ZeroHour
The Recordpublished ()ingested

CISA: US agency breached by cybercriminals, gov’t hackers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-11317
+1 in the same advisory: …11357
Unrestricted File Upload / RCE in Progress Telerik UI for ASP.NET AJAX

Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and in R2 releases before R2 2017 SP2 uses weak encryption for the RadAsyncUpload component, allowing unauthenticated remote attackers to forge upload parameters, upload arbitrary files to the web server, and ultimately execute arbitrary code. The flaw is triggered simply by sending crafted requests to the vulnerable upload handler over the network, with no authentication or user interaction required. Successful exploitation gives an attacker arbitrary file upload and remote code execution in the context of the ASP.NET application, which is typically hosted on IIS web servers. Any site or application built with Telerik UI for ASP.NET AJAX is affected, and the weakness is confirmed exploited in the wild: it was added to CISA's Known Exploited Vulnerabilities catalog on 2022-04-11, and related reporting describes multiple hacking groups — including IIS/ASP.NET-focused APT actors — breaching a U.S. federal agency through it.

Do: Upgrade Telerik UI for ASP.NET AJAX to R1 2017 or R2 2017 SP2 (or later) per vendor instructions, and verify the deployed Telerik.Web.UI.dll version in each application's bin folder. Given active in-the-wild exploitation of IIS/ASP.NET applications, review affected web servers for unauthorized uploads and web shells and rotate ASP.NET machine keys used with RadAsyncUpload.

9.884% KEV PoC ×2
  • Telerik (Progress) UI for ASP.NET AJAX (Telerik.Web.UI / RadAsyncUpload) before R1 2017; R2 releases before R2 2017 SP2
large≈tens of thousands of internet-exposed ASP.NET/IIS applications; the total installed base (including internal apps) is plausibly far larger
CVE-2017-9248
Cryptographic key leak (CWE-522) in Progress Telerik UI for ASP.NET AJAX & Sitefinity

Progress Telerik UI for ASP.NET AJAX (Telerik.Web.UI.dll) before R2 2017 SP1 and Progress Sitefinity before 10.0.6412.0 fail to adequately protect the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey (CWE-522, insufficient key/credential protection). A remote, unauthenticated attacker can send crafted requests to the component's encrypted dialog-parameter handler to recover the dialog encryption key and then leak the MachineKey, and a public proof-of-concept exists (Exploit-DB 43873). With the MachineKey in hand, the attacker can forge or decrypt ASP.NET ViewState, upload or download arbitrary files, and inject XSS, which on IIS servers commonly chains to remote code execution via malicious ViewState. Any website or application embedding the vulnerable Telerik UI assembly, including older Sitefinity CMS releases, is affected. The flaw is confirmed exploited in the wild: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 75.1% EPSS score (99th percentile), and its use in ransomware campaigns is unknown.

Do: Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP1 or later and Sitefinity to 10.0.6412.0 or later per vendor instructions, as required by CISA's KEV listing. After patching, rotate the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey, because keys leaked before patching remain usable to forge ViewState. Review IIS logs for requests to Telerik dialog handler endpoints and for unexpected file uploads, downloads, or ViewState-related anomalies.

9.875% KEV PoC
  • Progress (Telerik) UI for ASP.NET AJAX (Telerik.Web.UI.dll) all versions before R2 2017 SP1
  • Progress (Telerik) Sitefinity all versions before 10.0.6412.0
largetens of thousands of internet-exposed vulnerable installations (estimate)
CVE-2019-18935
Unauthenticated .NET Deserialization RCE in Progress Telerik UI for ASP.NET AJAX

CVE-2019-18935 is a .NET deserialization flaw (CWE-502) in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023. It is triggered when an attacker who knows the Telerik upload encryption keys — most commonly because the earlier flaws CVE-2017-11317 or CVE-2017-11357 exposed them, though keys can be obtained by other means — sends crafted serialized data to RadAsyncUpload, allowing remote code execution without authentication. Successful exploitation gives an attacker arbitrary code execution on the hosting IIS/ASP.NET web server, reflected in the critical 9.8 CVSS score. Any web application built with Telerik UI for ASP.NET AJAX at or below 2019.3.1023 is affected, unless 2019.3.1023 has the non-default hardening setting enabled (as of 2020.1.114 a default setting prevents the exploit). Exploitation is rampant in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, carries a 99.7% EPSS probability of exploitation, has multiple public exploits (Bishop Fox, RAU_crypto, noperator), and has been used by multiple threat groups — including ransomware and government-linked actors — to breach organizations including a U.S. federal agency.

