ZeroHour
Recorded Futurepublished ()ingested German Hoeffner, Aaron Soehnen & Gianni Perez

ESXiArgs Ransomware Targets Publicly-Exposed ESXi OpenSLP Servers

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2020-3992
Use-After-Free RCE in VMware ESXi OpenSLP Service (Port 427)

CVE-2020-3992 is a use-after-free (CWE-416) in the OpenSLP service used by VMware ESXi, rated critical at CVSS 9.8. An unauthenticated attacker with access to port 427 on an ESXi host's management network can send crafted SLP traffic that triggers the memory-reuse flaw and gains remote code execution on the hypervisor. Successful exploitation grants full control of the ESXi host, and attackers have used these OpenSLP flaws in the ESXiArgs ransomware campaign to encrypt the disks of hosted virtual machines. Affected products are ESXi 7.0, 6.7 and 6.5 prior to the October 2020 patch releases (as well as the related VMware Cloud Foundation). The flaw is in CISA's KEV catalog (added 2021-11-03) with ransomware use confirmed, and EPSS assigns an 83% probability of exploitation within 30 days (100th percentile); no public PoC is listed in the source data.

Do: Apply VMware's ESXi security patches: ESXi_7.0.1-0.0.16850804 (7.0), ESXi670-202010401-SG (6.7), or ESXi650-202010401-SG (6.5), or the corresponding VMware Cloud Foundation update, per CISA's required action. As interim mitigation, restrict or disable the SLP service and firewall port 427 so ESXi management interfaces are not reachable from the internet. Because ransomware use is confirmed, check hosts for signs of compromise; CISA has published an ESXiArgs recovery script for affected deployments.

9.883% KEV ransomware
  • vmware ESXi 7.0 before ESXi_7.0.1-0.0.16850804
  • vmware ESXi 6.7 before ESXi670-202010401-SG
  • vmware ESXi 6.5 before ESXi650-202010401-SG
  • +1 more
large≈90,000-100,000 internet-exposed ESXi hosts on port 427 (many more reachable only on internal management networks)
CVE-2021-21974
OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability.

OpenSLP as used in ESXi (7.0 before ESXi70U1c-17325551, 6.7 before ESXi670-202102401-SG, 6.5 before ESXi650-202102101-SG) has a heap-overflow vulnerability. A malicious actor residing within the same network segment as ESXi who has access to port 427 may be able to trigger the heap-overflow issue in OpenSLP service resulting in remote code execution.

NVD description · AI analysis pending
8.845% PoC
  • vmware cloud foundation
  • vmware esxi
Full article627 words · extracted from recordedfuture.com · click to collapse

An ongoing ransomware campaign dubbed ESXiArgs is targeting outdated VMware ESXi installations. While first reports surfaced on Friday, February 3rd, a more significant wave infected at least 2,000 hosts over the weekend, according to BleepingComputer. An internet-wide scan reported up to 8,000 infected hosts as of this writing.

The attack likely exploits CVE-2021-21974, a two-year-old remote code execution vulnerability in the bundled OpenSLP service, for which a patch has been available since February 2021.

VMware ESXi is a Type 1 hypervisor that runs directly on host server hardware, providing a virtualization layer capable of abstracting CPU, storage, memory, and networking resources into multiple virtual machines. OpenSLP is an open-source framework for networking applications to discover the existence, location, and configuration of services in enterprise networks, which ESXi client applications use to resolve network addresses and hosts.

Affected Systems

The following ESXi versions are affected by CVE-2021–21974:

  • ESXi 7.x prior to ESXi70U1c-17325551
  • ESXi 6.7.x prior to ESXi670-202102401-SG
  • ESXi 6.5.x prior to ESXi650-202102101-SG

For a system to be vulnerable to CVE-2021–21974, the OpenSLP service needs to be running, and its associated port 427 needs to be reachable from the internet. According to VMware, this service is disabled by default on new installations since ESXi 7.0 U2c and ESXi 8.0 GA.

It should be noted that CVE-2021-21974 is not yet officially confirmed as the attack vector. The French CERT lists CVE-2020-3992 as another possibility, which is also a vulnerability of OpenSLP. While the exact vulnerability is unknown, OVHcloud, a large hoster with ESXi servers in its portfolio, confirmed that the OpenSLP service is the point of entry used in this campaign. VMware also recommends disabling OpenSLP as mitigation.

Furthermore, OVHcloud blocked port 427 for all servers with ESXi installed. Besides being assigned to the OpenSLP service, this port may also be used by a backdoor script in compromised installations.

Mitigation and recovery

VMware recommends updating vulnerable ESXi servers to an unaffected version if possible. As an additional measure, the OpenSLP service can be disabled. The procedure for this is described in this document.

Current insights by OVH and the security community suggest that closing port 427 or restricting access to it might also mitigate this vulnerability as a stop-gap measure.

Infected systems will have the following files present in the /tmp folder, which can serve as an indicator of compromise:

  • encrypt
  • encrypt .sh
  • public.pem

The system’s motd (message of the day) file and index.html will be replaced with a ransom note after the encryption process. The ransomware will try to stop running VMs to be able to encrypt their associated files.

The encryption algorithm has no known weaknesses that allow decrypting files without the key. But according to OVHcloud, stopping the VMs often fails, which leaves the files locked and prevents any encryption. Even if the encryption succeeds, only small chunks of the files are encrypted, which makes a recovery theoretically possible. However, this process is quite difficult, and security analysts are still working on the best procedures. The current procedure is described in this blog post.

Additionally, CISA and the FBI have released an ESXiArgs Ransomware Recovery Guidance, including a specific recovery script for this type of ransomware attack. We encourage all affected organizations to follow this recovery guidance.

Summary

VMware identified a new ransomware campaign targeting public-facing ESXi servers worldwide. The attackers are likely leveraging a two-year-old heap overflow vulnerability in ESXi's OpenSLP service. Patches for this vulnerability have been available, but the attack has revealed that many servers may still be vulnerable. Users should upgrade to the latest ESXi version and restrict access to the OpenSLP service to trusted IP addresses to mitigate potential threats if patching isn’t readily available.

This content was originally published February 8, 2023 and updated February 9, 2023.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.recordedfuture.com/blog/esxiargs-ransomware-targets-vmware-esxi-openslp-servers