ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews1

XE Hacker Group Exploits VeraCore Zero

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2017-9248
Cryptographic key leak (CWE-522) in Progress Telerik UI for ASP.NET AJAX & Sitefinity

Progress Telerik UI for ASP.NET AJAX (Telerik.Web.UI.dll) before R2 2017 SP1 and Progress Sitefinity before 10.0.6412.0 fail to adequately protect the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey (CWE-522, insufficient key/credential protection). A remote, unauthenticated attacker can send crafted requests to the component's encrypted dialog-parameter handler to recover the dialog encryption key and then leak the MachineKey, and a public proof-of-concept exists (Exploit-DB 43873). With the MachineKey in hand, the attacker can forge or decrypt ASP.NET ViewState, upload or download arbitrary files, and inject XSS, which on IIS servers commonly chains to remote code execution via malicious ViewState. Any website or application embedding the vulnerable Telerik UI assembly, including older Sitefinity CMS releases, is affected. The flaw is confirmed exploited in the wild: it is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), carries a 75.1% EPSS score (99th percentile), and its use in ransomware campaigns is unknown.

Do: Upgrade Telerik UI for ASP.NET AJAX to R2 2017 SP1 or later and Sitefinity to 10.0.6412.0 or later per vendor instructions, as required by CISA's KEV listing. After patching, rotate the Telerik.Web.UI.DialogParametersEncryptionKey and the ASP.NET MachineKey, because keys leaked before patching remain usable to forge ViewState. Review IIS logs for requests to Telerik dialog handler endpoints and for unexpected file uploads, downloads, or ViewState-related anomalies.

9.875% KEV PoC
  • Progress (Telerik) UI for ASP.NET AJAX (Telerik.Web.UI.dll) all versions before R2 2017 SP1
  • Progress (Telerik) Sitefinity all versions before 10.0.6412.0
largetens of thousands of internet-exposed vulnerable installations (estimate)
CVE-2019-18935
Unauthenticated .NET Deserialization RCE in Progress Telerik UI for ASP.NET AJAX

CVE-2019-18935 is a .NET deserialization flaw (CWE-502) in the RadAsyncUpload function of Progress Telerik UI for ASP.NET AJAX through version 2019.3.1023. It is triggered when an attacker who knows the Telerik upload encryption keys — most commonly because the earlier flaws CVE-2017-11317 or CVE-2017-11357 exposed them, though keys can be obtained by other means — sends crafted serialized data to RadAsyncUpload, allowing remote code execution without authentication. Successful exploitation gives an attacker arbitrary code execution on the hosting IIS/ASP.NET web server, reflected in the critical 9.8 CVSS score. Any web application built with Telerik UI for ASP.NET AJAX at or below 2019.3.1023 is affected, unless 2019.3.1023 has the non-default hardening setting enabled (as of 2020.1.114 a default setting prevents the exploit). Exploitation is rampant in the wild: the flaw was added to CISA KEV on 2021-11-03 with known ransomware use, carries a 99.7% EPSS probability of exploitation, has multiple public exploits (Bishop Fox, RAU_crypto, noperator), and has been used by multiple threat groups — including ransomware and government-linked actors — to breach organizations including a U.S. federal agency.

Do: Upgrade to Progress Telerik UI for ASP.NET AJAX 2020.1.114 or later, where a default setting prevents exploitation (or, if staying on 2019.3.1023, enable the non-default hardening setting); per CISA KEV, apply updates per vendor instructions. Because exploitation requires the encryption keys to be known, also patch the older CVE-2017-11317/CVE-2017-11357 key-disclosure flaws or rotate the Telerik upload encryption keys. Check internet-facing IIS/ASP.NET applications for exposed RadAsyncUpload handlers and indicators of compromise, given known ransomware and federal-agency breaches.

9.8100% KEV ransomware PoC ×4
  • Telerik (Progress) UI for ASP.NET AJAX All versions through 2019.3.1023 (RadAsyncUpload exploitable when encryption keys are known; 2019.3.1023 requires a non-default setting to prevent exploitation;
largeTens of thousands of internet-exposed ASP.NET/IIS web applications using Telerik controls (order-of-magnitude estimate)
CVE-2020-15069
Unauthenticated Buffer Overflow RCE in Sophos XG Firewall

CVE-2020-15069 is a critical buffer overflow (CWE-120) in the HTTP/S Bookmarks feature used for clientless access in Sophos XG Firewall, affecting firmware versions 17.x through v17.5 MR12. The flaw is reachable over the network without credentials or user interaction, so an unauthenticated attacker can trigger it by sending crafted requests to the exposed bookmarks functionality. Successful exploitation yields remote code execution on the firewall with high impact on confidentiality, integrity, and availability. Any organization running Sophos XG Firewall 17.x through v17.5 MR12 is affected, especially firewalls with the clientless-access feature enabled or management interfaces reachable from the internet. Sophos published hotfix HF062020.1 for all firewalls running v17.x, and the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-02-06, indicating confirmed in-the-wild exploitation (EPSS puts the 30-day exploitation probability at about 10.7%).

