linked APT group that the experts tracked as DEV-0322.

Microsoft said that the recent attacks against SolarWinds file transfer servers were carried out by a Chinese hacking group tracked as DEV-0322.

This week SolarWinds addressed a zero-day remote code execution flaw (CVE-2021-35211) in Serv-U products which is actively exploited in the wild by a single threat actor.

SolarWinds was informed of the zero-day by Microsoft, the issue affects Serv-U Managed File Transfer Server and Serv-U Secured FTP. According to Microsoft, the flaw was exploited in attacks against a limited, targeted set of customers by a single threat actor.

The issue resides in Serv-U version 15.2.3 HF1 and all prior versions, the vendor released Serv-U version 15.2.3 hotfix (HF) 2 to fix the issue. All other SolarWinds and N-able (formerly SolarWinds MSP) are not affected by this issue, including the Orion Platform, and all Orion Platform modules. 

“Microsoft reported to SolarWinds that they had discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product. Microsoft provided a proof of concept of the exploit. If exploited, a threat actor may be able to gain privileged access to the threat actor on the machine hosting Serv-U.” reads the advisory published by SolarWinds. “Microsoft has provided evidence of limited, targeted customer impact, though SolarWinds does not currently have an estimate of how many customers may be directly affected by the vulnerability.”

The experts pointed out that this issue is not linked to the SolarWinds supply chain attack.

Now Microsoft provided further details about the attacks and the attack chain used by the threat actors.

The researchers refer to the threat actor as a DEV, which means that it is classified as a “development group,” and assign each DEV group a unique number (DEV-####) for tracking purposes. Microsoft has observed DEV-0322 targeting entities in the U.S. Defense Industrial Base Sector and software companies. According to the experts, the APT group is based in China and employed commercial VPN solutions and compromised consumer routers in their attacker infrastructure.

Microsoft first spotted the DEV-0322 attacks by analyzing the Microsoft 365 Defender telemetry during a routine investigation. 

“MSTIC discovered the 0-day attack behavior in Microsoft 365 Defender telemetry during a routine investigation. An anomalous malicious process was found to be spawning from the Serv-U process, suggesting that it had been compromised.” reads the post published by Microsoft.

Microsoft also provided detection guidance to allow admins to check for indicators of compromise within their infrastructure.

“Customers should review the Serv-U DebugSocketLog.txt log file for exception messages like the line below. A C0000005; CSUSSHSocket::ProcessReceive exception can indicate that an exploit was attempted, but it can also appear for unrelated reasons. Either way, if the exception is found, customers should carefully review their logs for behaviors and indicators of compromise discussed here.” continues Microsoft.

This isn’t the first time that Chinese hacking groups target SolarWinds solutions, experts also spotted another China-linked APT group, tracked as Spiral, targeting the vendor.

Researchers at Secureworks’ counter threat unit (CTU) were investigating the exploit of SolarWinds servers to deploy the Supernova web shell when collected evidence that linked the malicious activity to the Spiral cyberespionage group.

The attackers were observed exploiting the CVE-2020-10148 authentication bypass issue in the SolarWinds Orion API to remotely execute API commands.

Once the attackers have exploited the issue on a vulnerable server, they have deployed the Supernova web shell to disk using a PowerShell command.

SolarWinds customers using Serv-U file transfer servers have to install their company’s patch, the company also recommends disabling SSH access to the server as temporary mitigation.

Unfortunately, the number of SolarWinds Serv-U systems that exposed the SSH port online is still high and hasn’t decreased since the disclosure of the recent wave of attacks.

Follow me on Twitter: @securityaffairs and Facebook

[adrotate banner=”9″][adrotate banner=”12″]

Pierluigi Paganini

(SecurityAffairs – hacking, SolarWinds)

[adrotate banner=”5″]

[adrotate banner=”13″]



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/120084/apt/china-dev-0322-solarwinds-attacks.html