ZeroHour
Infosecurity Magazinepublished ()ingested Phil Muncaster

Clop Starts MOVEit Extortion as New Bug is Discovered

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-34362
Unauthenticated SQL Injection in Progress MOVEit Transfer

CVE-2023-34362 is an unauthenticated SQL injection flaw (CWE-89) in Progress MOVEit Transfer that allows an attacker with no credentials to gain unauthorized access to the product's database. It is triggered remotely via crafted input submitted to the MOVEit Transfer web application, with the impact varying by the backend database engine in use (MySQL, Microsoft SQL Server, or Azure SQL). A successful attacker can infer the structure and contents of the database and, depending on the engine, execute SQL statements that alter or delete database elements, exposing data handled by the file-transfer service. Any organization running an internet-reachable MOVEit Transfer instance is affected; public internet-exposure scans around disclosure identified on the order of a few thousand servers, each typically serving enterprise or government user bases. Exploitation is confirmed in the wild: the flaw was added to CISA KEV on 2023-06-02 with known ransomware use and an EPSS exploitation probability of 99.9% (100th percentile), while no public PoC is known.

Do: Apply the vendor's updates immediately, per Progress instructions and CISA's required action. Until patched, restrict internet exposure of MOVEit Transfer and check the backend database for unexpected structure or content changes and deletions. Because in-the-wild exploitation and ransomware use are confirmed, treat any unpatched, internet-facing instance as potentially compromised and review stored transfer data and access logs for anomalies.

9.8100% KEV ransomware PoC
  • Progress MOVEit Transfer
large≈2,000-3,000 internet-exposed MOVEit Transfer servers (public internet-exposure scans)
CVE-2023-35036
In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilit

In Progress MOVEit Transfer before 2021.0.7 (13.0.7), 2021.1.5 (13.1.5), 2022.0.5 (14.0.5), 2022.1.6 (14.1.6), and 2023.0.2 (15.0.2), SQL injection vulnerabilities have been found in the MOVEit Transfer web application that could allow an unauthenticated attacker to gain unauthorized access to MOVEit Transfer's database. An attacker could submit a crafted payload to a MOVEit Transfer application endpoint that could result in modification and disclosure of MOVEit database content.

NVD description · AI analysis pending
9.113%
  • progress moveit transfer
Full article397 words · extracted from infosecurity-magazine.com · click to collapse

The Clop ransomware gang has begun publishing names of the organizations impacted by its recent data theft campaign, as MOVEit developer Progress Software warned customers of yet another newly discovered vulnerability.

Yet to receive a CVE, the new bug is rated critical and “could lead to escalated privileges and potential unauthorized access to the environment,” Progress warned in an update yesterday.

Read more on the original MOVEit flaw: Critical Zero-Day Flaw Exploited in MOVEit Transfer.

Although the vendor has patched MOVEit Cloud and fully restored all clusters, MOVEit Transfer customers are being asked to immediately disable all HTTP and HTTPS traffic in order to mitigate the risk of a breach, while Progress releases an official update.

This is the third vulnerability discovered in recent weeks in the popular managed file transfer software, following SQLi bug CVE-2023-34362, which was exploited by the Clop gang to compromise what it claims to be hundreds of global customers.

That vulnerability was patched by Progress on May 31, while a second SQLi vulnerability, CVE-2023-35036, was fixed on June 9.

True to its promise, Clop began releasing the names of its victims on a dedicated leak site yesterday, as the deadline expired for them to pay a ransom.

Emsisoft threat analyst, Brett Callow, claimed there were 47 confirmed victims as of late Thursday, plus an unspecified number of US government agencies.

Among the new names revealed by Clop are energy giant Shell and the University of Georgia. They join household names like BA, Boots, the BBC and Ireland’s health service (HSE).

Charl Van Der Walt, head of security research at Orange Cyberdefense, argued that the extortionists will probably try to ramp up the tension by drip feeding details of their victims.

“With this hack, it’s very likely that we don’t see all the data brought to light in one go; instead, we may see something eye-catching that will make industry and regulatory bodies stand up and take notice especially as most threat actors want to drag these out for as long as they can, partly to maintain the attention and build notoriety,” he explained.

“These actors often try to build a narrative about what they leak, doing their best to justify their actions or get a reaction from their victims.”

The US Cybersecurity and Infrastructure Security Agency (CISA) is thought to be assisting government victims of the attacks.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/clop-starts-moveit-extortion-new/