ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Zoho ManageEngine PoC Exploit to be Released Soon

criticalExploit / PoCimportance 60CVE-2022-47966

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-47966
Unauthenticated SAML RCE in Zoho ManageEngine On-Premise Products

CVE-2022-47966 is a critical (CVSS 9.8), unauthenticated remote code execution flaw in roughly two dozen Zoho ManageEngine on-premise products caused by their bundled Apache Santuario xmlsec (XML Security for Java) 1.4.1 library, in which the XSLT features leave security protections to the application and ManageEngine did not provide them. An attacker triggers the flaw by sending a crafted SAML response containing a malicious XSLT transform to the SAML single sign-on (SSO) endpoint; exploitation is only possible if SAML SSO has ever been configured for the product (for some products, SAML SSO must be currently active). Successful exploitation yields arbitrary code execution in the context of the affected ManageEngine application, typically full compromise of the server and a foothold into the wider enterprise network. Any organization running an affected product version with SAML SSO enabled is affected, with internet-exposed ITSM/identity-management servers the most likely targets. Exploitation is confirmed in the wild: the flaw is in CISA KEV with known ransomware use, Rapid7 reported broad attacker interest, North Korea's Lazarus Group used it to deploy QuiteRAT, and Iranian government-backed actors have targeted U.S. energy and transit-sector organizations.

Do: Apply vendor updates immediately, upgrading each installed product to at least the fixed version listed (e.g., ServiceDesk Plus 14004+, ADSelfService Plus 6211+, Endpoint Central/Endpoint Central MSP 10.1.2228.11+, Password Manager Pro 12124+, ServiceDesk Plus MSP 13001+, ADAudit Plus 7081+, ADManager Plus 7162+, AD360 4310+); this is a CISA KEV required action. As an interim mitigation, disable or restrict SAML SSO (or limit access to the product's SSO endpoints), since SAML SSO must have been configured for exploitation. Prioritize patching internet-exposed instances and review those servers for signs of compromise, given documented use by Lazarus Group, ransomware operators, and Iranian nation-state actors.

9.8100% KEV ransomware PoC ×6
  • zohocorp ManageEngine Access Manager Plus before 4308
  • zohocorp ManageEngine Active Directory 360 (AD360) before 4310
  • zohocorp ManageEngine ADAudit Plus before 7081
  • +9 more
largetens of thousands of installations plausibly affected (thousands of instances internet-exposed), out of ManageEngine's very large on-prem install base

Indicators of compromiseAll →

TypeIndicatorContext
domainhorizon3.aign-on (SSO) feature enabled, or had it enabled in the past. Horizon3.ai has now released Indicators of Compromise (IOCs) associated
Full article431 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJan 17, 2023Cyber Threat / Vulnerability

Users of Zoho ManageEngine are being urged to patch their instances against a critical security vulnerability ahead of the release of a proof-of-concept (PoC) exploit code.

The issue in question is CVE-2022-47966, an unauthenticated remote code execution vulnerability affecting several products due to the use of an outdated third-party dependency, Apache Santuario.

"This vulnerability allows an unauthenticated adversary to execute arbitrary code," Zoho warned in an advisory issued late last year, noting that it affects all ManageEngine setups that have the SAML single sign-on (SSO) feature enabled, or had it enabled in the past.

Horizon3.ai has now released Indicators of Compromise (IOCs) associated with the flaw, stating that it was able to successfully reproduce the exploit against ManageEngine ServiceDesk Plus and ManageEngine Endpoint Central products.

"The vulnerability is easy to exploit and a good candidate for attackers to 'spray and pray' across the internet," researcher James Horseman said. "This vulnerability allows for remote code execution as NT AUTHORITY\SYSTEM, essentially giving an attacker complete control over the system."

An attacker in possession of such elevated privileges could weaponize it to steal credentials with the goal of conducting lateral movement, the San Francisco-headquartered firm said, adding the threat actor will need to send a specially crafted SAML request to trigger the exploit.

Horizon3.ai further called attention to the fact that there are more than 1,000 instances of ManageEngine products exposed to the internet with SAML currently enabled, potentially turning them into lucrative targets.

It's not uncommon for hackers to exploit awareness of a major vulnerability for malicious campaigns. It's therefore essential that the fixes are installed as soon as possible irrespective of the SAML configuration.

Update: PoC Exploit Released

Horizon3.ai has officially released an exploit for CVE-2022-47966, a critical security flaw in several Zoho ManageEngine products that allows an adversary to gain remote code execution by issuing a HTTP POST request containing a malicious SAML response.

Cybersecurity company Rapid7 disclosed that it's "responding to various compromises arising from the exploitation of CVE-2022-47966" since at least January 17, 2023, with the threat actors weaponizing the flaw to drop PowerShell scripts to disable Microsoft Defender Antivirus real-time protections and download additional remote access tools.

"Organizations using any of the affected products [...] should update immediately and review unpatched systems for signs of compromise, as exploit code is publicly available and exploitation has already begun," Rapid7 researcher Glenn Thorpe said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/01/zoho-manageengine-poc-exploit-to-be.html