Do: Apply hotfix HF062020.1, which Sophos published for all firewalls running v17.x, or upgrade to a current supported release, prioritizing internet-exposed devices. Verify the hotfix is actually installed rather than assuming auto-update succeeded, and disable or restrict the clientless HTTP/S Bookmarks feature as interim mitigation. Review firewall logs for signs of unexpected access or compromise, since exploitation has been confirmed in the wild.

9.811% KEV
  • sophos XG Firewall firmware 17.x through v17.5 MR12
mass≈ hundreds of thousands of firewall deployments, with likely tens of thousands still running unpatched v17.x (internet-wide scans have historically shown…
CVE-2020-29574
Unauthenticated SQL Injection in Sophos CyberoamOS WebAdmin

CVE-2020-29574 is a critical (CVSS 9.8) SQL injection flaw (CWE-89) in the WebAdmin management console of Sophos CyberoamOS (CROS), the operating system of Cyberoam network security appliances acquired by Sophos. An unauthenticated remote attacker can send crafted requests to the exposed WebAdmin interface and execute arbitrary SQL statements against the backend database, with no credentials or user interaction required. Successful exploitation can reveal or alter firewall management data and facilitate further compromise; CISA notes it is being used in ransomware operations. Any organization still running a CyberoamOS appliance is affected, and CISA flags the product as end-of-life/end-of-service, so no current support exists. The flaw was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06; no public PoC is known, but exploitation in the wild is confirmed.

Do: Because CyberoamOS is end-of-life/end-of-service, CISA's required action is to discontinue use: migrate Cyberoam appliances to a currently supported Sophos Firewall release or retire them. Until migration, restrict WebAdmin access to trusted management networks rather than the public internet, review appliance logs for unexpected administrative or database activity, and hunt for signs of compromise given the known ransomware use.

9.85% KEV ransomware
  • Sophos CyberoamOS (CROS) - WebAdmin all versions through 2020-12-04 (CISA date-based range); product is EoL/EoS
largetens of thousands of deployed appliances (installed-base estimate; internet-exposed WebAdmin consoles likely in the low thousands)
CVE-2022-23748
DLL Sideloading Vulnerability in Audinate Dante Discovery (mDNSResponder.exe)

Audinate Dante Discovery's mDNSResponder.exe executable improperly specifies how, from which folder, and under what conditions it loads DLLs, enabling a DLL sideloading attack (CWE-114/CWE-426). An attacker who can place a crafted malicious DLL where the legitimate executable searches for libraries can trigger it to be loaded when the binary runs; the CVSS vector (AV:L, UI:R) indicates local access and some user interaction are required to start the vulnerable process. Because the malicious code executes under the cover of a valid, legitimate executable, the attacker gains code execution with high impact on confidentiality, integrity, and availability. The flaw affects Windows hosts running Audinate's Dante Discovery component, which ships with Dante software tooling and the Dante Application Library used in professional audio networking deployments. It was added to the CISA Known Exploited Vulnerabilities catalog on 2025-02-06, confirming exploitation in the wild; EPSS puts the 30-day exploitation probability at 9.1% (95th percentile), no public PoC is known, and ransomware use is unknown.

Do: Apply Audinate's mitigations or upgrade Dante Discovery / Dante Application Library to the latest vendor-recommended release per the CISA KEV required action, and discontinue use of the affected component if mitigations are unavailable. On Windows hosts, check for unexpected or unrecognized DLL files in the directory from which mDNSResponder.exe runs (and its DLL search paths), and restrict write permissions on the application folder to prevent malicious DLL placement. Given the KEV listing and 95th-percentile EPSS, prioritize patching internet-relevant and audio-control workstations in broadcast, live production, and installed-sound environments.

