Cring Ransomware Gang Exploits 11-Year
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2009-3960 | Information Disclosure in Adobe BlazeDS (Used by LiveCycle and ColdFusion) CVE-2009-3960 is an information disclosure vulnerability in Adobe BlazeDS, the Java-based remoting and messaging layer that ships with Adobe LiveCycle and is available with Adobe ColdFusion. An attacker can trigger the flaw by sending crafted requests to an application running an affected BlazeDS deployment, gaining access to information that should not be exposed. Successful exploitation can leak sensitive data and, as observed in the Cring ransomware campaign against unpatched ColdFusion servers, can serve as an initial foothold that leads to further compromise and ransomware deployment. Organizations running BlazeDS as part of LiveCycle or ColdFusion deployments are affected. The flaw has been exploited in the wild and was added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-07, with ransomware use explicitly confirmed and a very high EPSS of 90%. Do: Apply updates per vendor instructions as required by CISA, upgrading BlazeDS, LiveCycle, and ColdFusion to the patched releases specified in Adobe's advisory. Prioritize internet-facing ColdFusion and LiveCycle servers, verify BlazeDS-related endpoints are patched, and check for signs of compromise given known ransomware use. Until patched, restrict external access to BlazeDS/ColdFusion endpoints where feasible. | — | 90% | KEV ransomware |
| largeon the order of tens of thousands of internet-exposed ColdFusion/LiveCycle servers plausibly affected | |
| CVE-2010-2861 | Directory Traversal in Adobe ColdFusion Administrator Console CVE-2010-2861 is a directory traversal flaw (CWE-22) in the administrator console of Adobe ColdFusion that allows remote attackers to read arbitrary files on the server. It is triggered by sending crafted path-traversal input to the ColdFusion Administrator web interface, letting the attacker walk outside the intended directory. By reading sensitive files such as the server's configuration and administrator credential files, an attacker can obtain ColdFusion admin credentials and frequently escalate to broader system access. Any organization running an affected Adobe ColdFusion release is exposed, especially servers with the CFIDE administrator interface reachable from the internet. The flaw is actively exploited: it is in CISA's KEV (added 2022-03-25) with known ransomware use (including by the Cring gang), and EPSS puts 30-day exploitation probability at 99.7%. Do: Apply the ColdFusion updates per Adobe/vendor instructions as required by CISA, and if patching must wait, restrict or firewall access to the CFIDE administrator console (IP allowlisting or VPN only). Review web logs for path-traversal requests against the administrator console and check hosts for signs of ransomware or unauthorized changes, since exploitation is actively used for ransomware. | — | 100% | KEV ransomware |
| largetens of thousands of internet-exposed ColdFusion servers |
Full article432 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 21, 2021
Unidentified threat actors breached a server running an unpatched, 11-year-old version of Adobe's ColdFusion 9 software in minutes to remotely take over control and deploy file-encrypting Cring ransomware on the target's network 79 hours after the hack.
The server, which belonged to an unnamed services company, was used to collect timesheet and accounting data for payroll as well as to host a number of virtual machines, according to a report published by Sophos and shared with The Hacker News. The attacks originated from an internet address assigned to the Ukrainian ISP Green Floid.
"Devices running vulnerable, outdated software are low-hanging-fruit for cyberattackers looking for an easy way into a target," Sophos principal researcher Andrew Brandt said. "The surprising thing is that this server was in active daily use. Often the most vulnerable devices are inactive or ghost machines, either forgotten about or overlooked when it comes to patching and upgrades."
The British security software firm said the "rapid break-in" was made possible by exploiting an 11-year-old installation of Adobe ColdFusion 9 running on Windows Server 2008, both of which have reached end-of-life.
Upon gaining an initial foothold, the attackers used a wide range of sophisticated methods to conceal their files, inject code into memory, and cover their tracks by overwriting files with garbled data, not to mention disarm security products by capitalizing on the fact that tamper-protection functionalities were turned off.
Specially, the adversary took advantage of CVE-2010-2861, a set of directory traversal vulnerabilities in the administrator console in Adobe ColdFusion 9.0.1 and earlier that could be abused by remote attackers to read arbitrary files, such as those containing administrator password hashes ("password.properties").
In the next stage, the bad actor is believed to have exploited another vulnerability in ColdFusion, CVE-2009-3960, to upload a malicious Cascading Stylesheet (CSS) file to the server, consequently using it to load a Cobalt Strike Beacon executable. This binary, then, acted as a conduit for the remote attackers to drop additional payloads, create a user account with admin privileges, and even disable endpoint protection systems and anti-malware engines like Windows Defender, before commencing the encryption process.
"This is a stark reminder that IT administrators benefit from having an accurate inventory of all their connected assets and cannot leave out-of-date critical business systems facing the public internet," Brandt said. "If organizations have these devices anywhere on their network, they can be sure that cyberattackers will be attracted to them."
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2021/09/cring-ransomware-gang-exploits-11-year.html