Do: Upgrade to Progress Telerik UI for ASP.NET AJAX 2020.1.114 or later, where a default setting prevents exploitation (or, if staying on 2019.3.1023, enable the non-default hardening setting); per CISA KEV, apply updates per vendor instructions. Because exploitation requires the encryption keys to be known, also patch the older CVE-2017-11317/CVE-2017-11357 key-disclosure flaws or rotate the Telerik upload encryption keys. Check internet-facing IIS/ASP.NET applications for exposed RadAsyncUpload handlers and indicators of compromise, given known ransomware and federal-agency breaches.

9.8100% KEV ransomware PoC ×4
  • Telerik (Progress) UI for ASP.NET AJAX All versions through 2019.3.1023 (RadAsyncUpload exploitable when encryption keys are known; 2019.3.1023 requires a non-default setting to prevent exploitation;
largeTens of thousands of internet-exposed ASP.NET/IIS web applications using Telerik controls (order-of-magnitude estimate)
Full article623 words · extracted from therecord.media · click to collapse

Cybercriminals and a government-backed hacking group had access to the systems of an unnamed federal civilian executive branch agency from August 2022 to January 2023.

In a report released Wednesday by the Cybersecurity and Infrastructure Security Agency (CISA), FBI and other agencies, officials said hackers used several vulnerabilities affecting products from Bulgarian software developer Progress Telerik.

The hackers primarily exploited CVE-2019-18935 – a vulnerability that several cybersecurity agencies across the globe ranked as one of the most exploited security flaws throughout 2020 and 2021.

The vulnerability has been used mainly by an APT group named “Praying Mantis” – which Australian researchers have claimed is based in China. The report released Wednesday did not name Praying Mantis.

CISA described an attack pattern identical to one highlighted by Syngia and several other cybersecurity companies in 2021. CISA said the vulnerability affects all versions of Progress Telerik software made before 2020 and gave attackers a foothold in the agency’s Microsoft Internet Information Services (IIS) web server, which is used for hosting material online.

“This exploit, which results in interactive access with the web server, enabled the threat actors to successfully execute remote code on the vulnerable web server,” CISA said.

The agency explained that its vulnerability scanner failed to detect the issue because the Progress Telerik tool was installed in an area of the system that they do not scan.

“This may be the case for many software installations, as file paths widely vary depending on the organization and installation method,” CISA added.

The version of the Progress Telerik tool that was exploited also has several other vulnerabilities that were used by the hackers, including CVE-2017-11357, CVE-2017-11317, and CVE-2017-9248.

CISA explained that the main vulnerability was exploited in conjunction with either CVE-2017-11357 or CVE-2017-11317 – vulnerabilities “present in older, unpatched versions of Telerik released between 2007 and 2017.”

The advisory notes that there is no forensic evidence to definitively confirm whether CVE-2017-11357 or CVE-2017-11317 were involved in the attacks.

In addition to the government-backed hacking group that used the vulnerability, a cybercriminal actor known as XE Group was also seen conducting reconnaissance and scanning activities through the bug.

Cybersecurity firm Volexity said in 2021 the group is based in Vietnam and made a name for itself through its compromise of Progress Telerik products. They have launched credit card skimming attacks against travel, restaurants and non-profit websites.

“XE Group's credit card skimming operation has been ongoing since at least early 2020, using a relatively limited set of infrastructure. The attacker primarily focuses on compromising IIS environments and uses their access to deploy credit card skimming JavaScript code on affected websites,” the company said.

CISA noted that the actors used malware to remove files that made it difficult for a forensic analysis to be conducted after the fact. But they confirmed that there was no evidence that the hackers escalated their privileges or moved laterally within the network.

CISA did not respond to requests for comment about whether data was stolen during the incident. Google’s Threat Analysis Group (TAG) helped the agencies with some of the report, according to CISA.

“CISA, FBI, and MS-ISAC [Multi-State Information Sharing and Analysis Center] recommend that organizations utilize a centralized log collection and monitoring capability, as well as implement or increase logging and forensic data retention. Longer retention policies improve the availability of data for forensic analysis and aid thorough identification of incident scope,” the advisory explained.

No previous article

No new articles

Jonathan Greig

is a Breaking News Reporter at Recorded Future News. Jonathan has worked across the globe as a journalist since 2014. Before moving back to New York City, he worked for news outlets in South Africa, Jordan and Cambodia. He previously covered cybersecurity at ZDNet and TechRepublic.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-us-agency-breached-by-cybercriminals