7.89% KEV
  • Audinate Dante Discovery (Dante Application Library component, mDNSResponder.exe)
large≈ hundreds of thousands of Windows hosts running Audinate Dante software (Dante Controller/Discovery and Dante Application Library deployments)
CVE-2024-21413
Improper Input Validation RCE in Microsoft Outlook (MonikerLink)

CVE-2024-21413 is an improper input validation flaw (CWE-20) in Microsoft Outlook, publicly dubbed "MonikerLink", in which Outlook mishandles a specially crafted hyperlink (a file:// moniker link) and bypasses the security prompt normally applied before opening such links. The flaw is triggered when a user opens or clicks a maliciously crafted link in an email, causing Outlook to invoke the target outside its protected handling. A successful attack can leak the user's NTLM credentials and can achieve remote code execution in the context of the current user; the flaw carries a critical CVSS 3.1 score of 9.8. Anyone running affected Outlook clients — Microsoft 365 Apps, Office 2016, Office 2019, and Office LTSC — is exposed, and the issue was fixed in Microsoft's February 2024 Patch Tuesday release. Exploitation is confirmed in the wild: CISA added the flaw to its Known Exploited Vulnerabilities catalog on 2025-02-06, EPSS assigns a ~95% exploitation probability (100th percentile), and a public PoC is available.

Do: Apply Microsoft's February 2024 (or later) security updates for Microsoft 365 Apps, Office 2016, Office 2019, and Office LTSC, and verify Outlook builds are current, per the KEV required action to apply vendor mitigations or discontinue use. As interim mitigation, restrict outbound SMB/NTLM from endpoints (e.g., block outbound port 445 or disable NTLM where feasible) to blunt credential leakage from crafted file:// links. Hunt for signs of exploitation, such as unexpected outbound SMB connections or NTLM authentication events following users clicking links in email.

9.895% KEV PoC
  • Microsoft 365 Apps (Outlook)
  • microsoft Office 2016 (Outlook) all builds prior to the February 2024 security updates
  • microsoft Office 2019 (Outlook) all builds prior to the February 2024 security updates
  • +1 more
masshundreds of millions of users
CVE-2024-57968
+1 in the same advisory: …25181
Unrestricted File Upload in Advantive VeraCore upload.aspx

Advantive VeraCore, a warehouse management and order fulfillment platform, contains an unrestricted file upload flaw (CWE-434) in its upload.aspx endpoint that fails to properly restrict what files can be uploaded and where they are stored. A remote attacker with no credentials can abuse the endpoint to write files into unintended, attacker-influenced folders on the server. By placing crafted files (for example, script files) into web-reachable directories, an attacker can typically escalate an arbitrary upload into webshell deployment and code execution on the hosting server. Any organization running VeraCore, especially instances with the upload endpoint reachable from the internet, is exposed. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-03-10, indicating active exploitation, and EPSS assigns a 32.3% probability of exploitation within 30 days (98th percentile).

Do: Apply the mitigations required under CISA KEV/BOD 22-01, following Advantive's instructions, and contact the vendor for the fixed release since no patched version is specified in the available data. In the interim, restrict network access to upload.aspx (allow only trusted users or VPN/internal traffic), enforce file-type and destination validation at a WAF/reverse proxy where possible, and hunt for unexpected or recently modified files in VeraCore's web directories plus suspicious entries in web access logs to detect webshells or uploaded payloads.

8.8
group max
32% KEV PoC ×2
  • Advantive VeraCore
nicheroughly hundreds to low thousands of deployments (fulfillment/3PL and e-commerce operations running VeraCore)
CVE-2025-0411
Mark-of-the-Web Bypass in 7-Zip Enables Code Execution via Crafted Archives

CVE-2025-0411 is a protection-mechanism bypass in 7-Zip's handling of archived files: when extracting a crafted archive that carries the Mark-of-the-Web, 7-Zip fails to propagate the MotW flag to the extracted files. Exploitation requires user interaction, as the target must visit a malicious page or open a malicious archive. Because the extracted files lose their MotW designation, Windows skips its usual security prompts on attacker-supplied executables or scripts, allowing arbitrary code execution in the context of the current user. Anyone running affected 7-Zip installations is exposed, including NetApp Active IQ Unified Manager deployments that incorporate 7-Zip. The flaw was exploited as a zero-day — Russian cybercrime groups and SmokeLoader campaigns, notably targeting Ukrainian organizations, abused it — and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-06.

Do: Upgrade 7-Zip to the latest patched release per vendor guidance, and for NetApp Active IQ Unified Manager apply the update specified in NetApp's security advisory; the CISA KEV required action is to apply vendor mitigations or discontinue use. Until patched, treat archives from untrusted sources with caution and verify extracted executables manually, since MotW prompts will not fire on extracted files. Hunt for signs of SmokeLoader-style post-extraction execution in user workstations.

7.067% KEV
  • 7-Zip
  • NetApp Active IQ Unified Manager
masstens of millions of users (7-Zip is among the most widely deployed Windows archive utilities, plus NetApp-bundled deployments)
Full article777 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 10, 2025Vulnerability / Malware

Threat actors have been observed exploiting multiple security flaws in various software products, including Progress Telerik UI for ASP.NET AJAX and Advantive VeraCore, to drop reverse shells and web shells, and maintain persistent remote access to compromised systems.

The zero-day exploitation of security flaws in VeraCore has been attributed to a threat actor known as XE Group, a cybercrime group likely of Vietnamese origin that's known to be active since at least 2010.

"XE Group transitioned from credit card skimming to targeted information theft, marking a significant shift in their operational priorities," cybersecurity firm Intezer said in a report published in collaboration with Solis Security.

"Their attacks now target supply chains in the manufacturing and distribution sectors, leveraging new vulnerabilities and advanced tactics."

The vulnerabilities in question are listed below -

  • CVE-2024-57968 (CVSS score: 9.9) - An unrestricted upload of files with a dangerous type vulnerability that allows remote authenticated users to upload files to unintended folders (Fixed in VeraCore version 2024.4.2.1)
  • CVE-2025-25181 (CVSS score: 5.8) - An SQL injection vulnerability that allows remote attackers to execute arbitrary SQL commands (No patch available)

The latest findings from Intezer and Solis Security show that the shortcomings are being chained to deploy ASPXSpy web shells for unauthorized access to infected systems, in one instance leveraging CVE-2025-25181 as far back as early 2020. The exploitation activity was discovered in November 2024.

The web shells come fitted with capabilities to enumerate the file system, exfiltrate files, and compress them using tools like 7z. The access is also abused to drop a Meterpreter payload that attempts to connect to an actor-controlled server ("222.253.102[.]94:7979") via a Windows socket.

The updated variant of the web shell also incorporates a variety of features to facilitate network scanning, command execution, and running SQL queries to extract critical information or modify existing data.

While previous attacks mounted by XE Group have weaponized known vulnerabilities, namely flaws in Telerik UI for ASP.NET (CVE-2017-9248 and CVE-2019-18935, CVSS scores: 9.8), the development marks the first time the hacking crew has been attributed to zero-day exploitation, indicating an increase in sophistication.

"Their ability to maintain persistent access to systems, as seen with the reactivation of a web shell years after initial deployment, highlights the group's commitment to long-term objectives," researchers Nicole Fishbein, Joakim Kennedy, and Justin Lentz said.

"By targeting supply chains in the manufacturing and distribution sectors, XE Group not only maximizes the impact of their operations but also demonstrates an acute understanding of systemic vulnerabilities."

CVE-2019-18935, which was flagged by U.K. and U.S. government agencies in 2021 as one of the most exploited vulnerabilities, has also come under active exploitation as recently as last month to load a reverse shell and execute follow-up reconnaissance commands via cmd.exe.

"While the vulnerability in Progress Telerik UI for ASP.NET AJAX is several years old, it continues to be a viable entry point for threat actors," eSentire said. "This highlights the importance of patching systems, especially if they are going to be exposed to the internet."

CISA Adds 5 Flaws to KEV Catalog

The development comes as the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added five security flaws to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

  • CVE-2025-0411 (CVSS score: 7.0) - 7-Zip Mark of the Web Bypass Vulnerability
  • CVE-2022-23748 (CVSS score: 7.8) - Dante Discovery Process Control Vulnerability
  • CVE-2024-21413 (CVSS score: 9.8) - Microsoft Outlook Improper Input Validation Vulnerability
  • CVE-2020-29574 (CVSS score: 9.8) - CyberoamOS (CROS) SQL Injection Vulnerability
  • CVE-2020-15069 (CVSS score: 9.8) - Sophos XG Firewall Buffer Overflow Vulnerability

Last week, Trend Micro revealed that Russian cybercrime outfits are exploiting CVE-2025-0411 to distribute the SmokeLoader malware as part of spear-phishing campaigns targeting Ukrainian entities.

The exploitation of CVE-2020-29574 and CVE-2020-15069, on the other hand, has been linked to a Chinese espionage campaign tracked by Sophos under the moniker Pacific Rim.

There are currently no reports on how CVE-2024-21413, also tracked as MonikerLink by Check Point, is being exploited in the wild. As for CVE-2022-23748, the cybersecurity company disclosed in late 2022 that it observed the ToddyCat threat actor leveraging a DLL side-loading vulnerability in Audinate Dante Discovery ("mDNSResponder.exe").

Federal Civilian Executive Branch (FCEB) agencies are mandated to apply the necessary updates by February 27, 2025, under Binding Operational Directive (BOD) 22-01 to safeguard against active threats.

(The story was updated after publication to correctly mention that CVE-2024-57968 was patched in VeraCore version 2024.4.2.1, and not VeraCode version 2024.4.2.1.)

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/02/xe-hacker-group-exploits-veracore-zero.html